[Announcement About Account Security] Haven/Salem

General discussion and socializing.

[Announcement About Account Security] Haven/Salem

Postby jordancoles » Wed May 22, 2013 1:59 am

Currently the Haven forums are blowing up with reports of account hacking.

Some of this is apparently coming from a custom client that has a keylogger inside of it, but the hackers have also gotten the emails of many members of the community and have been requesting to change the passwords of accounts.
If you get an email from the Salem forums or the Haven forums asking you to change your password, delete the email and do not click the link.

Change the email linked to your account and these emails should (hopefully) stop coming. I've received emails for both my Salem and Haven accounts myself.

DO NOT CLICK THE LINKS INSIDE OF THESE EMAILS.


Reposted from this thread on the Salem forums
http://forum.salemthegame.com/viewtopic ... 657#p80854
Last edited by jordancoles on Wed May 22, 2013 5:24 am, edited 1 time in total.
Duhhrail wrote:No matter how fast you think you can beat your meat, Jordancoles lies in the shadows and waits to attack his defenseless prey. (tl;dr) Don't afk and jack off. :lol:

Check out my pro-tips thread
Image Image Image
User avatar
jordancoles
 
Posts: 14034
Joined: Sun May 29, 2011 6:50 pm
Location: British Columbia, Canada

Re: [Announcement About Account Security] Haven/Salem

Postby Phoenix246 » Wed May 22, 2013 2:08 am

What has become of Haven now in days?
User avatar
Phoenix246
 
Posts: 517
Joined: Sun Feb 13, 2011 3:49 am

Re: [Announcement About Account Security] Haven/Salem

Postby joojoo1975 » Wed May 22, 2013 2:18 am

tis easier to cheat, than to actually win. But "cheatin's" been going on since W2.

we can only hope for a brighter future.
To Protect The Helpless From The Heartless
User avatar
joojoo1975
 
Posts: 2146
Joined: Mon Sep 28, 2009 5:23 pm
Location: no where specific

Re: [Announcement About Account Security] Haven/Salem

Postby loftar » Wed May 22, 2013 3:57 am

jordancoles wrote:By clicking the link you are essentially agreeing to have your password changed by the other person.

What procedure are you implying? Changing the password should only be possible for the person actually doing the clicking.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9015
Joined: Fri Apr 03, 2009 7:05 am

Re: [Announcement About Account Security] Haven/Salem

Postby borka » Wed May 22, 2013 4:12 am

Interesting would be where the link leads to and what (if there is) script (and what's in that) ?!?
Avatar by SacreDoom
Java 8 - manually downloads - good to check for actual versions url here:
viewtopic.php?f=42&t=40331
Remember what the dormouse said: Feed your head Feed your head
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: [Announcement About Account Security] Haven/Salem

Postby jordancoles » Wed May 22, 2013 4:35 am

loftar wrote:
jordancoles wrote:By clicking the link you are essentially agreeing to have your password changed by the other person.

What procedure are you implying? Changing the password should only be possible for the person actually doing the clicking.

Could be different here I suppose? I did not click the link to find out. For most sites I've been on you change the PW to whatever and then you confirm with the email link to change it.
Duhhrail wrote:No matter how fast you think you can beat your meat, Jordancoles lies in the shadows and waits to attack his defenseless prey. (tl;dr) Don't afk and jack off. :lol:

Check out my pro-tips thread
Image Image Image
User avatar
jordancoles
 
Posts: 14034
Joined: Sun May 29, 2011 6:50 pm
Location: British Columbia, Canada

Re: [Announcement About Account Security] Haven/Salem

Postby loftar » Wed May 22, 2013 4:53 am

jordancoles wrote:For most sites I've been on you change the PW to whatever and then you confirm with the email link to change it.

Um.

If you already know the current password of an account, you can change it without any e-mail. As on most sites, indeed; I haven't seen any site that works differently, but feel free to enlighten me. :)

If you use a reset e-mail, the link in the e-mail brings you to a page where you enter a new password; not a page to confirm a password entered in the past.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9015
Joined: Fri Apr 03, 2009 7:05 am

Re: [Announcement About Account Security] Haven/Salem

Postby jordancoles » Wed May 22, 2013 5:05 am

loftar wrote:
jordancoles wrote:For most sites I've been on you change the PW to whatever and then you confirm with the email link to change it.

Um.

If you already know the current password of an account, you can change it without any e-mail. As on most sites, indeed; I haven't seen any site that works differently, but feel free to enlighten me. :)

If you use a reset e-mail, the link in the e-mail brings you to a page where you enter a new password; not a page to confirm a password entered in the past.

Aye, I seem to recall something different on some sites I've used in the past but I've been hearing of people being hacked simply through the link so it may be something different entirely :s
Either way don't click the link to avoid potential problems :lol:
Duhhrail wrote:No matter how fast you think you can beat your meat, Jordancoles lies in the shadows and waits to attack his defenseless prey. (tl;dr) Don't afk and jack off. :lol:

Check out my pro-tips thread
Image Image Image
User avatar
jordancoles
 
Posts: 14034
Joined: Sun May 29, 2011 6:50 pm
Location: British Columbia, Canada

Re: [Announcement About Account Security] Haven/Salem

Postby Momoka » Wed May 22, 2013 10:38 am

loftar wrote:
jordancoles wrote:For most sites I've been on you change the PW to whatever and then you confirm with the email link to change it.

Um.

If you already know the current password of an account, you can change it without any e-mail. As on most sites, indeed; I haven't seen any site that works differently, but feel free to enlighten me. :)

If you use a reset e-mail, the link in the e-mail brings you to a page where you enter a new password; not a page to confirm a password entered in the past.


It would be good if it would send a pre-confirmation to the email. The legitimate owner would get an email redirecting him to a password change page. That would make it harder to steal the account.


If the attacker got both, the email and the account passwords, it's the user's fault.
User avatar
Momoka
 
Posts: 46
Joined: Sun Jul 17, 2011 6:21 am

Re: [Announcement About Account Security] Haven/Salem

Postby fanit937 » Wed May 22, 2013 11:37 am

Good thing I never check my mails, I just delete them all.
People are capable of kindness angels can only dream of, yet can commit sins that put demons to shame.
User avatar
fanit937
 
Posts: 667
Joined: Fri Jan 29, 2010 9:23 am
Location: Smithy

Next

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Dotbot [Bot] and 3 guests