Forums

Uncle Arch's Security Corner

Quick find code: 86-87-850-62432224

Archaeox
Dec
fmod Member
2011

Archaeox

Forum Moderator Posts: 53,398 Emerald Posts by user Forum Profile RuneMetrics Profile
Nah. There's a whole Account Security forum already, this is just a quick reference for the folks here in CL (not all of whom use the main forums, after all).
~~~~ Just another victim of the ambient morality ~~~~

~~ Founder of the Caped Carousers quest cape clan ~~

!! Slava Ukraini - heroyam slava !!

19-Sep-2011 11:49:11

Kor
Aug Member 2021

Kor

Posts: 825 Gold Posts by user Forum Profile RuneMetrics Profile
You're very wise, I must admit this. I hope you don't mind that I've copied your quick summary from one of your other posts to another section on the forums to another player.

I'll keep coming back to here for future reference :P

14-Oct-2011 09:34:48

Archaeox
Dec
fmod Member
2011

Archaeox

Forum Moderator Posts: 53,398 Emerald Posts by user Forum Profile RuneMetrics Profile
Wise? Nah.

Paranoid? Oh yes :)

Glad it helps, you're welcome to use the information here in any way that helps your clan members (or others) - although a credit is always nice ;)
~~~~ Just another victim of the ambient morality ~~~~

~~ Founder of the Caped Carousers quest cape clan ~~

!! Slava Ukraini - heroyam slava !!

15-Oct-2011 01:52:01

Iron Faery
Jul Member 2007

Iron Faery

Posts: 2,474 Mithril Posts by user Forum Profile RuneMetrics Profile
What would you suggest to my clan member who had big security issues in past.

When he was online, like doing slayer task, sometimes he had strange cnnection lost and when he logged in, his account wasn't where he left it, armour, weapons, all valuable was gone as well. Sometimes pw was changed or bank pin cancelled.

It sounds to me like he had spyware in computer and he wasn't able to find and destroy it in this time. We met each other before hacker started and didn't keep added first time.

He was so annoyed of constant attacks, he left his lvl 130+ acc and started playing with pure. He posted about his security issues to certain threads in public forums and checked it for answers but no reply to him.

We met again and he told he would like to join but account security issues damaged him often and hard, he is not sure can he join combat events when he can lose all gears again. He explained attacks history.

I said he can play with us, do dungeon maybe first, no need to leave account, perhaps there is some way to help him.

He thinks that hacker can use old pw's or other info to attack again. He don't know how much exactly hacker knows but enough to do account recovery and take over his account. If hacker caused connection losts before and took all tradeable items, can do it again.

He wants to know - how can he eliminate this danger from past? Right now his computer looks clean and acc haven't been under attack lately.

16-Oct-2011 23:49:37

Iron Faery
Jul Member 2007

Iron Faery

Posts: 2,474 Mithril Posts by user Forum Profile RuneMetrics Profile
I checked his posts and found in account security forums in Mod Parrott's thread. They are investigating only last 30 days. Maybe they checked account but didn't answer to him or it is not investigated yet? He don't know.

16-Oct-2011 23:49:38 - Last edited on 16-Oct-2011 23:55:39 by Iron Faery

urmyleander

urmyleander

Posts: 8,620 Rune Posts by user Forum Profile RuneMetrics Profile
Arch you should prolly mention the skyp / teamspeak scams going around atm.Alot of clans use skype and teamspeak but recently on forums there have beens scam clans, what they do is say doing bandos/nex/whatever then they say you hafta go in teamspeak or skype.When you do they get your ip and dos attack your computer while your at the boss so you die they then loot your stuff.

17-Oct-2011 11:11:33

Archaeox
Dec
fmod Member
2011

Archaeox

Forum Moderator Posts: 53,398 Emerald Posts by user Forum Profile RuneMetrics Profile
Iron Faery:

Nasty business :(

As always, though, the place to start is with personal security. Your friend needs to be *certain* of how their information was obtained, and *certain* that the leak has been plugged - all BEFORE doing anything to recover the account, change the recovery questions etc.

They need to sanitise their own machine, not just using an antivirus, but also using anti-malware and anti-rootkit scans, and keep looking until they find the problem.


urmyleader:

Fair point - the technique is as old as IRC channels of course, only the medium is changing. I've added this:

""
* Your IP address can be revealed by using IRC channels, or through voice chat servers hosted by the dishonest. This in turn can make you vulnerable to Denial of Service attacks and even direct hacking.
""
~~~~ Just another victim of the ambient morality ~~~~

~~ Founder of the Caped Carousers quest cape clan ~~

!! Slava Ukraini - heroyam slava !!

17-Oct-2011 13:00:29 - Last edited on 17-Oct-2011 13:03:48 by Archaeox

Zetris

Zetris

Posts: 15,449 Opal Posts by user Forum Profile RuneMetrics Profile
Ty uncle

Maybe this should be mentioned to help recovering accounts
1. make sure your email is registered. it would also be more secure if that e-mail is separate from your main, if your key logged they wont be able to hack it unless u logged in.
2. Change your password frequently. this would help account recovering if anything happens, especially if your keylogged or forgotten your password.
3. firefox ad-on, the "WOT" add-on can help identify phising/unsafe links. in emails it shows a red circle next to my rs phishing emails.

30-Dec-2011 13:47:49 - Last edited on 30-Dec-2011 15:55:04 by Zetris

Quick find code: 86-87-850-62432224 Back to Top