Forums

Uncle Arch's Security Corner

Quick find code: 86-87-850-62432224

Archaeox
Dec
fmod Member
2011

Archaeox

Forum Moderator Posts: 53,398 Emerald Posts by user Forum Profile RuneMetrics Profile
Hey Zetris :)

Ref points 1 & 2, I already have...
""* Never give out the email address you registered for RS with. Use a disposable address instead.""
and
""* Change your passes from time to time (as long as you are SURE you have no infection when you do!) ""
on the list, but you're right, something about registering the e-mail would be useful.

I haven's seen WOT (Web of Trust), probably because I don't trust anyone really, but I'll wander over and have a look at it later - thanks! :)

---------------------------------------------

Leta -

Good plan, there may be questions later! :P
~~~~ Just another victim of the ambient morality ~~~~

~~ Founder of the Caped Carousers quest cape clan ~~

!! Slava Ukraini - heroyam slava !!

02-Jan-2012 13:58:40 - Last edited on 02-Jan-2012 14:00:10 by Archaeox

Bunny Kick

Bunny Kick

Posts: 14,188 Opal Posts by user Forum Profile RuneMetrics Profile
Oh, i despair. How do we save people from themselves? How do we protect the innocents? How do we REACH people and make them truly understand the risks?

We can share the information such as is posted in this thread, and in other threads like it, and you'd hope that with our clan ties we'd be able to spread the word pretty effectively. But the message - is not getting through.

Phishing is worse than ever before, it's widespread and professionally done. Many people from this forum have made note of the very eye-catching, Jagexy emails-with-phishing-links. Some of you may have stumbled across innocent-looking-deadly-phish-links on 3rd-party websites. Phishing is epidemic. How do we protect people from it?

I feel sometimes we are actually doing the opposite. For example, once Jagex started to use email for "select purposes," it opened up the floodgates for phish email. It might seem "common sense/obvious" to many of us, how to tell a phish mail from a legit Jagex email. But it is NOT common knowledge to the playerbase at large. The security-related posts in the forums are excellent - but how many do they actually reach?

Another example - clan websites. Before we had "clan pages" on the official website, many/most clan leaders maintained offsites - and probably the majority of clans still do. We must stop perpetuating the myth "trust me I'm a clan leader." Sure, all of us here are Upstanding Runescape Citizens - but those with evil intent can dress up in the guise of clan-leader respectability - how's the typical player supposed to tell the difference?

Jagex has made it harder for rwt's to create new accounts. GOOD. But there's a downside - when you can't make a new/throwaway account, STEALING an existing account becomes a very attractive option. Rwt's are going high-gear perfecting their ability to do this. WHAT can we do to stop this menace in its tracks?

(Short of removing free trade)

Sigh!

02-Jan-2012 17:08:01

Light Eric

Light Eric

Posts: 8,227 Rune Posts by user Forum Profile RuneMetrics Profile
Something I believe that would serve some good here-

Somewhat recently, Jagex added a new feature to the bank pins that can help stop hackers from attacking your account while you are away. You now have the option to change the amount of time it takes to change your bank pin from the normal 3 days to a full 7 days. This ensures you that a hacker will not be able to delete your pin in order to access your bank while you are on a one week vacation, and a better chance that you'll stumble upon it if you are going away for even longer.

To access this feature just talk to a banker and hit "I'd like to check my PIN settings." Then proceed to click the box that says "Change recovery delay." It will automatically change from 3 to 7 days.

~Eric

03-Jan-2012 01:33:51 - Last edited on 03-Jan-2012 01:42:11 by Light Eric

Leta
Jan
fmod Member
2008

Leta

Forum Moderator Posts: 25,401 Sapphire Posts by user Forum Profile RuneMetrics Profile
If someone gets ahold of your IP, what can be done with it? You can't be hacked with just an IP can you?

(I'm not very techy, sorry if this is a silly question).
RSC - Gone, but never forgotten.

03-Jan-2012 03:06:58 - Last edited on 03-Jan-2012 03:07:26 by Leta

inij123
Nov Member 2023

inij123

Posts: 360 Silver Posts by user Forum Profile RuneMetrics Profile
Got quite an urgent question. Everytime a clanmate logs in he notices that someone else has been on his account. He keeps his stuff on his bank for safety, but is scared that one day they will get hold of his account. He keeps changing bankpin, password, changed computer etc. He gets disconnected a lot. Virusscan didn't show anything irregular.

Is there a possibility to temporarily allow only 1 IP-address on your account? Or are there other solutions tot temporarily lock the account untill he figured out what went wrong?

03-Jan-2012 09:05:39

Light Eric

Light Eric

Posts: 8,227 Rune Posts by user Forum Profile RuneMetrics Profile
You can be hacked by ip. I believe once they get your ip its easy for them to send stuff to your computer over the internet, maybe a hidden keylogger or something.

It's also possible to hack a christian conservative morning radio talk show and make it play mexican music :D . It's been done.

04-Jan-2012 02:56:13

Bunny Kick

Bunny Kick

Posts: 14,188 Opal Posts by user Forum Profile RuneMetrics Profile
Inij, some virus scans aren't too good at picking up keyloggers... which might be the issue in this case, given that the problem is persisting through pass changes etc. I'm sure there's some tecchies here that can recommend a safe/free keylogger scan that he could try.

Also, there is the possibility that the guy has been responding to phishing emails, and despite his current troubles is still unaware that they aren't "real jagex emails." particularly if he's changing his pass/experiencing concerns with account security, if he's getting bogus messages saying "pass changed confirm here or click here to cancel request" or "we have reason to believe your account is compromised, click here to confirm your ownership" or stuff along those lines - he might be falling for a phish repeatedly.

(I know that we're all supposed to be filled with street smarts and common sense... but let's face it, sense is not common at all and phishes can be very deceptive).

04-Jan-2012 08:10:51

inij123
Nov Member 2023

inij123

Posts: 360 Silver Posts by user Forum Profile RuneMetrics Profile
Ty Bunny.

Yes I think he has been falling for some fake jagexmails, but once into that cycle it seems almost impossible to get out of it. For instance yesterday he created a new email address just for rs registration. Strangely enough he got a confirmation email on that new address but did not get a confirmation code. Which makes us doubt if it was a real jagex confirmation. I think it's now a mix of authentic and fake messages he is getting and he isn't able to tell them apart.

04-Jan-2012 13:06:26

Quick find code: 86-87-850-62432224 Back to Top