CurvedSpace Forums: 22nd April 2005 - Warning Fansite users hijacked - CurvedSpace Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

22nd April 2005 - Warning Fansite users hijacked RS Update

#1 {lang:macro__useroffline}   Kowboy {lang:icon}

  • 05.Banshee.SE
  • Icon
  • Group: New Member
  • Posts: 2,330
  • Joined: 26-July 03

Posted 22 April 2005 - 05:26 PM

QUOTE
22nd April 2005 - Warning Fansite users hijacked

Warning: fansite users getting hijacked
It has come to our attention that several users of a large RuneScape fansite have recently had their RuneScape password stolen. The fansite is an independent website, and isn't run by us or affiliated with us, but many of our users do choose to use it.

We don't know for sure, and we are basically trying to work this out from the pattern of attack, but it seems quite likely this was done by posting malicious content or images on the forums of the 3rd party fansite. People viewing that page then got infected with a keylogger which could be used to steal all their passwords.

I know it's hard to believe that just viewing a page on a forum could be enough to be infected with a keylogger, but there have actually historically already been a number of security flaws in the image code in web browsers which allowed exactly that!

Our own forums deliberately don't allow users to post images or html exactly because of this security risk. Lots of people complain that we don't offer this feature, but we believe security is far more important than features. Unfortunately many third party fansites aren't as secure as ours with regards to this. Indeed we've noticed the attacker spreading recent rumours to try to pursuade more people to use fan-site forums instead of ours, presumably so he can hack more people through them.

I would like to emphasize that we believe the security of our own servers and forums is in no way compromised. It appears that the accounts are being stolen not by targeting our servers, but by instead targeting the home computers of users. Possibly via fansite forums.

We have of course very thoroughly double checked our own server security as well, but can find no sign of intrusion, and the fact that the people being hijacked are users of the same fansite seems unlikely to be a coincidence.

We take our own security very seriously here, but our users still have to take good care of their own computer as well. It is essential that you are careful to keep your computer secure to prevent a keylogger being installed on it, we recommend EVERYONE pays close attention to the following advice:

1) Ensure your computer is fully patched. Go to www.windowsupdate.com and make sure you have all the latest patches for your machine and web-browser. You may have to reboot and visit the site several times to get all patches.

2) If you use Internet Explorer it might be worth considering using an alternative web-browser which historically has been less targetted by attacks, and appears to often patch such critical problems more quickly. Here at Jagex we use Firefox, because we believe it offers better security. Although even if you do this it is still VERY important to make sure you always only use the latest version of the browser. Because firefox has previously had security problems too.

3) DON'T use your password anywhere except runescape.com. It is very important NOT to use the same password for RuneScape and other websites.

4) DON'T believe that just having anti-virus software instantly makes you 100% immune. It doesn't. There are many less common threats and attacks which you will still not be protected from. Anti-virus software helps, and is worth having, but it doesn't mean you can ignore all other security advice!

Unfortunately if you've already been infected then this particular keylogger doesn't appear to be picked up by anti-virus software yet, and the only sure way to get rid of it is a total reformat and reinstall of your computer (which should only be done by a professional). If anybody knows an easier way to detect or get rid of it then please let us know and we'll pass the info on. Of course your best bet is to be careful and not get infected in the first place!



(Not sure if anyone posted this yet.)

I think this may be the action taken by JaGex to kill off SS (Swiftswitch.)

-Cowboy
0

#2 {lang:macro__useroffline}   BubbaMurphy {lang:icon}

  • Senior Member
  • Icon
  • Group: New Member
  • Posts: 1,268
  • Joined: 14-December 03
  • Location:Florida

Posted 22 April 2005 - 05:26 PM

QUOTE
22nd April 2005 - Warning Fansite users hijacked

Warning: fansite users getting hijacked

It has come to our attention that several users of a large RuneScape fansite have recently had their RuneScape password stolen. The fansite is an independent website, and isn't run by us or affiliated with us, but many of our users do choose to use it.

We don't know for sure, and we are basically trying to work this out from the pattern of attack, but it seems quite likely this was done by posting malicious content or images on the forums of the 3rd party fansite. People viewing that page then got infected with a keylogger which could be used to steal all their passwords.

I know it's hard to believe that just viewing a page on a forum could be enough to be infected with a keylogger, but there have actually historically already been a number of security flaws in the image code in web browsers which allowed exactly that!

Our own forums deliberately don't allow users to post images or html exactly because of this security risk. Lots of people complain that we don't offer this feature, but we believe security is far more important than features. Unfortunately many third party fansites aren't as secure as ours with regards to this. Indeed we've noticed the attacker spreading recent rumours to try to pursuade more people to use fan-site forums instead of ours, presumably so he can hack more people through them.

I would like to emphasize that we believe the security of our own servers and forums is in no way compromised. It appears that the accounts are being stolen not by targeting our servers, but by instead targeting the home computers of users. Possibly via fansite forums.

We have of course very thoroughly double checked our own server security as well, but can find no sign of intrusion, and the fact that the people being hijacked are users of the same fansite seems unlikely to be a coincidence.

We take our own security very seriously here, but our users still have to take good care of their own computer as well. It is essential that you are careful to keep your computer secure to prevent a keylogger being installed on it, we recommend EVERYONE pays close attention to the following advice:

1) Ensure your computer is fully patched. Go to www.windowsupdate.com and make sure you have all the latest patches for your machine and web-browser. You may have to reboot and visit the site several times to get all patches.

2) If you use Internet Explorer it might be worth considering using an alternative web-browser which historically has been less targetted by attacks, and appears to often patch such critical problems more quickly. Here at Jagex we use Firefox, because we believe it offers better security. Although even if you do this it is still VERY important to make sure you always only use the latest version of the browser. Because firefox has previously had security problems too.

3) DON'T use your password anywhere except runescape.com. It is very important NOT to use the same password for RuneScape and other websites.

4) DON'T believe that just having anti-virus software instantly makes you 100% immune. It doesn't. There are many less common threats and attacks which you will still not be protected from. Anti-virus software helps, and is worth having, but it doesn't mean you can ignore all other security advice!

Unfortunately if you've already been infected then this particular keylogger doesn't appear to be picked up by anti-virus software yet, and the only sure way to get rid of it is a total reformat and reinstall of your computer (which should only be done by a professional). If anybody knows an easier way to detect or get rid of it then please let us know and we'll pass the info on. Of course your best bet is to be careful and not get infected in the first place!

0

#3 {lang:macro__useroffline}   Zoo {lang:icon}

  • ~@~@~@~@~@~@~
  • Icon
  • {lang:view_blog}
  • Group: Moderator
  • Posts: 1,615
  • Joined: 13-July 04
  • Location:Florida

Posted 22 April 2005 - 05:29 PM

Heheh

*merged*
You can do whatever, just had to do that bluetongue.gif
0

#4 {lang:macro__useroffline}   BubbaMurphy {lang:icon}

  • Senior Member
  • Icon
  • Group: New Member
  • Posts: 1,268
  • Joined: 14-December 03
  • Location:Florida

Posted 22 April 2005 - 05:30 PM

QUOTE(Cowboy @ Apr 22 2005, 01:28 PM)
Lol, I posted this at the same time as you. (I will delete mine after I post this.)

Here's what I said in the other post:

"I think this may be JaGex's action to kill off SS (Switchfoot.)"

-Cowboy
{lang:macro__view_post}


Um..I think you mean SwiftSwitch grnwink.gif
0

#5 {lang:macro__useroffline}   Red Sentinel {lang:icon}

  • Senior Member
  • Icon
  • Group: Member
  • Posts: 3,688
  • Joined: 26-June 04
  • Location:Florida

Posted 22 April 2005 - 05:31 PM

lol! shiftfoot! rofl.gif



i ponder which site it is...
0

#6 {lang:macro__useroffline}   Kowboy {lang:icon}

  • 05.Banshee.SE
  • Icon
  • Group: New Member
  • Posts: 2,330
  • Joined: 26-July 03

Posted 22 April 2005 - 05:32 PM

Lol, sorry. I was in a rush to delete the other post. (Not to mention me thinking of the band.) Thanks for pointing that out. TheSmile.gif

-Cowboy
0

#7 {lang:macro__useroffline}   Red Sentinel {lang:icon}

  • Senior Member
  • Icon
  • Group: Member
  • Posts: 3,688
  • Joined: 26-June 04
  • Location:Florida

Posted 22 April 2005 - 05:33 PM

band or client?
QUOTE
Lol, sorry. I was in a rush to delete the other post. (Not to mention me thinking of the band.)

This post has been edited by The Norse God: 22 April 2005 - 05:33 PM

0

#8 {lang:macro__useroffline}   Zoo {lang:icon}

  • ~@~@~@~@~@~@~
  • Icon
  • {lang:view_blog}
  • Group: Moderator
  • Posts: 1,615
  • Joined: 13-July 04
  • Location:Florida

Posted 22 April 2005 - 05:34 PM

Switchfoot is a band, red.
0

#9 {lang:macro__useroffline}   Kowboy {lang:icon}

  • 05.Banshee.SE
  • Icon
  • Group: New Member
  • Posts: 2,330
  • Joined: 26-July 03

Posted 22 April 2005 - 05:35 PM

Meant to say Swiftswitch the client, but I had Switchfoot (the band) stuck in my head...those names are to close to each other...

-Cowboy
0

#10 {lang:macro__useroffline}   Jarik C-Bol {lang:icon}

  • Blue. The one true color.
  • Icon
  • Group: Moderator
  • Posts: 1,558
  • Joined: 20-April 03
  • Location:Florida

Posted 22 April 2005 - 06:04 PM

of course, they dont tell us what site it is so we can avoid it.
0

#11 {lang:macro__useroffline}   Bodom {lang:icon}

  • Echliurn
  • Icon
  • Group: Member
  • Posts: 6,746
  • Joined: 26-April 03
  • Location:Florida

Posted 22 April 2005 - 07:00 PM

I am pretty sure its Tip.IT tons of my friends on msn have had names containing Tip.it are hackers etc

Btw its nothing to do with swiftswitch

0

#12 {lang:macro__useroffline}   Kimojuno {lang:icon}

  • W00T! :D
  • Icon
  • {lang:view_blog}
  • {lang:view_gallery}
  • Group: Global Moderator
  • Posts: 4,536
  • Joined: 09-May 04
  • Location:Florida

Posted 22 April 2005 - 07:03 PM

This has nothing to do with SS, because trust me it's clean, I know enough people (who are real scan freaks) that use it. And I agree with Jarik should of told us the site, but I doubt it's any of the big ones, but they could be emailing the ISP of the site about the keyloggers.

~ Kimojuno

{lang:macro__view_post}Xmadole, on 09 August 2009 - 09:28 AM, said:

i wish i actually read the first post of threads.


Posted Image
0

#13 {lang:macro__useroffline}   Bodom {lang:icon}

  • Echliurn
  • Icon
  • Group: Member
  • Posts: 6,746
  • Joined: 26-April 03
  • Location:Florida

Posted 22 April 2005 - 07:10 PM

The only thing jagex ever had against SS was it blocked ads, and this got fixed, SS is clean

0

#14 {lang:macro__useroffline}   Red Sentinel {lang:icon}

  • Senior Member
  • Icon
  • Group: Member
  • Posts: 3,688
  • Joined: 26-June 04
  • Location:Florida

Posted 22 April 2005 - 07:16 PM

yep, ech is talking the truth!!!










I GOT SARA PL8!!
0

#15 {lang:macro__useroffline}   BubbaMurphy {lang:icon}

  • Senior Member
  • Icon
  • Group: New Member
  • Posts: 1,268
  • Joined: 14-December 03
  • Location:Florida

Posted 22 April 2005 - 07:19 PM

That whole thing was useless cause we have no idea what to watch out for... eek7.gif
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users