Like Minded Gamers Forum Index Like Minded Gamers

 
 FAQFAQ   SearchSearch   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Calendar
Calendar Calendar
Mon 06 Sep 2010 Tue 07 Sep 2010 Wed 08 Sep 2010 Thu 09 Sep 2010 Fri 10 Sep 2010 Sat 11 Sep 2010 Sun 12 Sep 2010
Hackers bypassing wow authenticators

 
Post new topic   Reply to topic    Like Minded Gamers Forum Index -> WoW General
View previous topic :: View next topic  
Author Message
OldScotch
Administrator

WoW Main Toon:
Morbidwrath
WoW Profession One:
Mining
WoW Profession Two:
Engineering

Joined: 28 Feb 2003
Posts: 7915
Location: Toronto

PostPosted: Tue Mar 09, 2010 10:25 am    Post subject: Hackers bypassing wow authenticators Reply with quote

http://www.tomshardware.com/news/blizzard-warcraft-authenticator-hack,9821.html

It doesn't actually bypass it, it simply records the authenticator input just like your password - it then takes advantage of the fact that the autheticator code stays active for 30 seconds and uses that time to login to your account manager with the freshly acquired password/authenticator code to change your password, and again to the game to steal all your stuff.

I don't know what, if anything Blizzard is doing to fix this. A possible solution would be to impletment a one-use policy on the authenticators, so as soon as you enter the code, the same code can't be used again. It'd be a bit of a pain because if you enter it wrong you have to wait 20 seconds or so for a new code. That'd be fine with me as a compromise.

That still doesn't change that there's a keylogger on your system though; Blizzard might do well to host approved mods on battle.net
_________________
These are stone killers, little man. They ain't cuddly like me.

Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
Shadowpound
LMG Member

WoW Main Toon:
Shadowpound
WoW Profession One:
Herbilism
WoW Profession Two:
Alchemy

Joined: 27 Jul 2005
Posts: 651
Location: Virginia Beach, VA

PostPosted: Tue Mar 09, 2010 11:43 am    Post subject: Reply with quote

Wow.. I had no idea that the online stuff for World of warcraft was so Lucrative that someone would develop a keylogger program to get around even the authenticators. wow...
not to mention you only have 30 seconds.. is that even possible? I mean come on.. you have to get the code and enter it in 30 seconds before the code resets.. yeesh
_________________
Shadowpound Level 80 Tauren Warrior (Herb/Alch)
Madmage Level 80 Undead Arcane Mage (Skinning/Miner)
Shadowsjudge Level 80 Belf Pally (Ret/Holy)
(Miner/blacksmith)
Shadowzulin (formerly Trollhunter, Sorry Nate) smile level 70
(Skin, Miner)
Back to top
View user's profile Send private message
OldScotch
Administrator

WoW Main Toon:
Morbidwrath
WoW Profession One:
Mining
WoW Profession Two:
Engineering

Joined: 28 Feb 2003
Posts: 7915
Location: Toronto

PostPosted: Tue Mar 09, 2010 12:14 pm    Post subject: Reply with quote

It would have to be done with a script, the keylogger causes your game to crash so the machine it has waiting to login remotely is just waiting to jump on it.
_________________
These are stone killers, little man. They ain't cuddly like me.

Back to top
View user's profile Send private message Send e-mail AIM Address MSN Messenger
dasnorm
LMG Member

WoW Main Toon:
Daslord
WoW Profession One:
inscribing
WoW Profession Two:
herbing

Joined: 22 Apr 2003
Posts: 567
Location: Calgary

PostPosted: Wed Mar 10, 2010 8:45 pm    Post subject: Reply with quote

my anti virus software comes with a virtual keyboard(so you mouse in your password) screw u keyloggers smile
_________________
can i hurry up and win the lotto so i can sc2 all day??!?!?

REALID= dasnorm@shaw.ca
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic   Reply to topic    Like Minded Gamers Forum Index -> WoW General All times are GMT
Page 1 of 1
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot post calendar events in this forum