BNET Account Scammed

well laugh if you want but its not me. its a friend. he downloaded a form of a mh from [highlight]no.com[/highlight] and he told me about it. i was like NOOOOOO!!! but now is it too late?
 
Sin Lord said:
i have a question. if you say had downloaded something d2 related and thought you were in danger what exactly could you do besides a full rebbot then pass change if you havent been got yet?
reboot's don't change jack all. Run antivirus + antimalware, clean out your internet cache, and run into the wall headfirst for being such a moron...
 
Ah, but it's not stupidity... It's laziness and greed, and someone decided to exploit those attributes that are oh so common. Sympathy? None.
 
k/t said:
Ah, but it's not stupidity... It's laziness and greed, and someone decided to exploit those attributes that are oh so common. Sympathy? None.


agreed.


I'm still not convinced on the OP's original problem though...anyone else?
 
I have been conducting an evaluation of where I use the same password I use for Bnet. I found only 3, my Yahoo account (not likely hacked from here), my D2 forum account and my RPG Traders.net account. Seeing that I'am 1000% sure I did not give out my password. I now believe that someone hacked into my forum account or my RPG Traders.net account, found my password and tried it out on my BNET account. Alternatively, someone who works for either of these 2 sites could also have access to passwords.

I would like to see if Von Lazuli also used same password for both BNET and the forums or RPG Traders.

Everyone should make sure they generate unique passwords for each application. Don't make same mistake I did.

I will probably never know what happened, but now that all my accounts//passwords are changed I have some piece of mind to go on and make a new Berzerker Barb
 
xNamastex said:
Alternatively, someone who works for either of these 2 sites could also have access to passwords.

Two things:

One: Member passwords - here at least - are encrypted and in fact, we do not have access to them - they are not even displayed in my control panel. If I needed to tend to your forum account for some reason, I could access it at will. I have no need or use for your password. Nevertheless ...

Two: Don't use the same password for your accounts that you use for other sites. Common sense should tell you that.
 
xNamastex said:
my RPG Traders.net account.

This is interesting, as I had my account cleaned of valuables a few months ago - the same day I stupidly created an RPG Traders account with the same pass I was using on b.net. Nowdays I keep seperate & random passwords for everything.
 
Is it that you live with anyone else or nearby? Someone could have come in when you were snoozing and you left your account on.

Is it possible that you were "smashed" and you simply don't remember selling all your items to Ormus?
 
Hey this exact thing happend to a friend of mine... all of his "godly" (exile fort nigma hoto anni torch etc) items were gone but the rest of his stuff and characters were fine..... i actualy saw the person on durrin the time they took his stuff..... so he not the only one...
 
There is a way to steal accounts without you doing anything, like what happened to this guy.

I'm not 100% sure on the details, but it involves Blizzard's email/pw registration system. I remember someone screaming about how easy it was to steal accounts and Blizzard should be more careful, etc, on the battlenet boards the day after the patch that enabled registration was released.

The only way I know to protect against it is to register your account name on all the realms.
 
Admittedly I did not read all of the posts so I don't know if this has been corrected.

Failed logon attempts are 'reset' whenever you type the correct password. If someone's cleaned out the acc then obviously someone got the right password --> no failed logon attempts shown to whoever logs on afterwards.
 
Xenon[KoA] said:
Check your PMs.

Apart from that.. a keylogger seems most likely; but what puzzles me, is that they left your password unchanged, and characters still there.

In the future, try swapping in ascii chars. They provide a lot more solid protection, than standard alphanumeric, and the battle.net forums do not recognize them.

ex: sublimity < 5u8|im17y < §ü8|im17¥

that is good information... but...
i am a mac user :rolleyes: and i can't figure out how to swap in the ASCII characters.. i tried holding down the left ctrl key when typing, but it didn't work.. when i held down the left option/alt key and typed

sublimity

i got

ߨ?¬ˆµˆ†¥

is that ASCII??

thanks :wave:
 
open one of the charts: http://images.google.ca/images?hl=x...//www.jimprice.com+filetype:gif&btnG=z34r<|-|

Those tell you the sequences relating to each symbol.

sublimity was an example.
weaker - weak - strong sorta escalation

§ü8|im17¥ is: [02215][0215]|im17[01445]
If you don't understand it, don't use it =/

The whole point of using ascii chars, is to create a password that's uncrackable by bnet scriptkiddies, and most crackers.

if you need more examples: (and ffs, don't use these as your pass...thats just asking for it...)
raszagal < r45z464| < ®4§zá6Åà ( [02222]4[02215]z[0225]6[143][02255] )
ressurection < r3s5ure<710n < ®3§5ü2é©7ìÓñ ( [02222]3[02215]5[0252]2[0233][05545]7[0236][0211][02545] )

edit/ I know resurrection is spelled wrong. using words that aren't in the dictionary also helps. either Way, it's just a starting point for your pass.
 
its not possible unless u downloaded or visisited an unclean site. or unless ur password was something stupid like ur account name or one number or letter..but as u said alphanumeric. the closest thing 2 this i have come encounter with is my friend had a torch disapear in his stash. thats about it. he didnt use any mods or hacks either, and never downloaded anything. u know it might not even been a d2 download. u can pick up a keylogger from almost any site these days, and maybe that person played d2? hope it helps.
 
I was hacked some time ago, back when I was more into dueling. I have never used a hack of any type and no one knows my password, and my password is huge and random. I just logged in one day and noticed my ama dueler, my mf Sorc and barb were all missing gear. Wf/mara/40/160 armor eth Skullder’s/silence/GF and a few other high end items. I ran every virus scanner I could find (that I trusted) and they never turned anything up. I changed my password to something even longer and moved on. So I know it can happen.

To all the people that swear up and down that they is no way for someone to get in to your account without the account owner doing something dumb, I'll point you to the first ladder. That's were the way to get any account's password was so obvious everyone was striping accounts left and right. Those were just regular idiots and children and they were able to get in the majority of the accounts on bnet, now think of what someone with a little experience could do...
 
Crazyhorse said:
I was hacked some time ago, back when I was more into dueling. I have never used a hack of any type and no one knows my password, and my password is huge and random. I just logged in one day and noticed my ama dueler, my mf Sorc and barb were all missing gear. Wf/mara/40/160 armor eth Skullder’s/silence/GF and a few other high end items. I ran every virus scanner I could find (that I trusted) and they never turned anything up. I changed my password to something even longer and moved on. So I know it can happen.

To all the people that swear up and down that they is no way for someone to get in to your account without the account owner doing something dumb, I'll point you to the first ladder. That's were the way to get any account's password was so obvious everyone was striping accounts left and right. Those were just regular idiots and children and they were able to get in the majority of the accounts on bnet, now think of what someone with a little experience could do...

Somehow, I very much doubt that...

So you're saying it easy and common for people to hack eachother's password without any clue of the password and the password itself being a complex alphanumeric combination? Meh.

If you're gonna says things like that, I for one would like to seem some proof. (legit proof, not something you wrote or made up yourself)
 
Dawnmaster said:
Somehow, I very much doubt that...

So you're saying it easy and common for people to hack eachother's password without any clue of the password and the password itself being a complex alphanumeric combination? Meh.

If you're gonna says things like that, I for one would like to seem some proof. (legit proof, not something you wrote or made up yourself)

I'm not saying I think these people try combinations of passwords as that would be a pain in the butt. There are what like 2 million or so combos if your password is only 4 chars. I'm saying there are other ways and if you are asking for proof I'm guessing you wern't around for season 1 of the ladder..

When 1.10 came out they added the register you email deal. People would find an account they wanted on west say account "DFGDFGDFGDF" they would run over to east make an account "DFGDFGDFGDF" and register their email to it then do a lost password email it to me. Then they changed the realm notes on the email and confirmed they lost the password and the automated system would send them a password for that account on whatever realm they wanted. In just a few days something like 80%+ of the HCL leaders were killed and stripped.

Ok so there is proof that hundreds (if not more) people that never used a hack or did anything wrong had thier accounts stolen. I never siad it was common, I said it can happen.
 
a- email exploit isnt hacking
b- email exploit isnt cracking
c- its was already fixed. Like I noted above.
d- that was already mentioned. rementioning it doesnt add any veracity.
 
Back
Top