AionSource.com - Powered by the Tower of Eternity: Recent Website Hacks Aimed at Gamers and Aion Players - AionSource.com - Powered by the Tower of Eternity

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Recent Website Hacks Aimed at Gamers and Aion Players Rate Topic: -----

#1 User is offline   Knite Icon

  • <b>NCWest</b>
  • PipPipPipPipPipPipPipPip
  • View blog
  • Group: Members
  • Posts: 3434
  • Joined: 20-February 07
  • Character:Knite
  • Legion:Knights of the Divine Order
  • Race :Elyos
  • Server:Triniel

Posted 26 January 2010 - 08:52 PM

Hey everyone-

Several popular Aion fansites, technology and gaming blogs, and places we all visit have been under attack lately from hackers. The most recent attempts ranging from the massive tech website TechCrunch, to right here at home on your favorite Aion fansites may have left sensitive data on your PC vulnerable.

AionSource was targeted along with these other sites beginning at 5pm on January 24th and was completely cleared up by 5:20pm. 6 hours later after we cleared the site of the breach, Google flagged AionSource as an "attack site" due to the small window where the breach took place. We appealed and were removed from this "attack site" list shortly after once Google verified we were clear.

We wanted to let everyone know we're doing everything we possibly can to ensure your safety, and the safety of things you hold dear. The reality so far is we do not know the intention or intentions of the persons who have been working so hard to redirect users and exactly what they're tried to install on our PCs. We have made several advancements in our security here at AionSource.com and have beefed up and re-installed plugins and custom code we use.

As we stated, we have since gone through, fully wiped and reinstalled vBulletin, and revamped our security to prevent intrusions like this from happening again. We want to encourage anyone who may have been logged into our site during that time to especially pay attention to the steps below.

Here are some tips on how to best protect yourself from these and other attacks:


- Install a good virus scanner (you can get high quality ones for free, such as Avast or AVG) or alternatively run a free online virus scanner like F-Secure: Free Online Scanner

- Make sure to clear your cache if you think you've been somewhere potentially dangerous, make sure all temporary internet files are removed.


- Use a different login/password for your E-mail, NCSoft Master Account, AionSource and Aion game accounts. If any of your passwords for these 4 services overlap, you are increasing your vulnerability to criminals seeking your personal data.

- On your master account, make sure you have good security questions that only you know the answers of, and that are difficult to guess - otherwise somebody can reset your password quite easily.


- Keep your computer and web browsers updated with the latest security patches, not updating leaves you vulnerable to attack.



Above all, we want to continue to provide a fun and safe community for everyone. These hackers/criminals are attacking high profile sites, but we are unaware if they are specifically targeting Aion accounts or if they have other motives. Please, please do all you can to protect yourself and your information and take the above steps very seriously.

As always, we appreciate your continued support!

To obtain latest security updates:
Internet Explorer: Microsoft Update
Firefox: Firefox web browser | Faster, more secure, & customizable
Safari on Mac OS X, click on the Apple menu and then Software Update.
Google Chrome: Google Chrome
Opera: Opera browser | Faster & safer internet | Free download

This post has been edited by Chalky: 27 January 2010 - 07:34 AM
Reason for edit: AV clarification

0

#2 User is offline   Cynic Icon

  • Administrator
  • Icon
  • View blog
  • Group: Administrators
  • Posts: 9803
  • Joined: 18-January 09
  • LocationNew Zealand
  • Legion:BennyLava
  • Server:Undecided

Posted 26 January 2010 - 09:45 PM

It's strangely quiet in here... I'm ever so slightly scared.
Posted Image



Ayase said:

I'll always reserve a special place in my heart for you.


Tworak said:

I'll be your trophy husband and your power bottom if you so desire, my Lord.


Snoozle said:

Will there be anything else needed master Cynic?
0

#3 User is offline   Ephrum Icon

  • General
  • PipPipPipPipPip
  • View blog
  • Group: Members
  • Posts: 986
  • Joined: 06-June 08
  • Character:Ephrum
  • Legion:DeathIsEternal

Posted 26 January 2010 - 09:50 PM

Firstish post? Cool!

Anyway, good to hear you guys are staying ontop of things. <3

Also a good thing that my login/pass here are not the same as my login in game, but thats besides the point.
Si vis pacem, para bellum. ~ "If you want peace, prepare for war."
0

#4 User is offline   Phantom Slave Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 64
  • Joined: 21-August 09

Posted 26 January 2010 - 09:54 PM

I just want to point out that your privacy question should always be something that's personal to you (an experience, a pet name, etc.) and never use Mother's maiden name or things like that because they're in open records available to the public (Birth Certificates show maiden name of your parents). Choosing a question/answer that are about a field trip you took will be much more secure.
0

#5 User is offline   Melchior Icon

  • This title is unamusing!
  • Icon
  • View blog
  • Group: Moderators
  • Posts: 874
  • Joined: 22-September 09
  • Race :Asmodians
  • Server:Undecided

Posted 26 January 2010 - 09:56 PM

Don't worry Cynic, I'm sure people will comment soon enough.

This announcement is OUTRAGEOUS! Thanks for the update Knite!
This signature is OUTRAGEOUS!
0

#6 User is offline   Antipathy Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 102
  • Joined: 05-September 09
  • LocationBC, Canada
  • Character:Antipathy
  • Legion:Antisocial
  • Race :Asmodians
  • Server:Kaisinel

Posted 27 January 2010 - 12:31 AM

Knite said:

we are unaware if they are specifically targeting Aion accounts or if they have other motives.


its most definitly not just aion websites/accounts/players. guildwars guru's database was accessed on friday as well.
0

#7 User is offline   Axle01 Icon

  • Daeva
  • Pip
  • View blog
  • Group: Members
  • Posts: 19
  • Joined: 17-July 09
  • LocationN.Ireland
  • Character:Dementia
  • Legion:Heresy
  • Race :Asmodians
  • Server:Perento

Posted 27 January 2010 - 04:05 AM

during the timeframe of the alleged attack i noticed a trojan called Infostealer.Gampass on my system on a regular scan.

Norton gave me a description

Infostealer.Gampass is a generic detection for a Trojan horse that steals online game accounts, such as Lineage, Ragnarok online, Rohan, and Rexue Jianghu.

this type of trojan has been around since 2006 I would say its been modified to catch aion accounts aswell.

This post has been edited by djsipo: 27 January 2010 - 04:10 AM

0

#8 User is offline   PewPewLaz0r Icon

  • General
  • PipPipPipPipPip
  • Group: Curse Premium
  • Posts: 837
  • Joined: 31-August 09
  • LocationLOLOLOLOLOLOLOLOLOLOLOLOLOLO
  • Character:LOLOLOLOLOLOLOLOLOLOLOLNAWSON
  • Legion:LOLOLOLOLOLOLOLOLOLOLOLOLOLOLO
  • Server:Siel

Posted 27 January 2010 - 07:33 AM

Never update my browsers but since you had a link i figured i might as well. Thanks knite

Edit: Now my wow forums aren't in my most visited =(
Posted Image

0

#9 User is offline   Empfy Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 75
  • Joined: 12-November 06

Posted 27 January 2010 - 08:50 AM

Knite said:

[B]- Install a good virus scanner (you can get high quality ones for free, such as Avast or AVG) or alternatively run a free online virus scanner like F-Secure: Free Online Scanner


Ehh, for the windows users: Use the free microsoft scanner?

If you think your account as been hacked or your info stolen use the Malicious Software Removal Tool to detect malicious software(its not detected by virus scanners). Again, from microsoft.
Oh and other scans from microsoft including (web scans) Virus scanner, firewall scanner and some clean up tool. Windows Live OneCare safety scanner: Free online tool for PC health and safety you guessed it, microsoft again..


Good luck people ;)
Life is unfair, dont change it, takes the fun out of it
0

#10 User is offline   Kalidren Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 64
  • Joined: 09-September 09
  • Legion:Flameborne

Posted 27 January 2010 - 10:05 AM

Several in our guild had some hijack file on our computers which i gather is a false positive (alarmed a few tho!) One who visits this site (but doesn't have a account) was hacked and passwords changed. Not sure what the name of the file was. I keep my computer fully up to date at all times and IE8 didn't tell me that AionSource had been compromized. Other's said that Firefox caught it (sort of)

For him ... Avg didn't detect a problem altho malwarebytes did.

Interesting how that all works.

This post has been edited by Kalidren: 27 January 2010 - 10:12 AM

0

#11 User is offline   msims81 Icon

  • Human
  • Pip
  • View blog
  • Group: Newbies
  • Posts: 7
  • Joined: 24-January 10
  • Character:Haken

Posted 27 January 2010 - 10:10 AM

Everyone forgets about Adobe. Updating Adobe Reader is highly recommended as well. They patched a critical vulnerability this month that bypasses browser security.
chown us:us allyourbase
0

#12 User is offline   Solo Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 64
  • Joined: 08-August 09

Posted 27 January 2010 - 10:17 AM

Thanks for posting this Knite. I'm very glad to see you guys making an official announcement about this. I know it's not the best thing for PR, but it's really good to know that those in charge of this site are doing their best to look out for their visitors.

I won't name names, but there have been a few postings from site moderators that have just come off as defensive posts, in denial about the possibility that the recent hackings may be related to fansite breaches and security issues. I'm glad this sets the tone straight.
0

#13 User is offline   DojoMax Icon

  • Lieutenant
  • PipPipPipPip
  • Group: Members
  • Posts: 637
  • Joined: 27-September 09
  • LocationLas Vegas, Nevada
  • Character:Hax-n-Strip
  • Legion:Trollz
  • Race :Asmodians
  • Server:Zikel

Posted 27 January 2010 - 06:12 PM

Solo said:

Thanks for posting this Knite. I'm very glad to see you guys making an official announcement about this. I know it's not the best thing for PR, but it's really good to know that those in charge of this site are doing their best to look out for their visitors.

I won't name names, but there have been a few postings from site moderators that have just come off as defensive posts, in denial about the possibility that the recent hackings may be related to fansite breaches and security issues. I'm glad this sets the tone straight.


:skip::skip::skip::shakeit::shakeit::shakeit:

/end
"Aw dammit im a grape again."

NCsoft is bad, and Aion sucks, if you don't like my OPINION you can always report me. <3 Dojo.
0

#14 User is offline   Moriwenne Icon

  • Advanced Member
  • PipPip
  • View blog
  • Group: Members
  • Posts: 45
  • Joined: 24-August 09
  • Race :Elyos
  • Server:Undecided

Posted 27 January 2010 - 06:16 PM

Here's a question, does this have anything to do with those funny looking posts that appeared on the dev tracker a few days ago? I remember a few posts that didn't seem to lead anywhere and had a subject filled with random characters.
Does anyone remember this?
0

#15 Guest_Azxiana_*

  • Group: Guests

Posted 27 January 2010 - 06:17 PM

Moriwenne said:

Here's a question, does this have anything to do with those funny looking posts that appeared on the dev tracker a few days ago? I remember a few posts that didn't seem to lead anywhere and had a subject filled with random characters.
Does anyone remember this?


Sorry, I broke the dev tracker. :(
0

#16 User is offline   Zeragna Icon

  • Daeva
  • Pip
  • View blog
  • Group: Members
  • Posts: 22
  • Joined: 12-June 09
  • Character:Razandor
  • Legion:Sinister
  • Race :Asmodians
  • Server:Undecided

Posted 27 January 2010 - 06:37 PM

I knew something was up for google chrome found malware on the site warning me that if I went to aionsource I would be allowing access to whatever it was(said something like that). Glad to hear you guys got it and have amped the security


Keep up the good work!
0

#17 User is offline   Moriwenne Icon

  • Advanced Member
  • PipPip
  • View blog
  • Group: Members
  • Posts: 45
  • Joined: 24-August 09
  • Race :Elyos
  • Server:Undecided

Posted 28 January 2010 - 12:53 AM

Azxiana said:

Sorry, I broke the dev tracker. :(


Aha! Finally the truth!!!! ^^
Alright, for my part I forgive you and will not be asking for damages on account of me being...you know, all stressful and stuff because of the occurrence in relation to the current security situation involv....ahhhhhhhh chill :=)

Along with Zeragna I too would like to exalt chromes successful warning (due to the google flagging) that made me not access aionsource. Usually I ignore those warnings for well known sites but given the current situation It seemed wise not to do so and just wait.

All this security mess...such wackadoo.
0

#18 User is offline   Quasimodo Icon

  • Soldier
  • PipPip
  • Group: Members
  • Posts: 58
  • Joined: 05-January 10

Posted 29 January 2010 - 07:07 AM

Could you please confirm if your user database was compromised? I do know that passwords are safe - salted and stored as md5 hash - but email addresses aren't. Since there seems to be some link between emails used to register @aionsource and the recent phishing scam I would like to know if it's coincidence or not.
If db was compromised (or you can't rule it out with 100% certainty) it would be wise to send an email to all your users to be extra cautious as they are way more likely to be target of this scam.

This post has been edited by Quasimodo: 29 January 2010 - 02:57 PM

0

#19 User is offline   roguefrequency Icon

  • Advanced Member
  • PipPip
  • View blog
  • Group: Members
  • Posts: 39
  • Joined: 10-June 09

Posted 29 January 2010 - 02:56 PM

I just received the notification that Quasimodo suggested. I was going to ask if the passwords were salted and hashed, but he seems to think they are. Can an admin confirm that the passwords were stored as salted MD5 or SHA1s?

Thanks.

P.S. Forcing HTTPS for login and registration pages (that is, if your SSL cert was working correctly) would be a good idea.

This post has been edited by roguefrequency: 29 January 2010 - 03:05 PM

0

#20 User is offline   Steph Icon

  • Daeva
  • Pip
  • View blog
  • Group: Members
  • Posts: 18
  • Joined: 11-July 07

Posted 29 January 2010 - 02:58 PM

I would like to mention that your email has all of its links hidden behind click trackers like http://clicks.skem1.com/v/?u=blahblah. It was not possible to determine if your email was legit without clicking on the links and discovering where they went to.

Rather ironic, IMO.
DxDiag.txt - Click for technical computer information.
Cable Connection:
2 MB/s down (theoretical), 260 KB/s up (theoretical)
Connection Speed Test 1 | Connection Speed Test 2
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users