<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1624465548926375030</id><updated>2011-11-27T15:59:49.830-08:00</updated><category term='raiding'/><category term='mmo-champion'/><category term='arena tournament'/><category term='flash'/><category term='domains'/><category term='soccer'/><category term='security'/><category term='vulnerability'/><category term='brute force'/><category term='compendium'/><category term='cataclysm'/><category term='hacking'/><category term='ranks'/><category term='wow'/><category term='adobe'/><category term='battle.net'/><category term='wowarmory'/><category term='trojan'/><category term='game'/><category term='blizzard'/><category term='security checklist'/><category term='beta'/><category term='alpha'/><category term='warcraft'/><category term='march'/><category term='phishing'/><category term='gumblar'/><category term='scams'/><category term='guild'/><category term='hacked'/><category term='password stealing'/><category term='fake'/><category term='hacks'/><category term='keylogger'/><category term='diablo 3 phishing scam'/><category term='patching'/><category term='drive-by'/><category term='authenticators'/><category term='email'/><category term='remote auction house'/><category term='scam'/><category term='authenticator'/><category term='dictionary attack'/><category term='account theft'/><category term='account'/><category term='password'/><category term='wowmatrix'/><category term='strong password'/><title type='text'>Securing WoW</title><subtitle type='html'>Dedicated to advice on how to secure your World of Warcraft game account.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-5273086877564121127</id><published>2011-09-04T19:59:00.000-07:00</published><updated>2011-09-04T22:58:45.352-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='diablo 3 phishing scam'/><title type='text'>Diablo 3 Beta Phishing Season Begins</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://diablo3x.com/wp-content/uploads/2008/09/diablo-3-announce.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="165" src="http://diablo3x.com/wp-content/uploads/2008/09/diablo-3-announce.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;The scammers are out in force with the recent &lt;a href="http://us.blizzard.com/en-us/company/events/diablo3-announcement/index.html#beta:d3-overview"&gt;Diablo 3 beta&lt;/a&gt; opt-in announcement. &amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Phishing scams are very common around any Blizzard beta release announcement so it is time to be especially on your guard.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I received the following in my in-box today:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Greetings from Blizzard Entertainment!&lt;/blockquote&gt;&lt;blockquote&gt;We’re gearing up for the forthcoming launch of Diablo III and would like to  extend you an invitation toparticipate in the beta test. If you are interested in participating, you  need to have a Battle.net&amp;nbsp;account, which you can create on our Battle.net website.&lt;/blockquote&gt;&lt;blockquote&gt;We will flag you for access to the Diablo III beta test when we begin  admitting press. You do not need to&amp;nbsp;go through the opt-in process.&lt;/blockquote&gt;&lt;blockquote&gt;To secure your place among the first of Sanctuary’s heroes,Please use the  following template below to&amp;nbsp;verify your account and information via email.&lt;/blockquote&gt;&lt;blockquote&gt;* Name:&lt;br /&gt;* Battle.account name:&lt;br /&gt;* Password:&lt;br /&gt;* Country:&lt;br /&gt;* E-mail  Address:&lt;/blockquote&gt;&lt;blockquote&gt;Thanks and see you all in the Burning Hells!&lt;/blockquote&gt;&lt;br /&gt;The email claims to give you an express beta invite without having to go through the formal opt-in process. Naturally, this is an phishing attempt aimed at getting hold your valuable battle.net account details. The reply email address resolves into a d3-blizzard.com domain which, not-so-surprisingly, is registered in China:&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;pre&gt;Domain Name: D3-BLIZZARD.COM&lt;br /&gt;   Registrar: HICHINA ZHICHENG TECHNOLOGY LTD.&lt;br /&gt;   Whois Server: grs-whois.hichina.com&lt;br /&gt;   Referral URL: http://www.net.cn&lt;br /&gt;   Name Server: DNS27.HICHINA.COM&lt;br /&gt;   Name Server: DNS28.HICHINA.COM&lt;br /&gt;   Status: ok&lt;br /&gt;   Updated Date: 29-aug-2011&lt;br /&gt;   Creation Date: 29-aug-2011&lt;br /&gt;   Expiration Date: 29-aug-2012&lt;/pre&gt;&lt;br /&gt;Remember, Blizzard will never ask your for your battle.net password - be wary of any communications that requests this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-5273086877564121127?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/5273086877564121127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2011/09/diablo-3-beta-phishing-season-begins.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/5273086877564121127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/5273086877564121127'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2011/09/diablo-3-beta-phishing-season-begins.html' title='Diablo 3 Beta Phishing Season Begins'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-2080811573777293105</id><published>2011-04-05T22:20:00.000-07:00</published><updated>2011-04-05T22:23:23.852-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='scams'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='march'/><title type='text'>Top WoW Phishing Scams for March 2011</title><content type='html'>I have established a WoW phishing honeypot and I see a lot of active phishing scams. &amp;nbsp;I thought I would take the time to cover off the top two WoW phishing scams for March :&lt;br /&gt;&lt;br /&gt;&lt;b&gt;#1 Titled "Too Many Attempts Warning No.x" - 37% of WoW scams&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The most common phishing scam for March comes in the form of a straight text email that warns you that your account has been locked due to too many login attempts. It provides a link to restore your account, but naturally points to a fake battle.net site, where your account details are captured.&lt;br /&gt;&lt;br /&gt;&lt;div style="color: black; font-style: normal; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;-----------------------------------------------------------------------------&lt;/i&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;Dear customer,&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:&lt;br /&gt;&lt;br /&gt;Step 1: Secure Your ComputerIn the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.&lt;br /&gt;&lt;br /&gt;Step 2: Secure Your E-mail AccountAfter you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.&lt;br /&gt;&lt;br /&gt;Step 3: Restore access to Your accountWe now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: xxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;br /&gt;&lt;br /&gt;If you still have questions or concerns after following the steps above, feel free to contact Customer Support at xxxxxxxxxxxxxxxxxxx.&lt;br /&gt;&lt;br /&gt;Sincerely,&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;The Battle.net Account Team&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;Online Privacy Policy&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;&lt;/i&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;-----------------------------------------------------------------------------&lt;/i&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;#2 Titled "Account Change" - 26% of WoW scams&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This scam attempts to scare you into thinking that your contact information has been illegally modified and entices you to log in to a fake site to verify your account information.&lt;br /&gt;&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;-----------------------------------------------------------------------------&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;Hello,&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt; This is an automated notification regarding your Battle.net account. Some or all of your contact information was recently modified through the Account Management website.&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;br /&gt;*** If you made recent account changes, please disregard this automatic notification.&lt;br /&gt;*** If you did NOT make any changes to your account, we recommend you log in to xxxxxxxxxxxxxxxxxxxx review your account settings.&lt;br /&gt;&lt;br /&gt;If you cannot sign into Account Management using the link above, or if unauthorized changes continue to happen, please contact Blizzard Billing &amp;amp; Account Services for further assistance.&lt;br /&gt;&lt;br /&gt;Billing &amp;amp; Account Services can be reached at 1-800-59-BLIZZARD (1-800-592-5499 Mon-Fri, 8AM-8PM Pacific Time) or at &lt;a href="mailto:billing@blizzard.com"&gt;billing@blizzard.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Account security is solely the responsibility of the accountholder. Please be advised that in the event of a compromised account, Blizzard representatives will typically lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;The Battle.net Support Team&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;Blizzard Entertainment&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;a href="http://www.blizzard.com/support"&gt;www.blizzard.com/support&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;Online Privacy Policy&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;&lt;i&gt;-----------------------------------------------------------------------------&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Other active scams including a "7 days free access offer", "investigations on the sale/trade of your game account" and various "compensation" emails. &amp;nbsp;I have also started to see scams for LOTRO and RIFT. &amp;nbsp;You know that you have made it as an MMO when you see active phishing scams - sad, but true.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;Learn more about the mechanics of these scams.&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-2080811573777293105?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/2080811573777293105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2011/04/top-wow-phishing-scams-for-march-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2080811573777293105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2080811573777293105'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2011/04/top-wow-phishing-scams-for-march-2011.html' title='Top WoW Phishing Scams for March 2011'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-8084578329985393123</id><published>2011-03-27T20:04:00.000-07:00</published><updated>2011-03-28T17:38:19.897-07:00</updated><title type='text'>Trust Me, I am a Security Pro</title><content type='html'>&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://harryallen.info/wp-content/uploads/2009/07/trust-me.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://harryallen.info/wp-content/uploads/2009/07/trust-me.jpg" width="199" /&gt;&lt;/a&gt;&lt;/div&gt;Everyone you talk to seems to have their own special advice on how to avoid having your game account hacked. Unfortunately, there is both good and bad advice given. While I normally blog about the good advice, I decided to take some time and dispel some of the common IT security myths out there.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;Myth: You can't get hacked by simply visiting a web site&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;People often claim that you can't be hacked by just visiting a web site and that you need to download and install something by clicking on it.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;This is false. You can indeed pick up a trojan/keylogger simply by browsing to a web site that has malicious content which takes advantage of a vulnerability and, depending on the vulnerability, you may not even know that you have been infected.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Vulnerabilities can be found in the operating system, your browser, your flash player, your media player and in any piece of software that runs on your machine. Many of these vulnerabilities, if exploited, allow remote code execution which can be used to automatically download malicious software without your interaction or knowledge.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;Myth:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;Running Firefox/Mozilla means I am safe&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Internet Explorer has traditionally been one of the most exploited browsers, mainly because of its historical prevalence. These days, Firefox is the most popular browser amongst WoW users (44%), with IE (22%) and Chrome (21%) coming next... and the hackers have followed. Many &lt;a href="http://www.mozilla.org/security/known-vulnerabilities/"&gt;vulnerabilities&lt;/a&gt; and exploits have been discovered with Firefox.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Other browsers are not perfect either. For example, a competition at a security conference found that&amp;nbsp;&lt;a href="http://www.zdnet.com/blog/hardware/ie8-safari-and-firefox-fall-at-pwn2own-2010/7807"&gt;most browsers could be easily compromised&lt;/a&gt;&amp;nbsp;with Google's Chrome being the last one standing.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;Myth:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;Run 'noscript' and you will be fine&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/noscript/"&gt;Noscript&lt;/a&gt; is an addon for firefox that allows you to block flash and javascript on web pages. It helps alleviate issues such as &lt;a href="http://securingwow.blogspot.com/2010/09/adobe-flash-vulnerability.html"&gt;flash vulnerabilities&lt;/a&gt; that are often announced.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Noscript is a very good idea in concept but it breaks most web sites, especially modern web sites that require flash and javascript (which is nearly all of them). &amp;nbsp;This is the traditional trade-off you get with security. &amp;nbsp;Noscript provides some excellent protection but you will not get the full functionality from web sites without extensive whitelisting.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;Myth:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;I run a Mac and Macs don't get malware&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Yes they do - just not as much malware as what Windows users can expect.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;However, you can still get &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;phished&lt;/a&gt;. &amp;nbsp;Given that many of the account hacks are a result of phishing attacks, Mac users need to remember that they are just as vulnerable to these as any other user.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;Myth:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;Pick up free anti-virus software and you will be right&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Honestly, you get what you pay for. &amp;nbsp;As someone that comes from the anti-virus industry, I know the investment required to produce a top-quality anti-virus solution. &amp;nbsp;Free AV is good, but paid-for AV is better. It ultimately comes down to your tolerance of risk and whether you are prepared to pay for better protection. You can see a list of AV products and their ratings at &lt;a href="http://www.av-test.org/certifications"&gt;avtest.org&lt;/a&gt;.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;Myth:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;I have an Authenticator therefore I am protected 100%&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;No security will provide 100% protection. Whenever you hear someone say that something is 100% secure then don't believe a word of it.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;The authenticator recently fell &lt;a href="http://securingwow.blogspot.com/2010/02/authenticator-hack-is-your-account.html"&gt;victim&lt;/a&gt; to some malware that intercepted the authenticator's code and sent it off to the hacker.&amp;nbsp;But don't despair - the authenticator is still one of the best prevention mechanisms you can buy.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;b&gt;I don't have an authenticator, I don't run AV, I don't have a firewall and I have never been hacked.&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;You should go and buy yourself a lottery ticket. Seriously, you are very lucky.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;As discussed earlier, you can get infected simply by surfing a page that features some malformed objects designed to exploit a vulnerability in some piece of software on your PC.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;But you avoid bad sites such as hack sites or porn sites, right?&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Well, even the good sites get hacked to become a source of malware. This is becoming a much more common method of malware propagation.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;i&gt;Visit our &lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;10 Easy WoW Security Steps&lt;/a&gt; post to learn more about securing your WoW account.&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-8084578329985393123?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/8084578329985393123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2011/03/trust-me-i-am-security-pro.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/8084578329985393123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/8084578329985393123'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2011/03/trust-me-i-am-security-pro.html' title='Trust Me, I am a Security Pro'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-7780721079027488760</id><published>2010-11-11T20:50:00.000-08:00</published><updated>2010-11-11T20:53:58.465-08:00</updated><title type='text'>Blizzard Adds Dial-in Authenticator</title><content type='html'>&lt;a href="http://us.media2.battle.net/cms/blog_header/PVUKCVHC717I1289351747695.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="151" src="http://us.media2.battle.net/cms/blog_header/PVUKCVHC717I1289351747695.jpg" width="400" /&gt;&lt;/a&gt;Blizzard has &lt;a href="http://us.battle.net/wow/en/blog/1113829#blog"&gt;announced&lt;/a&gt; a new security service for US players called the Dial-In Authenticator.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Verdana, sans-serif; font-size: 12px; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;"Similar to the&amp;nbsp;Battle.net Authenticator&amp;nbsp;and&amp;nbsp;Mobile Authenticator application, the Battle.net Dial-in Authenticator is an optional tool that provides an additional layer of security against unauthorized account access. The Battle.net Dial-in Authenticator is not a physical token or application run on a mobile device, however. Instead, it is a free opt-in service that will actively monitor an account and request additional authorization from the user when a potentially unauthorized login attempt occurs."&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The service asks you to nominate a phone and a PIN. &amp;nbsp;When your account is accessed from a different IP address it will ask you to authenticate by dialling a US toll-free number from your nominated phone and entering your PIN and a single-use security code. &amp;nbsp;The service is optional and best of all, it is free.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is a good addition to the security arsenal, especially for those users that move around a lot and don't have a hardware authenticator. Remember that good security is made up of several layers of protection, and this offers yet another layer.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;More information can be found at the official &lt;a href="http://us.blizzard.com/support/article.xml?locale=en_US&amp;amp;tag=dialinauth&amp;amp;rhtml=true"&gt;Battle.net Dial-in Authenticator FAQ&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-7780721079027488760?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/7780721079027488760/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/11/blizzard-adds-dial-in-authenticator.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/7780721079027488760'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/7780721079027488760'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/11/blizzard-adds-dial-in-authenticator.html' title='Blizzard Adds Dial-in Authenticator'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-6485150035601101556</id><published>2010-09-19T21:19:00.000-07:00</published><updated>2010-09-20T05:00:03.411-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cataclysm'/><category scheme='http://www.blogger.com/atom/ns#' term='authenticators'/><category scheme='http://www.blogger.com/atom/ns#' term='guild'/><category scheme='http://www.blogger.com/atom/ns#' term='ranks'/><title type='text'>Guild Ranks To Include Authenticators</title><content type='html'>&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://www.blogcdn.com/wow.joystiq.com/media/2010/09/authenticatorguildcontrolrlt.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="140" src="http://www.blogcdn.com/wow.joystiq.com/media/2010/09/authenticatorguildcontrolrlt.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Image courtesy of WoW Insider&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;The latest news from the Cataclysm beta program, via&amp;nbsp;&lt;a href="http://wow.joystiq.com/2010/09/15/cataclysm-beta-guild-ranks-can-be-set-to-require-authenticator/"&gt;WoW Insider&lt;/a&gt;, is that guild masters have the option tp set guild ranks to require the player to have an &lt;a href="http://us.blizzard.com/store/search.xml?q=authenticator"&gt;authenticator&lt;/a&gt; on their account.&lt;br /&gt;&lt;br /&gt;The obvious use for this is to have the guild master set this on any guild rank that has guild bank access. This will help reduce the chance of the guild bank being stripped in the event of an account compromise.&lt;br /&gt;&lt;br /&gt;However, guild masters can go further by mandating that all of their raiders, and even all of their members, have an authenticator. &amp;nbsp;Too often we see raiding disrupted when key players have had their accounts hacked. &amp;nbsp;Just imagine the inconvenience when a progression raid gets cancelled because the main tank is waiting for his/her account to be restored after a hack.&lt;br /&gt;&lt;br /&gt;This is a great initiative by Blizzard and will surely give people one less excuse for players to adopt this technology.&lt;br /&gt;&lt;br /&gt;Some of the more common excuses for people not having an authenticator include:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;"I don't have a credit card" or "They don't deliver to my country" - download the &lt;a href="https://us.battle.net/account/support/mobile-auth-download.html"&gt;free authenticator app&lt;/a&gt; for your mobile phone or ask a guild mate to purchase one for you and mail it to you&lt;/li&gt;&lt;li&gt;"I am too smart/cautious to get hacked" or "I have never been hacked" - Vulnerabilities in your operating system and applications can very easily result in you downloading a keylogger by simply visiting a legitimate web site that may have been compromised. &amp;nbsp;For well-written exploits, no user interaction is required to become infected - you just need to visit a compromised web site. &amp;nbsp;Your game login and password is then shipped off to the bad guys. &amp;nbsp;See the recent &lt;a href="http://securingwow.blogspot.com/2010/09/adobe-flash-vulnerability.html"&gt;Adobe&lt;/a&gt; example. Additionally, &lt;a href="http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html"&gt;common passwords can be attacked&lt;/a&gt; by automated processes - you don't even need a keylogger on your system to fall victim.&lt;/li&gt;&lt;li&gt;"I own a Mac" - Yes, you are less likely to pick up a keylogger since most are written for Windows however, owning a Mac won't stop you falling for &lt;a href="http://securingwow.blogspot.com/2009_09_01_archive.html"&gt;phishing attacks&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;"I pay for this service, authenticators should be free" - I doubt that Blizzard are making any real revenue on a product that sells for $6.50 - they are just aiming to recover costs. &amp;nbsp;Think of the amount of money you have paid for your subscription to date, and then ask yourself if it is worth the extra $6.50 to reduce the chance of all your hard work being compromised.&lt;/li&gt;&lt;li&gt;"It is inconvenient to type in the code" - the extra ten seconds required to login is a small price to pay for the extra security that it provides.&lt;/li&gt;&lt;li&gt;"&lt;a href="http://securingwow.blogspot.com/2010/02/authenticator-hack-is-your-account.html"&gt;Authenticators have been hacked&lt;/a&gt;" - well, it was not the authenticator that was hacked, it was more that a keylogger picked up the authenticator code and, in real time, shipped it off to the bad guys. &amp;nbsp;This was a fairly sophisticated attack and required people power to do the real time processing. &amp;nbsp;Keep in mind that security is never 100% and that the authenticator is just making it more difficult for the bad guys to get into your account. &amp;nbsp;An authenticator is still a very effective tool in your security arsenal.&lt;/li&gt;&lt;li&gt;"I don't care, Blizzard can restore my account after a few days" - if you are in a raiding guild then the delay in reporting and restoring your account may mean you miss out on raiding, potentially impacting your entire raid group. &amp;nbsp;This may even put your guild membership at risk if this happens regularly.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Check out &lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;Ten Easy Steps to Securing WoW&lt;/a&gt;&amp;nbsp;for more security tips.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-6485150035601101556?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/6485150035601101556/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/09/guild-levels-to-include-authenticators.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6485150035601101556'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6485150035601101556'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/09/guild-levels-to-include-authenticators.html' title='Guild Ranks To Include Authenticators'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-175895408016128868</id><published>2010-09-16T18:34:00.000-07:00</published><updated>2010-09-16T19:25:25.111-07:00</updated><title type='text'>Adobe Announces New Flash Vulnerability</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_3sAE3l3Wnqs/S3XcExbpBKI/AAAAAAAABlw/RBelVOJ9dQo/s1600/adobe.jpeg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_3sAE3l3Wnqs/S3XcExbpBKI/AAAAAAAABlw/RBelVOJ9dQo/s320/adobe.jpeg" /&gt;&lt;/a&gt;&lt;/div&gt;Adobe Systems has recently disclosed a vulnerability in their Flash Player 10.1.82.76 for Windows, Mac, Linux and Solaris.  The vulnerability allows the execution of code from a specially crafted PDF or Flash file. Adobe mention that they have seen this being actively exploited.&lt;br /&gt;&lt;br /&gt;Put simply, this type of vulnerability could see you become infected with a keylogger simply by browsing a web site that has been compromised. We have seen WoW keyloggers installed via this type of Adobe vulnerability before in &lt;a href="http://securingwow.blogspot.com/2010/06/patch-your-flash.html"&gt;June&lt;/a&gt; and &lt;a href="http://securingwow.blogspot.com/2010/02/adobe-flash-vulnerability-fix.html"&gt;February&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Adobe has not released a patch for this as yet, but plan to have something available during the week of September 27.&lt;br /&gt;&lt;br /&gt;You can reduce the chance of becoming subject to this attack by patching your flash player as soon as a patch is released and by running a PDF/flash blocker such as &lt;a href="http://noscript.net/"&gt;noscript&lt;/a&gt; in the meantime.&lt;br /&gt;&lt;br /&gt;You can find more information on this at the &lt;a href="http://www.adobe.com/support/security/advisories/apsa10-03.html"&gt;Adobe Security Advisory&lt;/a&gt; site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-175895408016128868?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/175895408016128868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/09/adobe-flash-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/175895408016128868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/175895408016128868'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/09/adobe-flash-vulnerability.html' title='Adobe Announces New Flash Vulnerability'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_3sAE3l3Wnqs/S3XcExbpBKI/AAAAAAAABlw/RBelVOJ9dQo/s72-c/adobe.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-8571141276631741237</id><published>2010-08-08T20:52:00.000-07:00</published><updated>2010-08-08T20:59:37.601-07:00</updated><title type='text'>Blizzard steps up password education</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/TANVzF3LnoI/AAAAAAAABnA/Lg27dY29hG4/s1600/login.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="198" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/TANVzF3LnoI/AAAAAAAABnA/Lg27dY29hG4/s200/login.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Blizzard has stepped up its security education program, with a big emphasis on password security. Via both a game login message and a recent blue post, Blizzard stresses the importance of having a different password for your World Of Warcraft game account and making sure that your password is a strong one.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://forums.worldofwarcraft.com/thread.html?topicId=26435493403&amp;amp;sid=1"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;BORNAKK&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;: We have been helping players deal with account theft for years now, and unfortunately, roughly a third of players make a very basic security mistake: using the same password for all of their security needs.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;b&gt; If you are serious about protecting your account and your personal security, your Battle.net password should be different from your email account password -- or other personal passwords for that matter!&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;No one wants account thieves rooting around in their personal email, address book, and contact lists. Too often we see thieves breaking in to this information because their target has used the same password across multiple types of accounts. Not only can this give thieves access to your account, it can lead to compromises far outside of Battle.net as well.&lt;br /&gt;&lt;br /&gt;It’s immensely important that everyone use separate passwords for separate applications, including games. Secure passwords have both numeric and alphabetical values, and are usually at least 10 characters in length.&amp;nbsp;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;Now this is very sound advice and is something that I have been highlighting for &lt;a href="http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html"&gt;quite some time&lt;/a&gt;. &amp;nbsp;One third of hacks being a result of using the same password across multiple sites and applications, such as email and fan sites, is a fairly alarming statistic. &amp;nbsp;This suggests that there are a lot of 3rd party systems out there that are being hacked to farm WoW user accounts and passwords.&lt;br /&gt;&lt;br /&gt;Also note that WoW does not impose restrictions on password attempts so dictionary attacks are also a real possibility on your account. &amp;nbsp;This is a great reason for selecting a strong, complex password.&lt;br /&gt;&lt;br /&gt;Oddly enough, Bornakk does not mention the use of an authenticator. The Blizzard authenticator is a great security mechanism and something that every WoW gamer should possess.&lt;br /&gt;&lt;br /&gt;You can read more on choosing secure passwords and dictionary attacks on your WoW account &lt;a href="http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-8571141276631741237?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/8571141276631741237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/08/blizzard-steps-up-password-education.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/8571141276631741237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/8571141276631741237'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/08/blizzard-steps-up-password-education.html' title='Blizzard steps up password education'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_3sAE3l3Wnqs/TANVzF3LnoI/AAAAAAAABnA/Lg27dY29hG4/s72-c/login.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-1915325887787466879</id><published>2010-07-12T19:15:00.000-07:00</published><updated>2010-07-12T19:21:48.803-07:00</updated><title type='text'>ESRB mistakenly releases player email addresses</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.esrb.org/privacy/images/privacy_symbol_edge.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://www.esrb.org/privacy/images/privacy_symbol_edge.gif" /&gt;&lt;/a&gt;&lt;/div&gt;Many people have asked me how the bad guys get hold of our battle.net login id's - the same bad guys that inundate us with WoW phishing emails and do dictionary attacks on our battle.net logins.&lt;br /&gt;&lt;br /&gt;The team at wow.com have published an &lt;a href="http://www.wow.com/2010/07/12/esrb-unintentionally-exposes-email-addresses-of-people-who-filed"&gt;article&lt;/a&gt; on how the Entertainment Software Rating Board (ESRB) managed to mistakenly release almost 1000 email addresses of wow players that wrote to them to complain about Blizzard's plan to use real names on the official wow forums. &lt;br /&gt;&lt;br /&gt;This email list is a gold mine to the bad guys, especially where these email addresses match up with battle.net ID's. &amp;nbsp;There is little doubt that these 1000 email addresses will end up on &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;WoW phishing&lt;/a&gt; lists and that they may also be targets for &lt;a href="http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html"&gt;WoW dictionary attacks&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;If you recently wrote to ESRB and you used the same email address as your battle.net ID then please consider changing your battle.net ID to a new, unique email address.&lt;br /&gt;&lt;br /&gt;You can read more about the mess-up at &lt;a href="http://www.wow.com/2010/07/12/esrb-unintentionally-exposes-email-addresses-of-people-who-filed"&gt;Wow.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-1915325887787466879?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/1915325887787466879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/07/esrb-mistakenly-releases-player-email.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1915325887787466879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1915325887787466879'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/07/esrb-mistakenly-releases-player-email.html' title='ESRB mistakenly releases player email addresses'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-4794695030986841284</id><published>2010-06-07T17:41:00.000-07:00</published><updated>2010-06-07T17:59:16.462-07:00</updated><title type='text'>Patch Your Flash!</title><content type='html'>Blizzard has released an &lt;a href="http://forums.worldofwarcraft.com/thread.html?sid=1&amp;amp;topicId=25170612979"&gt;advisory&lt;/a&gt; warning all players to update their Adobe Flash Player. &amp;nbsp;Adobe Flash Player 10.0.45.2 has a vulnerability that may allow an attacker to take control of your machine.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="color: #00c0ff; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;LUCYTR: A critical vulnerability has been discovered in Adobe Flash Player 10.0.45.2 and Adobe Reader/Acrobat 9.x, and could potentially be used to target World of Warcraft players and accounts. The newest available version of Adobe Flash 10.1, Release Candidate 7 (available at&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #00c0ff; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #00c0ff; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;a href="http://labs.adobe.com/technologies/flashplayer10/" style="color: #ffb019; font-weight: bold;" target="_new"&gt;http://labs.adobe.com/technol&lt;wbr&gt;&lt;/wbr&gt;ogies/flashplayer10/&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #00c0ff; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;), does not appear to contain this vulnerability, and we recommend that everyone upgrade their Flash player as soon as possible. Earlier versions of Adobe Reader and Acrobat, specifically version 8.x, do not appear to contain this vulnerability, either.&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #00c0ff; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/blockquote&gt;Adobe reports that it has seen evidence of this vulnerability already being exploited. &lt;br /&gt;&lt;br /&gt;Although the technical details are still sketchy, it is likely to require a specially crafted flash or PDF file to trigger the vulnerability. &amp;nbsp;We have seen this type of attack on Adobe flash before - where you can be infected by a keylogger/trojan by simply visiting a legitimate web page that renders this malicious code or redirects to a malicious site containing the code.&lt;br /&gt;&lt;br /&gt;Unfortunately, Adobe don't seem to have this fix on their auto-update system so be sure to visit &lt;a href="http://www.adobe.com/support/security/advisories/apsa10-01.html"&gt;Adobe's Security Page&lt;/a&gt;&amp;nbsp;and patch your machine with v10.1 today.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-4794695030986841284?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/4794695030986841284/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/06/patch-your-flash.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/4794695030986841284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/4794695030986841284'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/06/patch-your-flash.html' title='Patch Your Flash!'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-4706995817070650722</id><published>2010-06-03T01:30:00.000-07:00</published><updated>2010-06-03T19:28:59.505-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cataclysm'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='remote auction house'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><category scheme='http://www.blogger.com/atom/ns#' term='warcraft'/><category scheme='http://www.blogger.com/atom/ns#' term='beta'/><title type='text'>Phishers Ramp Up Their WoW Assault</title><content type='html'>&lt;div&gt;Phishers have begun targeting the remote auction house and cataclysm betas in the latest wave of WoW account phishing spam.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In the first example, unsuspecting users receive an email promoting the features and benefits of the remote auction house and invite them to participate in the beta by clicking on a download now link.  The link takes them to a fake battle.net login site where their game details are captured.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A sample email is shown below:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_3sAE3l3Wnqs/TAdqitXAUBI/AAAAAAAABnY/w8uxZ2Uvsn0/s1600/remoteauctionphish.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 372px; height: 400px;" src="http://4.bp.blogspot.com/_3sAE3l3Wnqs/TAdqitXAUBI/AAAAAAAABnY/w8uxZ2Uvsn0/s400/remoteauctionphish.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5478464616243679250" /&gt;&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A second type of phishing email is targeting the Cataclysm beta opt-in. Users are sent an email reminding them to update their system specifications to be eligible for a beta invite by logging into battle.net.  Naturally, the battle.net link is a fake site designed to collect your account credentials:&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_3sAE3l3Wnqs/TAdtW5ReC_I/AAAAAAAABng/Mseq183fNxE/s1600/phishingcatabeta.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 358px;" src="http://3.bp.blogspot.com/_3sAE3l3Wnqs/TAdtW5ReC_I/AAAAAAAABng/Mseq183fNxE/s400/phishingcatabeta.JPG" border="0" alt="" id="BLOGGER_PHOTO_ID_5478467711818140658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Be wary of any email that pretends to come from Blizzard and check the URL of any linked site before entering your account credentials. Visit our &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;anatomy of a phishing site&lt;/a&gt; post for information on how to spot phishing emails and better protect your game account.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Let us know if you have received emails scams like these.&lt;/i&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-4706995817070650722?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/4706995817070650722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/06/phishers-target-remote-auction-house.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/4706995817070650722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/4706995817070650722'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/06/phishers-target-remote-auction-house.html' title='Phishers Ramp Up Their WoW Assault'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_3sAE3l3Wnqs/TAdqitXAUBI/AAAAAAAABnY/w8uxZ2Uvsn0/s72-c/remoteauctionphish.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-5084659710711473299</id><published>2010-05-30T20:33:00.000-07:00</published><updated>2010-06-03T19:29:40.733-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='strong password'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='brute force'/><category scheme='http://www.blogger.com/atom/ns#' term='warcraft'/><category scheme='http://www.blogger.com/atom/ns#' term='dictionary attack'/><title type='text'>Suffer mortals, as your pathetic password betrays you!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/TANVzF3LnoI/AAAAAAAABnA/Lg27dY29hG4/s1600/login.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 200px; height: 200px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/TANVzF3LnoI/AAAAAAAABnA/Lg27dY29hG4/s320/login.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5477315908047969922" /&gt;&lt;/a&gt;One of the things we often don't put much thought into is password selection.  Usually it is a loved-one's name or an easily remembered string of characters. Unfortunately, a poor choice of password can dramatically increase the chance of your game account being hacked.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In an &lt;a href="http://www.imperva.com/news/press/2010/01_21_Imperva_Releases_Detailed_Analysis_of_32_Million_Passwords.html"&gt;analysis&lt;/a&gt; performed by Imperva of 32 million leaked passwords from rockyou.com, it was found that nearly 50% of passwords consist of people's names, slang words, dictionary words or trivial passwords.  The study estimates that if a hacker used the top 5000 passwords in a &lt;a href="http://en.wikipedia.org/wiki/Dictionary_attack"&gt;dictionary attack&lt;/a&gt;, it would take, on average, only 111 attempts to break into a given account.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.worldofwarcraft.com/"&gt;World of Warcraft&lt;/a&gt; does not have an account or IP address lockout after any number of bad password attempts.  This gives the bad guys an opportunity to dictionary attack your account.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Assuming that the WoW account password frequency distribution is similar and that a hacker could try a password every 2 seconds - it would take an average of only 3.7 minutes to hack an account.&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Obviously the time required to hack your account is going to vary based on the strength of your game password so choosing an uncommon and complex password is key.  The report lists the following as the most commonly used passwords:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;123456&lt;/li&gt;&lt;li&gt;12345&lt;/li&gt;&lt;li&gt;123456789&lt;/li&gt;&lt;li&gt;password&lt;/li&gt;&lt;li&gt;iloveyou&lt;/li&gt;&lt;li&gt;princess&lt;/li&gt;&lt;li&gt;rockyou (or 'warcraft' in our case)&lt;/li&gt;&lt;li&gt;1234567&lt;/li&gt;&lt;li&gt;12345678&lt;/li&gt;&lt;li&gt;abc123&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Other common passwords include monkey, qwerty, 654321 and first names of people.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;How can you better protect your WoW account?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;First, buy yourself an &lt;a href="http://blizzard.com/store"&gt;authenticator&lt;/a&gt; and add another layer of security to your account.  A dictionary attack is largely rendered useless with the addition of a hardware token.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Second, if you don't have an authenticator or wish to be more secure then choose a &lt;a href="http://www.microsoft.com/protect/fraud/passwords/create.aspx"&gt;strong password&lt;/a&gt;.  Strong passwords contain numeric and non-standard characters and do not have any strings that contain dictionary words.  They should be at 12-14 characters in length. However, don't bother too much with upper and lower case characters since the battle.net authentication service does not differentiate between upper/lower case.  An example of strong WoW password would be something like "sdm#6wua2pa9jk".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you have trouble remembering a strong password (and most of us will) then try to create something similar from a memorable saying.  For example, Professor Putricide's "Bad news everyone! I don't think I'm going to make it" becomes "bne!idtig2mi" as your password.  Such a password will be close to impossible to dictionary attack and will take a long time to &lt;a href="http://en.wikipedia.org/wiki/Brute_force_attack"&gt;brute force&lt;/a&gt; attack.  Don't share this password with anyone and don't use this password on any other service - keep it unique to WoW only.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Finally, create a unique email address as your battle.net login.  Hackers need to be able to guess or steal your username so making this complex will certainly hinder their efforts.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Update: If you want to read more about hackers stealing account usernames and passwords, check out the &lt;a href="http://www.symantec.com/connect/blogs/44-million-stolen-gaming-credentials-uncovered"&gt;Symantec&lt;/a&gt; article where they recently discovered 44 million stolen gaming credentials.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A little bit of effort with your password selection will make hacking your precious account significantly more difficult... and don't forget to get yourself an authenticator.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-5084659710711473299?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/5084659710711473299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/5084659710711473299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/5084659710711473299'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html' title='Suffer mortals, as your pathetic password betrays you!'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_3sAE3l3Wnqs/TANVzF3LnoI/AAAAAAAABnA/Lg27dY29hG4/s72-c/login.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-6676672579649411116</id><published>2010-05-21T17:25:00.000-07:00</published><updated>2010-05-21T18:30:23.990-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gumblar'/><category scheme='http://www.blogger.com/atom/ns#' term='hacked'/><category scheme='http://www.blogger.com/atom/ns#' term='mmo-champion'/><title type='text'>MMO-Champion hacked</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://static.mmo-champion.com/mmoc/images/mmochampavatar.gif"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 85px; height: 85px;" src="http://static.mmo-champion.com/mmoc/images/mmochampavatar.gif" border="0" alt="" /&gt;&lt;/a&gt;The team at the popular WoW fan site MMO-champion have &lt;a href="http://www.mmo-champion.com/news-2/oh-god-mmo-champion-got-hacked/"&gt;announced that their site was recently hacked&lt;/a&gt;. What happened here and how can you best protect yourself against malicious code on legitimate web pages?&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The malicious code was &lt;a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojjsredirr.html"&gt;Gumblar&lt;/a&gt; - a malicious piece of javascript that was placed on their pages.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;How did the malicious code get there?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is a question that has not been answered by the web site owners.   However, it is likely to be one of the following causes:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;The mmo-champion.com site was hacked and the code was manually planted there by the attacker. There are multiple ways this could have happened, but one common way is via &lt;a href="http://en.wikipedia.org/wiki/SQL_injection"&gt;SQL-Injection&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;One of their admins was infected on their own PC and their FTP login details were used by the malware to log in to the mmo-champion.com web servers and automatically infect their files. &lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Hackers often target legitimate web sites, especially high traffic sites, so that they get the widest exposure to their malware. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;What is the malicious code designed to do?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;According to a &lt;a href="http://blog.scansafe.com/journal/2009/5/14/gumblar-qa.html"&gt;Gumbar Q&amp;amp;A&lt;/a&gt;, the malicious code redirects a user to a malicious web site that contains specially crafted PDF or flash files that automatically infect your machine if you do not have your Adobe flash player patched.  The malware that it installs can redirect your google searches and replace search results with links to malicious sites.  It also harvests FTP information from your machine so that it can try to automatically inject code on other web servers.  Finally, it can open a back door so that your machine can be controlled remotely.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Could I have been infected from MMO-champion?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The team at mmo-champion claim that the malicious code was only on their site for 30 mins before it was detected, shut down and subsequently cleaned.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you browsed the site in that time, you probably would have noticed an attempt to redirect your browser to another web site.  Many browsers have in-built blocking mechanisms so you may have seen a big red message on your browser advising you that you are about to visit a malicious web site.  If you proceeded, and the malicious web site was online at the time, then you would have been exposed to malicious pdf or flash files.  If, and only if, your &lt;a href="http://securingwow.blogspot.com/2010/02/adobe-flash-vulnerability-fix.html"&gt;Adobe flash player&lt;/a&gt; was not patched, then these malicious files may have automatically executed.  If you were running up-to-date and mainstream antivirus products then it should have been detected and stopped at this stage.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The short answer is, you may have been infected but you would have needed to have no antivirus (or poor antivirus), no recent patching of your Adobe flash player and would have needed to visit the site in the 30 mins when the code was there.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you think your machine is infected then try this free web-based scanner - &lt;a href="http://housecall.trendmicro.com/"&gt;Housecall&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Does it steal my WoW account info?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;No, but if you were infected then you still need to clean it off your machine since it may compromise any FTP sites that you might visit, install a backdoor and your search engine results may be replaced with malicious sites.  This is not the type of malware that you want on your PC.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Would the firefox 'noscript' add-on help?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Probably, although if you are a regular mmo-champion visitor then you would have been likely to nominate their site as a trusted site in noscript - resulting in noscript having no effect. Noscript is a great security measure, but it breaks a lot of sites.  It is the old security vs usability trade-off.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;What can I do to protect myself against these attacks?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Make sure your software is fully patched - this includes your operating system (OS), browser, flash player, javascript, etc.  Most people just worry about patching their OS, but there are many other avenues for exploiting software vulnerabilities on your PC.&lt;/li&gt;&lt;li&gt;Make sure you run reputable anti-virus on your system - and make sure it is always updated.&lt;/li&gt;&lt;li&gt;Don't ignore your browser when it tells you that the site you are about to go to is potentially dangerous.&lt;/li&gt;&lt;li&gt;Get yourself an authenticator.  Even though this malware is not written to steal WoW information, the next one might be. An authenticator is a last line of defense, and may prove to be your savior should all else fail.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Finally, don't assume you can't get infected by malware without user interaction - you can!  You can pick up malware simply by visiting a web page and you won't even know it is happening.  This is why you need several defense mechanisms in your security arsenal.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-6676672579649411116?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/6676672579649411116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/05/mmo-champion-hacked.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6676672579649411116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6676672579649411116'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/05/mmo-champion-hacked.html' title='MMO-Champion hacked'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-6476530635729987679</id><published>2010-04-25T15:28:00.000-07:00</published><updated>2010-06-03T19:27:54.902-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><category scheme='http://www.blogger.com/atom/ns#' term='arena tournament'/><title type='text'>Beware 2010 Arena Tournament scams</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.worldofwarcraft.com/news/images/09-03/arena2009.png"&gt;&lt;img style="float: right; margin: 0px 0px 10px 10px; cursor: pointer; width: 128px; height: 109px;" src="http://www.worldofwarcraft.com/news/images/09-03/arena2009.png" alt="" border="0" /&gt;&lt;/a&gt;Scammers are increasing their efforts with the recent announcement of the &lt;a href="http://www.worldofwarcraft.com/pvp/tournament/news.xml"&gt;2010 Arena Tournament&lt;/a&gt;. I am starting to see phishing emails that tell you all about the new arena tournament and provides you with a convenient "Register Now" link.  This link takes you to a fake login page and steals any details that you enter.&lt;br /&gt;&lt;br /&gt;The fake login page will capture your username and password. The site then redirects you to the genuine US battle.net login page and tournament registration.  Like an ATM skimming device attack, the user rarely detects that a scam has taken place until their account is stripped.&lt;br /&gt;&lt;br /&gt;An example of these emails:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_3sAE3l3Wnqs/S9TEUic_tUI/AAAAAAAABm4/LROUiAfhSU8/s1600/email1.GIF"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 327px; height: 400px;" src="http://4.bp.blogspot.com/_3sAE3l3Wnqs/S9TEUic_tUI/AAAAAAAABm4/LROUiAfhSU8/s400/email1.GIF" alt="" id="BLOGGER_PHOTO_ID_5464208105032103234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;Want to learn more about how to spot phishing scams? Check out our post covering the &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;anatomy of a WoW phishing site&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-6476530635729987679?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/6476530635729987679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/04/beware-2010-arena-tournament-scams.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6476530635729987679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6476530635729987679'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/04/beware-2010-arena-tournament-scams.html' title='Beware 2010 Arena Tournament scams'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_3sAE3l3Wnqs/S9TEUic_tUI/AAAAAAAABm4/LROUiAfhSU8/s72-c/email1.GIF' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-7070223801401081845</id><published>2010-04-21T23:38:00.000-07:00</published><updated>2010-05-14T22:28:45.403-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='domains'/><category scheme='http://www.blogger.com/atom/ns#' term='compendium'/><title type='text'>WoW Phishing Domain Compendium</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/S8_wuNsbIYI/AAAAAAAABmw/cmbWy44ZPgg/s1600/nofish.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 150px; height: 150px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/S8_wuNsbIYI/AAAAAAAABmw/cmbWy44ZPgg/s200/nofish.jpg" alt="" id="BLOGGER_PHOTO_ID_5462849549764338050" border="0" /&gt;&lt;/a&gt;World of Warcraft phishing scams are becoming commonplace these days.   I wrote an article last year which covered the &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;anatomy of a WoW phishing site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;To give you some idea on how widespread the issue is, I have put together a collection of the known illegal phishing domains seen so far this year. This list is largely based on a WoW spam &lt;a href="http://en.wikipedia.org/wiki/Honeypot_%28computing%29"&gt;honeypot&lt;/a&gt; that I have established and further supplemented by tips from players.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Warning - do not visit these sites!&lt;/span&gt;&lt;span style="font-style: italic;"&gt; They are included here to help educate gamers on what to look for with regards to phishing URL's. Some are still active and may feature malware/keyloggers. I have purposely mangled the URL so that you don't accidently click on the sites.  If you feel tempted then stop reading now - you have been warned.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;WoW Phishing Domain List&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;http_://www.accountmanagement-worldofwarcraft.net&lt;br /&gt;&lt;br /&gt;http_://www.wor1dcfwarcraft.com&lt;br /&gt;http_://www.worldrofwarcraft.net&lt;br /&gt;http_://www.wor1dofwancreft.com&lt;br /&gt;http_://www.wor1dofwancrvft.com&lt;br /&gt;http_://www.wor1dofwororaft.com&lt;br /&gt;http_://www.worldofwarcrarrft.com&lt;br /&gt;http_://we-io8.worldofwarcraftftc.com&lt;br /&gt;http_://www.worldofwacacraft.com&lt;br /&gt;&lt;br /&gt;http_://www.worldofwarcraft-accountadmin-battle.net&lt;br /&gt;http_://www.worldofwarcraft-account-athonticate-account-authonticate.com&lt;br /&gt;http_://www.worldofwarcraftaccount-billing.com&lt;br /&gt;http_://www.worldofwarcraft-account-checkwarning.com&lt;br /&gt;http_://www.worldofwarcraftaccountsecurity.com&lt;br /&gt;http_://www.worldofwarcraft-instruction-account.com&lt;br /&gt;http_://www.worldofwarcraft-certification-account.com&lt;br /&gt;http_://www.worldofwarcraft-supports-account.com&lt;br /&gt;http_://www.worldofwarcraft-subscription-security.com&lt;br /&gt;http_://www.worldofwarcraft-account-investigate.com&lt;br /&gt;http_://www.worldofwarcraft-account-authorization.com&lt;br /&gt;http_://www.worldofwarcraft-account-authontisate.com&lt;br /&gt;http_://www.worldofwarcraft-account-inspect.com&lt;br /&gt;http_://www.worldofwarcraft-account.com&lt;br /&gt;http_://www.worldofwarcrauft-account.com&lt;br /&gt;http_://www.worldofwxarcraft-test.com&lt;br /&gt;http_://www.worldofwarcrcft-test.com&lt;br /&gt;http_://www.worldofwarcruaft-account.com&lt;br /&gt;http_://www.worldofwariraft-manage.com&lt;br /&gt;http_://www.worldofwarcranft-login.com&lt;br /&gt;http_://www.worldofwarcraft-battles-account.com&lt;br /&gt;http_://www.worldofwarcraft-login-admin.com&lt;br /&gt;http_://www.worldofwarcraft-security-billing.com&lt;br /&gt;http_://www.worldofwarcraft-account.info&lt;br /&gt;http_://www.worldofwarcraft-battle-admin.net&lt;br /&gt;http://www.worldofwarcraft-account-authoriration.com/&lt;br /&gt;  &lt;br /&gt;http_://www.wowaccountmobilephone.com&lt;br /&gt;&lt;br /&gt;http_://www.management-adminis-blizzard.com&lt;br /&gt;&lt;br /&gt;http_://www.battlenetaccount.com&lt;br /&gt;http_://battle.arena-award-management.com&lt;br /&gt;&lt;br /&gt;http_://www.blizzard-feedback.net&lt;br /&gt;http_://www.blizzard-forums.com&lt;br /&gt;http_://www.blizzardaccount-management.com&lt;br /&gt;http_://www.blizzard-account-login-management.com&lt;br /&gt;http_://www.blizzardaccount-billreview.com&lt;br /&gt;http_://www.blizzardaccount-support.com&lt;br /&gt;http_://www.blizzardbattle-management.net&lt;br /&gt;http_://www.blizzardbattle-bill.net&lt;br /&gt;http_://www.blizzardhosting.net&lt;br /&gt;&lt;br /&gt;http://www.us-battle-blizzard.net/&lt;br /&gt;http://www.info-battle.net/&lt;br /&gt;http://www.security-accounts-blizzard.com/&lt;br /&gt;http://battle.tournament-administration.com/&lt;br /&gt;http://www.management-ccount-blizzard.com/&lt;br /&gt;&lt;br /&gt;These domains are constantly changing - as one is shut down or blocked, another appears. As you can see, there are a lot of variations.&lt;br /&gt;&lt;br /&gt;These URL's are usually associated with a spam email telling you that your WoW account has been suspended.  The email asks you to click on a link (which may be disguised as a valid game site URL) which takes you to these malicious URL's to phish for your game details.  The link could also arrive as an in-game mail or whisper.&lt;br /&gt;&lt;br /&gt;As always, don't click on links in emails that appear to come from Blizzard and don't believe the random in-game whispers that tell you that you have won a rare spectral tiger or that your account has been suspended and that you immediately need to log in in to unlock it.&lt;br /&gt;&lt;br /&gt;For more information on how to look out for phishing attempts visit the official &lt;a href="http://us.battle.net/security/types.html#phishing"&gt;Battle.net security site&lt;/a&gt; and our &lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;top 10 security steps&lt;/a&gt; article.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;If you see any other fake WoW phishing domains then report them to polar at guildox dot com&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-7070223801401081845?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/7070223801401081845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/04/2010-wow-phishing-domains.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/7070223801401081845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/7070223801401081845'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/04/2010-wow-phishing-domains.html' title='WoW Phishing Domain Compendium'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_3sAE3l3Wnqs/S8_wuNsbIYI/AAAAAAAABmw/cmbWy44ZPgg/s72-c/nofish.jpg' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-3023848589931185160</id><published>2010-03-15T22:03:00.000-07:00</published><updated>2010-03-17T20:14:36.187-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='raiding'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='soccer'/><category scheme='http://www.blogger.com/atom/ns#' term='warcraft'/><title type='text'>Kicking Goals in the World of Warcraft</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/S57ciQIHj6I/AAAAAAAABmI/5yc4wFVFnJs/s1600-h/Soccer_Indoor.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 120px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/S57ciQIHj6I/AAAAAAAABmI/5yc4wFVFnJs/s320/Soccer_Indoor.jpg" alt="" id="BLOGGER_PHOTO_ID_5449035080167559074" border="0" /&gt;&lt;/a&gt;Is a member of your family or close friend crazy about a game called &lt;a href="http://www.worldofwarcraft.com/"&gt;World of Warcraft&lt;/a&gt;? Do they lock themselves in their room, playing the game for hours and refusing to take phone calls or talk to you? It's time to investigate this seemingly strange behavior by drawing parallels to the universal sport of soccer/football.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What is the World of Warcraft?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;World of Warcraft (WoW) is a highly popular multi-player online game with over 11 million subscribers.  Unlike traditional stand-alone computer games, online games feature interaction with hundreds and sometimes thousands of other real human players.  In WoW, these players form 'raid groups' of up to 25 players to tackle an in-game dungeon.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What exactly is a WoW raid group?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Think of a raid group as a soccer team and think of an dungeon as a series of matches where the team plays against computer controlled opponents, also known as "bosses". The raid group works as a team to win these matches - there is a nominated raid leader (the coach and captain) who gives instructions and coordinates the team.  The team consists of attackers (&lt;a href="http://internetgames.about.com/od/glossary/g/dps.htm"&gt;DPS&lt;/a&gt; members) which are assigned to attack and damage the boss and defenders (&lt;a href="http://geekdictionary.computing.net/define/tank"&gt;tanks&lt;/a&gt; and healers) which aim to distract the boss and heal up the team so that the attackers can do their job. Each team member is assigned a specific role and, like any sporting match, all players need to be present for the full game time and perform their assigned duties to the best of their ability. Many raid groups also have reserve players that sit on the bench, waiting to be called in to replace players.&lt;br /&gt;&lt;br /&gt;Team members will communicate with each other via a microphone and headphones connected to the PC - you may see your partner sporting a very ugly set of headphones, looking something like a submarine commander. This is the equivalent of the on field communication that happens between players, the captain and the coach.&lt;br /&gt;&lt;br /&gt;Each of the matches takes typically between 5-10 mins.  During this time, there is no way to pause the game - all raiding takes place in real time.  After each match, the raid leader will analyse the performance of the team, make adjustments and then re-engage until the "boss" is defeated - just like any good soccer coach.&lt;br /&gt;&lt;br /&gt;A full raid session may consist of many boss kills and can easily go for several hours.  Raids are typically scheduled at specific times each week.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;So why won't they come and have dinner when they are called?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Players are required to be present for the full duration of the raid.  Like any sporting match, you cannot just leave the game whenever you decide.  Many of the matches require all members of the raid to play at their best - any single member that steps away from a match and goes 'away from keyboard - AFK' without pre-warning the raid leader will very likely cause the match to be lost - upsetting the other 24 players in the raid.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_3sAE3l3Wnqs/S57dud3RrdI/AAAAAAAABmo/bV-EBJ2cSRQ/s1600-h/redcard.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 200px;" src="http://3.bp.blogspot.com/_3sAE3l3Wnqs/S57dud3RrdI/AAAAAAAABmo/bV-EBJ2cSRQ/s320/redcard.jpg" alt="" id="BLOGGER_PHOTO_ID_5449036389525073362" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Why can't I talk to them for 5 mins during a raid?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Players will either be participating in the match or will be listening to the raid leader, taking instructions before the next match. Either way, the player needs to give the raid his/her full attention.&lt;br /&gt;&lt;br /&gt;It is best to wait for a "bio" break to speak with them. Bio breaks are scheduled breaks where the player can get a coffee or visit the bathroom.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;What happens when all of the bosses are defeated&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This only occurs for the very elite teams and only for certain periods of the year. The creators of WoW are constantly adding new bosses and content to the game to keep players entertained. Most raiding groups always have something bigger to aim for.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;I asked them to go out this weekend but they claim they are rostered. What's the deal?&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Just like your weekend soccer games, players announce their availability to play typically 1-2 weeks ahead of the scheduled raid. A team roster is usually published by the raid leader a few days before the raid.  Players that made themselves available and subsequently get rostered are expected to play.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Why bother raiding - it's just a computer game?  Why don't they go outside and kick a ball instead?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The real thrill of raiding is the feeling of progression, team work and accomplishment - just like the feeling you get after winning a sporting final.&lt;br /&gt;&lt;br /&gt;Each completed boss encounter awards the group with several items of equipment, otherwise known as 'loot'. This loot comes in the form of items that the player can wear and may be a new piece of armor, weapon or other similar item.  Loot items increase the power of individual players and are highly sought after.  Winning loot in a raid is a significant achievement - very similar to that sporting trophy you display with pride on the mantle piece.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;So if I have to engage in conversation with my WoW gamer, what should I be asking?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.cup2010.info/trophy/trophy.jpg"&gt;&lt;img style="float: right; margin: 10pt 10px 10px 10pt; cursor: pointer; width: 120px;" src="http://www.cup2010.info/trophy/trophy.jpg" alt="" border="0" /&gt;&lt;/a&gt;Stun your WoW gamer by asking them any of the following questions:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;What role do you play in WoW raids?  A tank, healer or DPS? Why did you chose that role?&lt;/li&gt;&lt;li&gt;What new loot did you get from your raid today? Show me your character.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;What boss are you currently working on? How did you go?&lt;/li&gt;&lt;li&gt;Your dinner is almost ready, when can you take your next extended bio break?&lt;/li&gt;&lt;/ul&gt;Ask these and your fellow raider is bound to be most impressed with your understanding of their gaming world.&lt;br /&gt;&lt;br /&gt;Finally, just remember that calling your WoW player for dinner or asking them to do chores in the middle of the raid is likely to be met with some serious resistance. Would David Beckham or Ronaldo leave the field mid-game to put the trash out? At least wait for half-time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-3023848589931185160?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/3023848589931185160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2009/09/kicking-goals-in-world-of-warcraft.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/3023848589931185160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/3023848589931185160'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2009/09/kicking-goals-in-world-of-warcraft.html' title='Kicking Goals in the World of Warcraft'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_3sAE3l3Wnqs/S57ciQIHj6I/AAAAAAAABmI/5yc4wFVFnJs/s72-c/Soccer_Indoor.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-9216065567356865060</id><published>2010-03-01T18:13:00.000-08:00</published><updated>2010-03-01T18:50:28.891-08:00</updated><title type='text'>Update: Keylogger websites shut down</title><content type='html'>The main infection source of the recent &lt;a href="http://securingwow.blogspot.com/2010/02/authenticator-hack-is-your-account.html"&gt;anti-authenticator keylogger/trojan&lt;/a&gt; appears to have been shut down.  The main places of infection - the fake site wowmatrixf._com and other associated fake addon sites, including cursea._com and deadlybossmodss._com - are no longer online.  (Victims were lured to these fake sites via Google advertisements)&lt;br /&gt;&lt;br /&gt;We can breathe a sigh of relief but don't become complacent.  This trojan/keylogger is likely to spring up somewhere else. Be cautious of what you download and execute from any web site. Addons should not require an installer package to execute.  Be very suspicious of anything that asks you to "run a program". Follow our &lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;10 Easy Steps&lt;/a&gt; to increase protection.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;If you notice that these fake sites pop up in another spot then let us know.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-9216065567356865060?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/9216065567356865060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/03/update-keylogger-websites-shut-down.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/9216065567356865060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/9216065567356865060'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/03/update-keylogger-websites-shut-down.html' title='Update: Keylogger websites shut down'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-4448750260783506344</id><published>2010-02-28T18:18:00.000-08:00</published><updated>2010-11-15T15:31:40.820-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='keylogger'/><category scheme='http://www.blogger.com/atom/ns#' term='authenticator'/><category scheme='http://www.blogger.com/atom/ns#' term='fake'/><category scheme='http://www.blogger.com/atom/ns#' term='wowmatrix'/><category scheme='http://www.blogger.com/atom/ns#' term='hacked'/><category scheme='http://www.blogger.com/atom/ns#' term='account'/><category scheme='http://www.blogger.com/atom/ns#' term='game'/><category scheme='http://www.blogger.com/atom/ns#' term='blizzard'/><title type='text'>Authenticator hack - is your account still safe?</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SmUryhDYDfI/AAAAAAAABj0/05zWd4L9aMM/s200/authenticator.jpeg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" src="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SmUryhDYDfI/AAAAAAAABj0/05zWd4L9aMM/s200/authenticator.jpeg" style="cursor: pointer; float: right; height: 200px; margin: 0pt 0pt 10px 10px; width: 148px;" /&gt;&lt;/a&gt;The big security news of the weekend is that &lt;a href="http://forums.wow-europe.com/thread.html?topicId=12730404058&amp;amp;sid=1&amp;amp;pageNo=1"&gt;Blizzard has confirmed&lt;/a&gt; a man-in-the-middle attack that is being used to hack accounts that are using an authenticator.&lt;br /&gt;&lt;br /&gt;Let me state up front that this is not a reason to throw your authenticator away nor should it be an excuse for not getting one. The authenticator is a very sound device - but it is, and will always be, just one of many security mechanisms that you should use to help secure your account.  It is what us IT security guys call "layered security" - more on this in a moment.&lt;br /&gt;&lt;br /&gt;The attack itself requires a keylogger/trojan.  The keylogger, once installed on your system, logs your game user name, password AND authenticator code.  It proceeds to post this information off to a rogue server so that the attacker can use this information in near real-time to access your game account.  In the meantime, it sends an incorrect code to the battle.net authentication server from your machine - resulting in an "incorrect login" type message from the game.  It does this so that you don't consume the one-time-use code that the authenticator provides.&lt;br /&gt;&lt;br /&gt;Now it was only a matter of time before we saw this kind of attack.  More and more people have been using authenticators. In a survey of over 90 gamers at &lt;a href="http://securingwow.blogspot.com/"&gt;securingwow.blogspot.com&lt;/a&gt;, 84% of them claim to have an authenticator attached to their game account.  This tells us that more and more people are now running with an authenticator - reducing the pool size of "easy" victims.&lt;br /&gt;&lt;br /&gt;The bad guys are now being forced to step up the sophistication of their attacks and have started targeting those with authenticators. We are bound to see many more keyloggers with this capability in the near future.  Additionally, &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;phishing attacks&lt;/a&gt; will also begin to operate in the same fashion - asking you to type in your authentication code, along with your other game account details, posting the info off to the attacker - who uses them in real time - leaving you with a "system unavailable" message and a soon-to-be-stripped game account.  If we don't have these mechanisms in WoW phishing sites already then I can assure you that they are not far away.&lt;br /&gt;&lt;br /&gt;So how do you prevent it from happening? It all comes down to minimizing the chance of being infected with a keylogger in the first place.   One of the many tenets of IT Security is that "no sercurity system is 100% effective".  Anyone that tells you otherwise does not know what they are preaching or they are trying to sell you some snake-oil. In this case, we can't rely on authenticators to be the only defense mechansim - here are &lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;ten simple steps&lt;/a&gt; you can do to reduce the chance of your  game account being compromised:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Don't share your game password  with anyone and pick a password that is not easily guessed&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don't  use the same password for subscribing to fan sites&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Keep  your operating system, browser and other software (especially Adobe Flash) fully patched - start  with &lt;a href="http://windowsupdate.microsoft.com/"&gt;Windows Update&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Run  a reputable antivirus product, preferably a full internet security  suite with a firewall and keystroke encryption&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don't click  on email attachments, especially when you don't know the sender&lt;/li&gt;&lt;li&gt;Don't  download and run executable files from web pages&lt;/li&gt;&lt;li&gt;Don't enter  your game password into any web site other than the official game sites&lt;/li&gt;&lt;li&gt;Don't  enter your game password to a legitimate Blizzard web site from a PC  that may be compromised&lt;/li&gt;&lt;li&gt;Be very suspicious if an addon requires  some form of install package to be run&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Invest in a Blizzard  authenticator or install the Battlenet authenticator application on your phone&lt;/li&gt;&lt;/ol&gt;Try to follow all of these recommendations - not just one or two points.&lt;br /&gt;&lt;br /&gt;In this specific case, the keylogger was &lt;a href="http://www.worldofraids.com/topic/15642-authenticator-keylogger-source-fake-wowmatrix-website/?s=d219116fe3c0fcbf6546164eeb5f36ed"&gt;reportedly&lt;/a&gt; delivered via a fake site for the &lt;a href="http://www.wowmatrix.com/"&gt;Wowmatrix&lt;/a&gt; addon manager.  The site was created to look and feel like wowmatrix.com but, instead of downloading and installing the addon manager, the keylogger was installed instead.  Our recommendations #6 and #9 talk about being "very suspicious" of add-ons that require an installer to run and avoid running executable files from web sites.&lt;br /&gt;&lt;br /&gt;The bottom line is that keyloggers and phishing sites are here to stay. Don't rely on your authenticator to protect you 100% of the time - but don't throw it out either. It still forms a very strong part of your layered defense against the bad guys.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Post a comment - we would like to hear from you if you have fallen victim to this attack.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-4448750260783506344?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/4448750260783506344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/02/authenticator-hack-is-your-account.html#comment-form' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/4448750260783506344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/4448750260783506344'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/02/authenticator-hack-is-your-account.html' title='Authenticator hack - is your account still safe?'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_3sAE3l3Wnqs/SmUryhDYDfI/AAAAAAAABj0/05zWd4L9aMM/s72-c/authenticator.jpeg' height='72' width='72'/><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-8915177583461705671</id><published>2010-02-12T14:47:00.000-08:00</published><updated>2010-02-12T14:58:41.180-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='keylogger'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='flash'/><category scheme='http://www.blogger.com/atom/ns#' term='drive-by'/><title type='text'>Adobe Flash Vulnerability Fix</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_3sAE3l3Wnqs/S3XcExbpBKI/AAAAAAAABlw/RBelVOJ9dQo/s1600-h/adobe.jpeg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 129px; height: 129px;" src="http://4.bp.blogspot.com/_3sAE3l3Wnqs/S3XcExbpBKI/AAAAAAAABlw/RBelVOJ9dQo/s320/adobe.jpeg" alt="" id="BLOGGER_PHOTO_ID_5437494099666601122" border="0" /&gt;&lt;/a&gt;Adobe has released a patch for the latest Flash vulnerability.  Adobe Flash is used by the majority of browsers to display dynamic content on web pages. This vulnerability can potentially lead to automatic keylogger downloads by visiting a web site that has a specially crafted flash file embedded in its pages. This is known as a 'drive-by download' - one in which malware can be downloaded and installed without you knowing.&lt;br /&gt;&lt;br /&gt;While I am yet to see this specific vulnerability exploited, it is only a matter of time before it is. I have seen previous Flash vulnerabilities exploited to download keyloggers from popular WoW fan sites.&lt;br /&gt;&lt;br /&gt;So - play it safe - visit the official &lt;a href="http://get.adobe.com/flashplayer/"&gt;Adobe Flash download site&lt;/a&gt; and update your flash player.&lt;br /&gt;&lt;br /&gt;Be sure to visit our &lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;10 Easy Steps&lt;/a&gt; page to further protect your WoW account.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-8915177583461705671?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/8915177583461705671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/02/adobe-flash-vulnerability-fix.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/8915177583461705671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/8915177583461705671'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/02/adobe-flash-vulnerability-fix.html' title='Adobe Flash Vulnerability Fix'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_3sAE3l3Wnqs/S3XcExbpBKI/AAAAAAAABlw/RBelVOJ9dQo/s72-c/adobe.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-2838082135748881361</id><published>2010-01-29T17:45:00.000-08:00</published><updated>2010-02-09T16:01:21.515-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='account theft'/><category scheme='http://www.blogger.com/atom/ns#' term='security checklist'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacked'/><category scheme='http://www.blogger.com/atom/ns#' term='account'/><category scheme='http://www.blogger.com/atom/ns#' term='blizzard'/><category scheme='http://www.blogger.com/atom/ns#' term='battle.net'/><title type='text'>Blizzard Launches Battle.Net Security Site</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/S2OQF1FkhUI/AAAAAAAABlo/4TZofCT1TrE/s1600-h/blizzaccountsecurity.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/S2OQF1FkhUI/AAAAAAAABlo/4TZofCT1TrE/s320/blizzaccountsecurity.JPG" alt="" id="BLOGGER_PHOTO_ID_5432344005363139906" border="0" /&gt;&lt;/a&gt;Blizzard has launched their official security awareness page offering helpful advice on what you can do to safeguard your computer, how to spot scams, info on the adverse effects of buying gold, and tried-and-true methods to help prevent account compromises.&lt;br /&gt;&lt;br /&gt;The specifically provide:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;A Security Checklist - covering preventative measures that you should be taking&lt;/li&gt;&lt;li&gt;Type of Account Thefts - listing the common methods used to hack accounts&lt;/li&gt;&lt;li&gt;Advice on what to do if you get hacked&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Be sure to check it out at &lt;a href="http://us.battle.net/security/"&gt;http://us.battle.net/security/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As always, having a Blizzard Authenticator is one of the best methods of hack prevention.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-2838082135748881361?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/2838082135748881361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/01/blizzard-launches-battlenet-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2838082135748881361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2838082135748881361'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/01/blizzard-launches-battlenet-security.html' title='Blizzard Launches Battle.Net Security Site'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_3sAE3l3Wnqs/S2OQF1FkhUI/AAAAAAAABlo/4TZofCT1TrE/s72-c/blizzaccountsecurity.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-1500969831837758336</id><published>2010-01-15T16:39:00.000-08:00</published><updated>2010-01-15T16:53:15.097-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wowarmory'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>The Armory Phishing Scam</title><content type='html'>The new and improved wowarmory has brought with it opportunity for scammers seeking to trick you into disclosing your wow game passwords.  Check out the full coverage at wow.com on this latest scam:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.wow.com/2010/01/15/beware-of-wow-armory-phishing-scams/"&gt;http://www.wow.com/2010/01/15/beware-of-wow-armory-phishing-scams/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As always, never enter your game username/password into a site that is not "blizzard.com" or "worldofwarcraft.com" and get yourself an authenticator today!&lt;br /&gt;&lt;br /&gt;If you have had a close encounter with a wow phishing scam then post and comment and let us know about it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-1500969831837758336?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/1500969831837758336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/01/armory-phishing-scam.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1500969831837758336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1500969831837758336'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/01/armory-phishing-scam.html' title='The Armory Phishing Scam'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-2748291481970487970</id><published>2010-01-12T18:04:00.000-08:00</published><updated>2010-01-15T16:52:10.145-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cataclysm'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='beta'/><category scheme='http://www.blogger.com/atom/ns#' term='alpha'/><title type='text'>Beware of Cataclysm Phishing Scams</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_3sAE3l3Wnqs/S00ropAQSjI/AAAAAAAABlg/TzjIbhUfbxE/s1600-h/world-of-warcraft-cataclysm.jpg"&gt;&lt;img style="margin: 0pt 0px 10px 10pt; float: right; cursor: pointer; width: 180px; " src="http://2.bp.blogspot.com/_3sAE3l3Wnqs/S00ropAQSjI/AAAAAAAABlg/TzjIbhUfbxE/s320/world-of-warcraft-cataclysm.jpg" alt="" id="BLOGGER_PHOTO_ID_5426041103252998706" border="0" /&gt;&lt;/a&gt;With the recent announcement of the Catalysm alpha, users are warned not to fall victim to phishing scams.&lt;br /&gt;&lt;br /&gt;Be aware that if you receive an email inviting you to join the Cataclysm testing cycle then it will most likely be a scam.  Cataclysm open beta does not exist as yet.&lt;br /&gt;&lt;br /&gt;Do not enter your game username and password into any sites that may link from any email claiming to be an official Blizzard invite to Cataclysm.&lt;br /&gt;&lt;br /&gt;If you see a Cataclysm phishing scam then feel free to share your comments on it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-2748291481970487970?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/2748291481970487970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2010/01/beware-cataclysm-phishing-scams.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2748291481970487970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2748291481970487970'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2010/01/beware-cataclysm-phishing-scams.html' title='Beware of Cataclysm Phishing Scams'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_3sAE3l3Wnqs/S00ropAQSjI/AAAAAAAABlg/TzjIbhUfbxE/s72-c/world-of-warcraft-cataclysm.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-2723739318726847860</id><published>2009-12-11T03:03:00.001-08:00</published><updated>2010-03-01T18:51:11.447-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><title type='text'>Latest phishing scam</title><content type='html'>The latest phishing scam is an email titled "Battle.net Account – Password Change Notice" telling you that your password has been changed and if you did not make the change then you should visit the blizzard FAQ at a URL of:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;http_://www.worldofwarcra&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;rr&lt;/span&gt;&lt;span style="font-style: italic;"&gt;ft.net/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Spot the scam?  I hope so (emphasis added).&lt;br /&gt;&lt;br /&gt;This is a &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;traditional wow phishing scam&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-2723739318726847860?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/2723739318726847860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2009/12/latest-phishing-scam.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2723739318726847860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/2723739318726847860'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2009/12/latest-phishing-scam.html' title='Latest phishing scam'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-6650890422261681520</id><published>2009-10-01T04:37:00.000-07:00</published><updated>2009-10-01T23:57:33.899-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><title type='text'>New phishing scam</title><content type='html'>You receive an in-game whisper promising a new mount by visiting:&lt;br /&gt;&lt;br /&gt;http://www.blizzus-wow.com/&lt;br /&gt;&lt;br /&gt;This is a scam phishing site designed to steal your account information.  In fact, it appears to be the very same set of pages that are discussed &lt;a href="http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html"&gt;in my previous blog&lt;/a&gt; about how to identify WoW phishing sites.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-6650890422261681520?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/6650890422261681520/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2009/10/recent-phishing-scam.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6650890422261681520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/6650890422261681520'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2009/10/recent-phishing-scam.html' title='New phishing scam'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-1884531655949708895</id><published>2009-09-16T17:32:00.000-07:00</published><updated>2009-09-22T18:45:18.090-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='wow'/><category scheme='http://www.blogger.com/atom/ns#' term='hacks'/><category scheme='http://www.blogger.com/atom/ns#' term='password stealing'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>The Anatomy of a WoW Phishing Site</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_3sAE3l3Wnqs/Srbv8xpHzeI/AAAAAAAABk0/2dZNWxPZ52Y/s1600-h/nofish.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 150px; height: 150px;" src="http://3.bp.blogspot.com/_3sAE3l3Wnqs/Srbv8xpHzeI/AAAAAAAABk0/2dZNWxPZ52Y/s320/nofish.jpg" alt="" id="BLOGGER_PHOTO_ID_5383754231965011426" border="0" /&gt;&lt;/a&gt;Password stealing via a bogus phishing site is a common tactic for those wanting to break into your WoW account. Let's explore the workings of an illegal WoW phishing site and give you some tips on how to spot such fakes.  &lt;span style="font-style: italic;"&gt;Note that the phishing site discussed here is no longer online.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Bait&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You receive an in-game whisper or mail telling you that you are eligible to trial an all-new mount.  All you have to do to claim this mount is to register on an "official" site and the mount will be sent to your account. The message contains the URL of a site to visit - in this case it is "http://www.blizzard-forums.com".  Eagerly, you race off to claim your special mount.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Hook&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You enter the URL to your browser and you get the following site:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/SrGGFtOrbpI/AAAAAAAABj8/44qhBPoSab0/s1600-h/hackss.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: none; cursor: pointer; width: 200px; height: 200px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/SrGGFtOrbpI/AAAAAAAABj8/44qhBPoSab0/s320/hackss.gif" alt="" id="BLOGGER_PHOTO_ID_5382230462283083410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You enter your account name and password, hit submit and are taken through to the following page:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SrGGxV2BqUI/AAAAAAAABkE/mh4pI48joEY/s1600-h/hackss3.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: none; cursor: pointer; width: 200px; height: 232px;" src="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SrGGxV2BqUI/AAAAAAAABkE/mh4pI48joEY/s400/hackss3.gif" alt="" id="BLOGGER_PHOTO_ID_5382231211919911234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;They are now asking for my email address and they want to confirm my account's secret question and answer.  You enter the required information and hit submit.  You finish on the following success screen:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_3sAE3l3Wnqs/SrGHgJXX41I/AAAAAAAABkM/hS4dzKYS9VY/s1600-h/hackss4.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: none; cursor: pointer; width: 300px; height: 300px;" src="http://3.bp.blogspot.com/_3sAE3l3Wnqs/SrGHgJXX41I/AAAAAAAABkM/hS4dzKYS9VY/s400/hackss4.gif" alt="" id="BLOGGER_PHOTO_ID_5382232016023970642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Application Successful! You just need to wait for your mount to arrive in my in-game mail - but it never does.  However, next time you log in to the game you find that all of your characters have been stripped of their worldly possessions, you have no gold and your guild's bank has been raided.&lt;br /&gt;&lt;br /&gt;You have been the unfortunate victim of a phishing attack!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Where did I go wrong?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;How could you have prevented falling for such a trick?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Phishing"&gt;Phishing&lt;/a&gt; is a form of social engineering - a tactic used by the bad guys to lure in unsuspecting victims to steal personal information - in this case your account login details.&lt;br /&gt;&lt;br /&gt;The first part of this attack was to offer something that was highly desirable - in this case the promise of a new, special, in-game mount.  Other attacks use the promise of special access to beta new expansion content or tell you your account has been locked as a result of a hack and you need to follow certain steps to unlock it.  It can come as an in-game whisper, an in-game mail or a regular email.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Rule#1: Be highly suspicious of anything that is offered for free or anything email that claims your account has been compromised&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next, you were given the URL of something that turned out to be a phishing site.  But how can you tell if it is official or not?&lt;br /&gt;&lt;br /&gt;The two sites, one bogus and one legitimate:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/SrGGFtOrbpI/AAAAAAAABj8/44qhBPoSab0/s1600-h/hackss.gif"&gt;&lt;img style="margin: 0pt 0pt 5px 5px; float: none; cursor: pointer; width: 180px; height: 232px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/SrGGFtOrbpI/AAAAAAAABj8/44qhBPoSab0/s320/hackss.gif" alt="" id="BLOGGER_PHOTO_ID_5382230462283083410" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SrGJ2tucF_I/AAAAAAAABkU/K0JV4cJ1Pok/s1600-h/hackss2.gif"&gt;&lt;img style="margin: 0pt 0pt 5px 5px; float: none; cursor: pointer; width: 180px; height: 232px;" src="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SrGJ2tucF_I/AAAAAAAABkU/K0JV4cJ1Pok/s400/hackss2.gif" alt="" id="BLOGGER_PHOTO_ID_5382234602764769266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Spot the difference? No?&lt;br /&gt;&lt;br /&gt;It is extremely difficult to spot the difference.   It is very easy for an attacker to copy the images, layout and text of the legitimate site - and do it perfectly.&lt;br /&gt;&lt;br /&gt;However, there are key things to look for in the URLs. The official Blizzard site is a secured SSL site, with the URL prefixed with "https://".  The site is also part of the battle.net domain (in this case us.battle.net):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SrGLIMRSJ5I/AAAAAAAABkc/tE3QOr8x47E/s1600-h/URL2.gif"&gt;&lt;img style="cursor: pointer; width: 400px; height: 27px;" src="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SrGLIMRSJ5I/AAAAAAAABkc/tE3QOr8x47E/s400/URL2.gif" alt="" id="BLOGGER_PHOTO_ID_5382236002533386130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The bogus phishing site has no &lt;a href="http://en.wikipedia.org/wiki/Transport_Layer_Security"&gt;SSL&lt;/a&gt;, no "https://" and is not part of a battle.net, worldofwarcraft.com or blizzard.com domain:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_3sAE3l3Wnqs/SrGLOOpF0-I/AAAAAAAABkk/by2i5GHqJ5Y/s1600-h/URL1.gif"&gt;&lt;img style="cursor: pointer; width: 400px; height: 26px;" src="http://1.bp.blogspot.com/_3sAE3l3Wnqs/SrGLOOpF0-I/AAAAAAAABkk/by2i5GHqJ5Y/s400/URL1.gif" alt="" id="BLOGGER_PHOTO_ID_5382236106249327586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In fact, looking up the blizzard-forums.com domain ownership, it was found to be owned by an individual in Shanghai, China.&lt;br /&gt;&lt;br /&gt;The real  irony is that the official Blizzard warning is still shown on the bogus phishing site:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_3sAE3l3Wnqs/SrGMgvU5t6I/AAAAAAAABks/mIFSioeblBI/s1600-h/warning.gif"&gt;&lt;img style="cursor: pointer; width: 375px; height: 87px;" src="http://3.bp.blogspot.com/_3sAE3l3Wnqs/SrGMgvU5t6I/AAAAAAAABks/mIFSioeblBI/s400/warning.gif" alt="" id="BLOGGER_PHOTO_ID_5382237523772290978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rule#2: Do not type your game account username/password into any web site other than worldofwarcraft.com (wow-europe.com), blizzard.com and battle.net.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rule#3: Check for a secured "https:" session on such sites when entering your username/password - while not a 100% guarantee of legitimacy, phishing sites generally don't bother with &lt;a href="http://en.wikipedia.org/wiki/Identity_certificate"&gt;digital certificates&lt;/a&gt; and https&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Some other things that could tip a user off with this example were:&lt;br /&gt;&lt;br /&gt;1. Nothing happened if you clicked on any of the language options on the first page - the bad guys were a bit lazy and could not be bothered writing the multi-language support for the site.  They were obviously only targeting the english speaking community.&lt;br /&gt;&lt;br /&gt;2. Many of the links on the subsequent pages were incomplete and broken.&lt;br /&gt;&lt;br /&gt;3. Entering a dummy username and password still allowed you to progress to the subsequent "success" pages - there was obviously no way to check the username/password combination.&lt;br /&gt;&lt;br /&gt;4. There was extremely poor grammar on many of the subsequent pages.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Final words&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A word of warning regarding the URL - I recently saw a similar phishing attack that cleverly used the URL of "www.promotion-battle.net".  At a glance it looks like a battle.net domain but it is not.  The domain is promotion-battle.net and this domain is definitely not an official website.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rule#4: Just because the letters battle.net or worldofwarcraft.com or blizzard.com appear somewhere in the URL does not make it an official site.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Official login sites should have the format:&lt;br /&gt;&lt;br /&gt;https://[prefix].battle.net/...&lt;br /&gt;or&lt;br /&gt;&lt;/span&gt;&lt;span&gt;https://[prefix].worldofwarcraft.com/...&lt;br /&gt;or&lt;br /&gt;&lt;/span&gt;&lt;span&gt;https://[prefix].wow-europe.com/...&lt;br /&gt;or&lt;br /&gt;&lt;/span&gt;&lt;span&gt;https://[prefix].blizzard.com/...&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;Where [prefix] can be 'www' or 'US' or 'EU' or similar.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;We have covered the main things to watch out for with regards to bogus phishing sites. There are other, more advanced &lt;a href="http://en.wikipedia.org/wiki/Phishing"&gt;phishing&lt;/a&gt; techniques including &lt;a href="http://en.wikipedia.org/wiki/DNS_hijacking"&gt;DNS hijacking&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Cross-site_scripting"&gt;cross-site scripting&lt;/a&gt; that are beyond the scope of this article but are worthy reading topics for those that wish to know more.&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;If you ever have any doubt about a site that asks for your game username/password then contact http://blizzard.com - manually type the URL and don't follow links from the suspect site - and ask them if the suspect site is real.&lt;br /&gt;&lt;br /&gt;Grab yourself a Blizzard authenticator (or phone application) and add another layer of protection to these kinds of attacks - if the bad guys get hold of your username and password then it is of little use to them without your hardware authenticator.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html"&gt;10-steps to better WoW acount security&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-1884531655949708895?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/1884531655949708895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1884531655949708895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1884531655949708895'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2009/09/anatomy-of-wow-phising-site.html' title='The Anatomy of a WoW Phishing Site'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_3sAE3l3Wnqs/Srbv8xpHzeI/AAAAAAAABk0/2dZNWxPZ52Y/s72-c/nofish.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1624465548926375030.post-1670453014842188667</id><published>2009-07-19T16:28:00.000-07:00</published><updated>2010-08-08T18:30:21.831-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='patching'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='keylogger'/><category scheme='http://www.blogger.com/atom/ns#' term='authenticator'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Protecting Your WoW Account: Ten Easy Steps</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_3sAE3l3Wnqs/SmPYFZ89R7I/AAAAAAAABjk/4tXIooKZexI/s1600-h/security.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5360365568878528434" src="http://4.bp.blogspot.com/_3sAE3l3Wnqs/SmPYFZ89R7I/AAAAAAAABjk/4tXIooKZexI/s320/security.jpg" style="cursor: pointer; float: right; height: 202px; margin: 0pt 0pt 10px 10px; width: 192px;" /&gt;&lt;/a&gt;You invest a lot of time leveling your characters so don't leave yourself exposed to the disappointment and frustration of account compromise.&lt;br /&gt;&lt;br /&gt;Let's explore the common hacking methods of the bad guys and introduce some simple and easy steps on how to help prevent character loss and down time.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%; font-weight: bold;"&gt;How do WoW accounts get hacked?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The keylogger&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Keystroke_logging"&gt;Keyloggers&lt;/a&gt; or keystroke loggers are covert pieces of software that sit in memory, logging your keystrokes when you enter the game or when you enter the Blizzard account or forum web sites.  The keylogger then sends this information out to the bad guys. Many people wrongly believe that keyloggers only look for your password when you enter the game, but more commonly than not, they intercept it when you enter the Blizzard forums or account pages on the official web site.&lt;br /&gt;&lt;br /&gt;Keyloggers are often included in the functionality of malware called "Trojans". &lt;a href="http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29"&gt;Trojans&lt;/a&gt; are pieces of software that are designed to look like legitimate software but have backdoors for malicious functions.&lt;br /&gt;&lt;br /&gt;Reputable antivirus software will detect keyloggers as soon as they attempt to install themselves and will often identify them as trojans.  There are plenty of good, free antivirus products out there but if you sometimes get what you pay for.  In fact, there are many scam products out there that appear to be antivirus products which are actually keyloggers themselves.  I recommend sticking with the major commercial antivirus vendors such as Symantec, McAfee, Trend Micro, Sophos, AVG and Kaspersky. If you think you might have a keylogger then most of these vendors have a free online scan that you can use to check your system - in fact, it is best to try a couple of these free scans to be sure.&lt;br /&gt;&lt;br /&gt;Also note that some newly developed keyloggers may not be detected by antivirus software so don't rely on it 100%.&lt;br /&gt;&lt;br /&gt;But how did you get the keylogger in the first place? There are several ways that you can pick one of these up:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;You opened an email attachment that launched this software on your machine.&lt;/li&gt;&lt;li&gt;You downloaded and launched the software thinking it was something else. For example, you may have been browsing a web site that prompted you to download a "codec" to watch a video.  You excitedly clicked on the download and then the "run" button, only to find that the video still did not play.  In the background, you just installed a keylogger.&lt;/li&gt;&lt;li&gt;Your browser or some browser application such as Flash was not patched for a certain vulnerability and you browsed a page that automatically launched and installed the keylogger.&lt;/li&gt;&lt;li&gt;You downloaded what you thought was an addon, that strangely asked you to run some installation package.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;The common theme here is that to install a keylogger you generally have to be tricked into running some form of installation process.&lt;br /&gt;&lt;br /&gt;Don't think you are perfectly safe if you have a Mac either.  While the Microsoft operating systems have traditionally been the target of most malware, Macs are beginning to increase in popularity for malware writers.&lt;br /&gt;&lt;br /&gt;The Blizzard authentication token is a great way to protect against a keylogger.  The authenticator helps provide &lt;a href="http://en.wikipedia.org/wiki/Two-factor_authentication"&gt;two-factor authentication&lt;/a&gt;.  Two-factor authentication is far more effective since it requires two pieces of information from two different sources - in this case, something that you know (your regular account password) and something that you have (the authenticator generated password).  The added security comes from the fact that the authenticator changes its password every 60 seconds - so even if the keylogger captures the authenticator password it is only valid for a very short time.&lt;br /&gt;&lt;br /&gt;If you have a iPhone then you can pick up the free Blizzard Battlenet Authenticator application from the iStore.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The phishing site&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Phishing"&gt;Phishing&lt;/a&gt; is the process of using deceptive methods to acquire sensitive information, in this case your game account details.&lt;br /&gt;&lt;br /&gt;For example, you saw a notice in trade chat or received a whisper saying that you have won a competition to win a spectral tiger mount.  All you have to do is visit a web site and type in a special redemption code.  You go to the site, it looks legitimate, you enter the code and it then asks you for your account name and password so that the tiger mount can be mailed to your character. STOP! This is a phishing site with one aim - to get you to type in your username and password so they can log in to your game account.&lt;br /&gt;&lt;br /&gt;A similar ploy is the email that reads "Official email from Blizzard. Your account has been suspended. Click here to confirm your details and unlock your account".  Again, you click on the link in the email and it looks like a legitimate Blizzard site... but it is nothing but a scam.&lt;br /&gt;&lt;br /&gt;It often takes a trained eye to spot a fake web site. Be extra cautious when any site asks you for your account details.  I know of only three sites that should ever require your game password - worldofwarcraft.com, blizzard.com and battle.net. If the URL is anything other than these then it is highly likely to be a phishing site that you are visiting.&lt;br /&gt;&lt;br /&gt;Again, the Blizzard authenticator provides great protection here since phished authenticator passwords are only valid for a very, very short time.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The insider&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You have shared your account password with a friend or a leveling service. You never changed your password and now your friend is no longer a friend or the leveling service had other intentions. The solution here is - don't share your username/password with anyone. Choose a password that can't be &lt;a href="http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html"&gt;easily guessed&lt;/a&gt; by your friends and enemies.&lt;br /&gt;&lt;br /&gt;Also, be sure to use a different login/password combination when you subscribe to Blizzard fan sites. There are hundreds of fan sites and not all are reputable. Even reputable fan sites with username/password databases are a gold mine for successful hackers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Ten Steps - Don't become a statistic&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here are ten simple steps you can do to reduce the chance of your account being compromised:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Don't share your game password with anyone and pick a password that is not &lt;a href="http://securingwow.blogspot.com/2010/05/suffer-mortals-as-your-pathetic.html"&gt;easily guessed&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don't use the same password for subscribing to fan sites&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Keep your operating system, browser and other software fully patched - start with &lt;a href="http://windowsupdate.microsoft.com/"&gt;Windows Update&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Run a reputable antivirus product, preferably a full internet security suite with a firewall and keystroke encryption&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don't click on email attachments, especially when you don't know the sender&lt;/li&gt;&lt;li&gt;Don't download and run executable files from web pages&lt;/li&gt;&lt;li&gt;Don't enter your game password into any web site other than the official game sites&lt;/li&gt;&lt;li&gt;Don't enter your game password to a legitimate Blizzard web site from a PC that may be compromised&lt;/li&gt;&lt;li&gt;Be very suspicious if an addon requires some form of install package to be run&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Invest in a Blizzard authenticator or install the Battlenet Authenticator application on your iPhone&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;a href="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SmUryhDYDfI/AAAAAAAABj0/05zWd4L9aMM/s1600-h/authenticator.jpeg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5360739078320426482" src="http://2.bp.blogspot.com/_3sAE3l3Wnqs/SmUryhDYDfI/AAAAAAAABj0/05zWd4L9aMM/s200/authenticator.jpeg" style="cursor: pointer; float: right; height: 200px; margin: 0pt 0pt 10px 10px; width: 148px;" /&gt;&lt;/a&gt;Remember, security is never 100% guaranteed and there will always be opportunities for your account to be compromised. I have touched on the more common methods in this post. The important message here is to make it as difficult as possible for the bad guys. Out of all the advice, the hardware authenticator is one of &lt;span style="font-weight: bold;"&gt;the&lt;/span&gt; simplest, inexpensive and most effective steps you can take to avoid becoming a hack statistic.  Pick one up from the &lt;a href="http://www.blizzard.com/store"&gt;Blizzard store&lt;/a&gt; today.&lt;br /&gt;&lt;br /&gt;Update: You can also purchase this as an application for many mobile phones at &lt;a href="http://mobile.blizzard.com/"&gt;mobile.blizzard.com&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1624465548926375030-1670453014842188667?l=securingwow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securingwow.blogspot.com/feeds/1670453014842188667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html#comment-form' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1670453014842188667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1624465548926375030/posts/default/1670453014842188667'/><link rel='alternate' type='text/html' href='http://securingwow.blogspot.com/2009/07/protecting-your-wow-account.html' title='Protecting Your WoW Account: Ten Easy Steps'/><author><name>Polar</name><uri>http://www.blogger.com/profile/07221490946405772164</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_3sAE3l3Wnqs/SmPYFZ89R7I/AAAAAAAABjk/4tXIooKZexI/s72-c/security.jpg' height='72' width='72'/><thr:total>12</thr:total></entry></feed>
