Showing posts with label wow. Show all posts
Showing posts with label wow. Show all posts

Tuesday, April 5, 2011

Top WoW Phishing Scams for March 2011

I have established a WoW phishing honeypot and I see a lot of active phishing scams.  I thought I would take the time to cover off the top two WoW phishing scams for March :

#1 Titled "Too Many Attempts Warning No.x" - 37% of WoW scams

The most common phishing scam for March comes in the form of a straight text email that warns you that your account has been locked due to too many login attempts. It provides a link to restore your account, but naturally points to a fake battle.net site, where your account details are captured.

-----------------------------------------------------------------------------
Dear customer, 
Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your ComputerIn the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail AccountAfter you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your accountWe now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: xxxxxxxxxxxxxxxxxxxxxxxxxxxx

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at xxxxxxxxxxxxxxxxxxx.

Sincerely, 
The Battle.net Account Team 
Online Privacy Policy
-----------------------------------------------------------------------------


#2 Titled "Account Change" - 26% of WoW scams

This scam attempts to scare you into thinking that your contact information has been illegally modified and entices you to log in to a fake site to verify your account information.

-----------------------------------------------------------------------------
Hello,
This is an automated notification regarding your Battle.net account. Some or all of your contact information was recently modified through the Account Management website.

*** If you made recent account changes, please disregard this automatic notification.
*** If you did NOT make any changes to your account, we recommend you log in to xxxxxxxxxxxxxxxxxxxx review your account settings.

If you cannot sign into Account Management using the link above, or if unauthorized changes continue to happen, please contact Blizzard Billing & Account Services for further assistance.

Billing & Account Services can be reached at 1-800-59-BLIZZARD (1-800-592-5499 Mon-Fri, 8AM-8PM Pacific Time) or at billing@blizzard.com.

Account security is solely the responsibility of the accountholder. Please be advised that in the event of a compromised account, Blizzard representatives will typically lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.

Regards,
The Battle.net Support Team 
Blizzard Entertainment
Online Privacy Policy
-----------------------------------------------------------------------------

Other active scams including a "7 days free access offer", "investigations on the sale/trade of your game account" and various "compensation" emails.  I have also started to see scams for LOTRO and RIFT.  You know that you have made it as an MMO when you see active phishing scams - sad, but true.

Learn more about the mechanics of these scams.

Thursday, June 3, 2010

Phishers Ramp Up Their WoW Assault

Phishers have begun targeting the remote auction house and cataclysm betas in the latest wave of WoW account phishing spam.

In the first example, unsuspecting users receive an email promoting the features and benefits of the remote auction house and invite them to participate in the beta by clicking on a download now link. The link takes them to a fake battle.net login site where their game details are captured.

A sample email is shown below:

























A second type of phishing email is targeting the Cataclysm beta opt-in. Users are sent an email reminding them to update their system specifications to be eligible for a beta invite by logging into battle.net. Naturally, the battle.net link is a fake site designed to collect your account credentials:






















Be wary of any email that pretends to come from Blizzard and check the URL of any linked site before entering your account credentials. Visit our anatomy of a phishing site post for information on how to spot phishing emails and better protect your game account.

Let us know if you have received emails scams like these.

Sunday, May 30, 2010

Suffer mortals, as your pathetic password betrays you!

One of the things we often don't put much thought into is password selection. Usually it is a loved-one's name or an easily remembered string of characters. Unfortunately, a poor choice of password can dramatically increase the chance of your game account being hacked.

In an analysis performed by Imperva of 32 million leaked passwords from rockyou.com, it was found that nearly 50% of passwords consist of people's names, slang words, dictionary words or trivial passwords. The study estimates that if a hacker used the top 5000 passwords in a dictionary attack, it would take, on average, only 111 attempts to break into a given account.

World of Warcraft does not have an account or IP address lockout after any number of bad password attempts. This gives the bad guys an opportunity to dictionary attack your account.

Assuming that the WoW account password frequency distribution is similar and that a hacker could try a password every 2 seconds - it would take an average of only 3.7 minutes to hack an account.

Obviously the time required to hack your account is going to vary based on the strength of your game password so choosing an uncommon and complex password is key. The report lists the following as the most commonly used passwords:
  1. 123456
  2. 12345
  3. 123456789
  4. password
  5. iloveyou
  6. princess
  7. rockyou (or 'warcraft' in our case)
  8. 1234567
  9. 12345678
  10. abc123
Other common passwords include monkey, qwerty, 654321 and first names of people.

How can you better protect your WoW account?

First, buy yourself an authenticator and add another layer of security to your account. A dictionary attack is largely rendered useless with the addition of a hardware token.

Second, if you don't have an authenticator or wish to be more secure then choose a strong password. Strong passwords contain numeric and non-standard characters and do not have any strings that contain dictionary words. They should be at 12-14 characters in length. However, don't bother too much with upper and lower case characters since the battle.net authentication service does not differentiate between upper/lower case. An example of strong WoW password would be something like "sdm#6wua2pa9jk".

If you have trouble remembering a strong password (and most of us will) then try to create something similar from a memorable saying. For example, Professor Putricide's "Bad news everyone! I don't think I'm going to make it" becomes "bne!idtig2mi" as your password. Such a password will be close to impossible to dictionary attack and will take a long time to brute force attack. Don't share this password with anyone and don't use this password on any other service - keep it unique to WoW only.

Finally, create a unique email address as your battle.net login. Hackers need to be able to guess or steal your username so making this complex will certainly hinder their efforts.

Update: If you want to read more about hackers stealing account usernames and passwords, check out the Symantec article where they recently discovered 44 million stolen gaming credentials.

A little bit of effort with your password selection will make hacking your precious account significantly more difficult... and don't forget to get yourself an authenticator.

Monday, March 15, 2010

Kicking Goals in the World of Warcraft

Is a member of your family or close friend crazy about a game called World of Warcraft? Do they lock themselves in their room, playing the game for hours and refusing to take phone calls or talk to you? It's time to investigate this seemingly strange behavior by drawing parallels to the universal sport of soccer/football.

What is the World of Warcraft?

World of Warcraft (WoW) is a highly popular multi-player online game with over 11 million subscribers. Unlike traditional stand-alone computer games, online games feature interaction with hundreds and sometimes thousands of other real human players. In WoW, these players form 'raid groups' of up to 25 players to tackle an in-game dungeon.

What exactly is a WoW raid group?

Think of a raid group as a soccer team and think of an dungeon as a series of matches where the team plays against computer controlled opponents, also known as "bosses". The raid group works as a team to win these matches - there is a nominated raid leader (the coach and captain) who gives instructions and coordinates the team. The team consists of attackers (DPS members) which are assigned to attack and damage the boss and defenders (tanks and healers) which aim to distract the boss and heal up the team so that the attackers can do their job. Each team member is assigned a specific role and, like any sporting match, all players need to be present for the full game time and perform their assigned duties to the best of their ability. Many raid groups also have reserve players that sit on the bench, waiting to be called in to replace players.

Team members will communicate with each other via a microphone and headphones connected to the PC - you may see your partner sporting a very ugly set of headphones, looking something like a submarine commander. This is the equivalent of the on field communication that happens between players, the captain and the coach.

Each of the matches takes typically between 5-10 mins. During this time, there is no way to pause the game - all raiding takes place in real time. After each match, the raid leader will analyse the performance of the team, make adjustments and then re-engage until the "boss" is defeated - just like any good soccer coach.

A full raid session may consist of many boss kills and can easily go for several hours. Raids are typically scheduled at specific times each week.

So why won't they come and have dinner when they are called?

Players are required to be present for the full duration of the raid. Like any sporting match, you cannot just leave the game whenever you decide. Many of the matches require all members of the raid to play at their best - any single member that steps away from a match and goes 'away from keyboard - AFK' without pre-warning the raid leader will very likely cause the match to be lost - upsetting the other 24 players in the raid.

Why can't I talk to them for 5 mins during a raid?

Players will either be participating in the match or will be listening to the raid leader, taking instructions before the next match. Either way, the player needs to give the raid his/her full attention.

It is best to wait for a "bio" break to speak with them. Bio breaks are scheduled breaks where the player can get a coffee or visit the bathroom.

What happens when all of the bosses are defeated
?

This only occurs for the very elite teams and only for certain periods of the year. The creators of WoW are constantly adding new bosses and content to the game to keep players entertained. Most raiding groups always have something bigger to aim for.

I asked them to go out this weekend but they claim they are rostered. What's the deal?

Just like your weekend soccer games, players announce their availability to play typically 1-2 weeks ahead of the scheduled raid. A team roster is usually published by the raid leader a few days before the raid. Players that made themselves available and subsequently get rostered are expected to play.

Why bother raiding - it's just a computer game? Why don't they go outside and kick a ball instead?

The real thrill of raiding is the feeling of progression, team work and accomplishment - just like the feeling you get after winning a sporting final.

Each completed boss encounter awards the group with several items of equipment, otherwise known as 'loot'. This loot comes in the form of items that the player can wear and may be a new piece of armor, weapon or other similar item. Loot items increase the power of individual players and are highly sought after. Winning loot in a raid is a significant achievement - very similar to that sporting trophy you display with pride on the mantle piece.

So if I have to engage in conversation with my WoW gamer, what should I be asking?

Stun your WoW gamer by asking them any of the following questions:
  • What role do you play in WoW raids? A tank, healer or DPS? Why did you chose that role?
  • What new loot did you get from your raid today? Show me your character.
  • What boss are you currently working on? How did you go?
  • Your dinner is almost ready, when can you take your next extended bio break?
Ask these and your fellow raider is bound to be most impressed with your understanding of their gaming world.

Finally, just remember that calling your WoW player for dinner or asking them to do chores in the middle of the raid is likely to be met with some serious resistance. Would David Beckham or Ronaldo leave the field mid-game to put the trash out? At least wait for half-time.

Sunday, February 28, 2010

Authenticator hack - is your account still safe?

The big security news of the weekend is that Blizzard has confirmed a man-in-the-middle attack that is being used to hack accounts that are using an authenticator.

Let me state up front that this is not a reason to throw your authenticator away nor should it be an excuse for not getting one. The authenticator is a very sound device - but it is, and will always be, just one of many security mechanisms that you should use to help secure your account. It is what us IT security guys call "layered security" - more on this in a moment.

The attack itself requires a keylogger/trojan. The keylogger, once installed on your system, logs your game user name, password AND authenticator code. It proceeds to post this information off to a rogue server so that the attacker can use this information in near real-time to access your game account. In the meantime, it sends an incorrect code to the battle.net authentication server from your machine - resulting in an "incorrect login" type message from the game. It does this so that you don't consume the one-time-use code that the authenticator provides.

Now it was only a matter of time before we saw this kind of attack. More and more people have been using authenticators. In a survey of over 90 gamers at securingwow.blogspot.com, 84% of them claim to have an authenticator attached to their game account. This tells us that more and more people are now running with an authenticator - reducing the pool size of "easy" victims.

The bad guys are now being forced to step up the sophistication of their attacks and have started targeting those with authenticators. We are bound to see many more keyloggers with this capability in the near future. Additionally, phishing attacks will also begin to operate in the same fashion - asking you to type in your authentication code, along with your other game account details, posting the info off to the attacker - who uses them in real time - leaving you with a "system unavailable" message and a soon-to-be-stripped game account. If we don't have these mechanisms in WoW phishing sites already then I can assure you that they are not far away.

So how do you prevent it from happening? It all comes down to minimizing the chance of being infected with a keylogger in the first place. One of the many tenets of IT Security is that "no sercurity system is 100% effective". Anyone that tells you otherwise does not know what they are preaching or they are trying to sell you some snake-oil. In this case, we can't rely on authenticators to be the only defense mechansim - here are ten simple steps you can do to reduce the chance of your game account being compromised:
  1. Don't share your game password with anyone and pick a password that is not easily guessed
  2. Don't use the same password for subscribing to fan sites
  3. Keep your operating system, browser and other software (especially Adobe Flash) fully patched - start with Windows Update
  4. Run a reputable antivirus product, preferably a full internet security suite with a firewall and keystroke encryption
  5. Don't click on email attachments, especially when you don't know the sender
  6. Don't download and run executable files from web pages
  7. Don't enter your game password into any web site other than the official game sites
  8. Don't enter your game password to a legitimate Blizzard web site from a PC that may be compromised
  9. Be very suspicious if an addon requires some form of install package to be run
  10. Invest in a Blizzard authenticator or install the Battlenet authenticator application on your phone
Try to follow all of these recommendations - not just one or two points.

In this specific case, the keylogger was reportedly delivered via a fake site for the Wowmatrix addon manager. The site was created to look and feel like wowmatrix.com but, instead of downloading and installing the addon manager, the keylogger was installed instead. Our recommendations #6 and #9 talk about being "very suspicious" of add-ons that require an installer to run and avoid running executable files from web sites.

The bottom line is that keyloggers and phishing sites are here to stay. Don't rely on your authenticator to protect you 100% of the time - but don't throw it out either. It still forms a very strong part of your layered defense against the bad guys.

Post a comment - we would like to hear from you if you have fallen victim to this attack.

Tuesday, January 12, 2010

Beware of Cataclysm Phishing Scams

With the recent announcement of the Catalysm alpha, users are warned not to fall victim to phishing scams.

Be aware that if you receive an email inviting you to join the Cataclysm testing cycle then it will most likely be a scam. Cataclysm open beta does not exist as yet.

Do not enter your game username and password into any sites that may link from any email claiming to be an official Blizzard invite to Cataclysm.

If you see a Cataclysm phishing scam then feel free to share your comments on it.

Friday, December 11, 2009

Latest phishing scam

The latest phishing scam is an email titled "Battle.net Account – Password Change Notice" telling you that your password has been changed and if you did not make the change then you should visit the blizzard FAQ at a URL of:

http_://www.worldofwarcrarrft.net/

Spot the scam? I hope so (emphasis added).

This is a traditional wow phishing scam.

Thursday, October 1, 2009

New phishing scam

You receive an in-game whisper promising a new mount by visiting:

http://www.blizzus-wow.com/

This is a scam phishing site designed to steal your account information. In fact, it appears to be the very same set of pages that are discussed in my previous blog about how to identify WoW phishing sites.

Wednesday, September 16, 2009

The Anatomy of a WoW Phishing Site

Password stealing via a bogus phishing site is a common tactic for those wanting to break into your WoW account. Let's explore the workings of an illegal WoW phishing site and give you some tips on how to spot such fakes. Note that the phishing site discussed here is no longer online.

The Bait

You receive an in-game whisper or mail telling you that you are eligible to trial an all-new mount. All you have to do to claim this mount is to register on an "official" site and the mount will be sent to your account. The message contains the URL of a site to visit - in this case it is "http://www.blizzard-forums.com". Eagerly, you race off to claim your special mount.

The Hook

You enter the URL to your browser and you get the following site:



You enter your account name and password, hit submit and are taken through to the following page:



They are now asking for my email address and they want to confirm my account's secret question and answer. You enter the required information and hit submit. You finish on the following success screen:



Application Successful! You just need to wait for your mount to arrive in my in-game mail - but it never does. However, next time you log in to the game you find that all of your characters have been stripped of their worldly possessions, you have no gold and your guild's bank has been raided.

You have been the unfortunate victim of a phishing attack!

Where did I go wrong?

How could you have prevented falling for such a trick?

Phishing is a form of social engineering - a tactic used by the bad guys to lure in unsuspecting victims to steal personal information - in this case your account login details.

The first part of this attack was to offer something that was highly desirable - in this case the promise of a new, special, in-game mount. Other attacks use the promise of special access to beta new expansion content or tell you your account has been locked as a result of a hack and you need to follow certain steps to unlock it. It can come as an in-game whisper, an in-game mail or a regular email.

Rule#1: Be highly suspicious of anything that is offered for free or anything email that claims your account has been compromised

Next, you were given the URL of something that turned out to be a phishing site. But how can you tell if it is official or not?

The two sites, one bogus and one legitimate:



Spot the difference? No?

It is extremely difficult to spot the difference. It is very easy for an attacker to copy the images, layout and text of the legitimate site - and do it perfectly.

However, there are key things to look for in the URLs. The official Blizzard site is a secured SSL site, with the URL prefixed with "https://". The site is also part of the battle.net domain (in this case us.battle.net):



The bogus phishing site has no SSL, no "https://" and is not part of a battle.net, worldofwarcraft.com or blizzard.com domain:



In fact, looking up the blizzard-forums.com domain ownership, it was found to be owned by an individual in Shanghai, China.

The real irony is that the official Blizzard warning is still shown on the bogus phishing site:



Rule#2: Do not type your game account username/password into any web site other than worldofwarcraft.com (wow-europe.com), blizzard.com and battle.net.

Rule#3: Check for a secured "https:" session on such sites when entering your username/password - while not a 100% guarantee of legitimacy, phishing sites generally don't bother with digital certificates and https.

Some other things that could tip a user off with this example were:

1. Nothing happened if you clicked on any of the language options on the first page - the bad guys were a bit lazy and could not be bothered writing the multi-language support for the site. They were obviously only targeting the english speaking community.

2. Many of the links on the subsequent pages were incomplete and broken.

3. Entering a dummy username and password still allowed you to progress to the subsequent "success" pages - there was obviously no way to check the username/password combination.

4. There was extremely poor grammar on many of the subsequent pages.

Final words

A word of warning regarding the URL - I recently saw a similar phishing attack that cleverly used the URL of "www.promotion-battle.net". At a glance it looks like a battle.net domain but it is not. The domain is promotion-battle.net and this domain is definitely not an official website.

Rule#4: Just because the letters battle.net or worldofwarcraft.com or blizzard.com appear somewhere in the URL does not make it an official site.

Official login sites should have the format:

https://[prefix].battle.net/...
or
https://[prefix].worldofwarcraft.com/...
or
https://[prefix].wow-europe.com/...
or
https://[prefix].blizzard.com/...

Where [prefix] can be 'www' or 'US' or 'EU' or similar.

We have covered the main things to watch out for with regards to bogus phishing sites. There are other, more advanced phishing techniques including DNS hijacking and cross-site scripting that are beyond the scope of this article but are worthy reading topics for those that wish to know more.

If you ever have any doubt about a site that asks for your game username/password then contact http://blizzard.com - manually type the URL and don't follow links from the suspect site - and ask them if the suspect site is real.

Grab yourself a Blizzard authenticator (or phone application) and add another layer of protection to these kinds of attacks - if the bad guys get hold of your username and password then it is of little use to them without your hardware authenticator.

10-steps to better WoW acount security