Gmail + WoW Hacked

Discussion in 'The Guru's Pub' started by Nbz, Jul 9, 2011.

  1. Nbz

    Nbz Master Guru

    Messages:
    942
    Likes Received:
    0
    GPU:
    Sapphire HD6850 1000/1150
    Hello fellas,

    So just 10minutes ago, whilst I was getting ready to go out to the cinema, I wanted to check my email and I noticed Firefox prompted my Password.
    I thought it was weird so I typed it in and it failed, redid it and failed again.

    So I tried to login to my WoW account and it failed. Was able to recover both of them by recovering Gmail's account through. After 10 minutes, both are gone and I can't login my Gmail account.

    I submited a ticket to Gmail and am awaiting contact.
    I ran malwarebytes and theres nothing wrong with my PC malware wise and I barely click anything odd. Now I know someone is at the account because my cousin is checking it for me. One of my toons is logged in.

    So I wonder, how the **** did this happen, I am so cautions when I open websites and ****...

    Any other tips for malware removal tools?
     
  2. Extraordinary

    Extraordinary Guest

    Messages:
    19,558
    Likes Received:
    1,638
    GPU:
    ROG Strix 1080 OC
    More than likely you use the same email / password combo on other sites, and one of those sites have had their databases hacked, found your details and took pot luck at your account.

    You should really attach a mobile / cell phone to your gmail account, you can always recover the account with that security as you can not remove the number without physically having the phone (Receiving the SMS)
     
  3. Nbz

    Nbz Master Guru

    Messages:
    942
    Likes Received:
    0
    GPU:
    Sapphire HD6850 1000/1150
    I use the same email obviously but I do not use the same password.
    How did they manage to fetch my email password?

    They only hacked my Gmail to get into my Warcraft account, that is obvious since every other account I have is fine.
    Also, my phone uses Symbian which isn't supported by Gmail.

    EDIT: Just ran Fsecure and it found some tracking cookies, eventhough I use noscript...

    Omfg so ****ing annoyed.
     
  4. Extraordinary

    Extraordinary Guest

    Messages:
    19,558
    Likes Received:
    1,638
    GPU:
    ROG Strix 1080 OC
    You do not need any support, you just add the phone number to gmail via a PC, verify via SMS code, type the code back into the PC in gmail

    Then when you want to recover your account if it was hacked, you can do it via SMS

    You do not need to access gmail from the phone, just the SMS code that you type back into the PC to reset your gmail password


    Not sure how they managed, brute force? Maybe you have a rootkit infection / keylogger hiding on the PC ?

    Most AVs can not see rootkits - download something like Kaspersky's Rescue Disk 10, burn / copy to flash - boot the PC from that, update via wired connection, run scan on the MBR boot sector of the disk

    http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/


    EDIT - Tracking cookies are not the issue here, they are spyware / adware
     

  5. Seref

    Seref Guest

    Messages:
    1,622
    Likes Received:
    3
    GPU:
    Nvidia 3080 Ti
    In future, you should use an authenticator with your WoW account. If you don't want to pay for one, you can download the official Android SDK dev emulator to your computer and download the Authenticator app from the Android store for free.
     
  6. MrH

    MrH Guest

    Messages:
    2,812
    Likes Received:
    14
    GPU:
    RTX 3080 FE
    The authenticator was money well spent, everyone that cares about their account should buy one.
     
  7. PhazeDelta1

    PhazeDelta1 Guest

    Messages:
    15,608
    Likes Received:
    14
    GPU:
    EVGA 1080 FTW
    both gmail and bnet have an authentication tool.
     
  8. Nbz

    Nbz Master Guru

    Messages:
    942
    Likes Received:
    0
    GPU:
    Sapphire HD6850 1000/1150
    Just recovered my WoW account through a cousin that also plays.
    The account was changed to a new email adress through a different computer while this one is being checked for Rootkits and other malware.

    Now, I still need to recover my Gmail account because I have an airplane ticket there and also it is linked to my University account.

    The thing that boggles my mind is, I only have a handful of places where I use this email, and I do not click anything at all. How would someone know the email account was linked to a battlenet acount because I can guarantee you that they are only after my WoW account and nothing else. It really boggles my mind...
     
  9. Extraordinary

    Extraordinary Guest

    Messages:
    19,558
    Likes Received:
    1,638
    GPU:
    ROG Strix 1080 OC
    Hackers hack gmail all the time, you did not have good enough security, so you along with 100's of other gmail users were hacked today and had not set up the correct security on the account to recover it.

    Once they were in there, they found your battle.net account and tried to take that too, and whatever else they find they will try and steal too

    I doubt they knew what was in your gmail until they gained access and found your WOW account in there.

    Other possibility is that is was someone who knows you and your details
     
  10. Nbz

    Nbz Master Guru

    Messages:
    942
    Likes Received:
    0
    GPU:
    Sapphire HD6850 1000/1150
    Just setup the two side verification on my new Gmail account.
    Should make it "impossible" to login without authorisation...

    Now I'm wondering if I should format my PC or not...
     

  11. anticitizen013

    anticitizen013 Ancient Guru

    Messages:
    3,465
    Likes Received:
    0
    GPU:
    2x R9 280X CrossFire
    Same thing happened to me earlier. I got an Authenticator. Very good idea. Plus the pet is cool (but not as cool as my wind rider cub) :D

    I'm not sure exactly how it got hacked but my suspicion was that I had joined my new guild (at the time) forum and it may not have been secure, and since I (at the time) used the same email for both WoW and Gmail and didn't have an Authenticator, it was easy pickings. Poop.

    In any case I got ALL my items & gold back as I was able to tell them exactly when my last login was. Good times were renewed :nerd:
     
  12. Zer0K3wL

    Zer0K3wL Banned

    Messages:
    3,073
    Likes Received:
    0
    GPU:
    gtx 480 850/1700/2000 h2o
    you probably got on a fake website and filled in your details their.
     
    Last edited: Jul 13, 2011
  13. MasterBash

    MasterBash Guest

    Messages:
    819
    Likes Received:
    18
    GPU:
    EVGA GTX970 SSC+
    it happened to me, I used the same password to hotmail and wow.

    I had nothing on my computer... It must be some kind of exploit somewhere.
     
  14. Nbz

    Nbz Master Guru

    Messages:
    942
    Likes Received:
    0
    GPU:
    Sapphire HD6850 1000/1150
    Just finished formating and I will buy an autenticathor tomorrow for this.
    Also, just enabled the two way login feature from Gmail (mobile) which should make things way harder.

    Now, the tricky part. I had my cousin scouting my WoW account online so that he could see if the hacker was on or not. When the GM contacted him, the account got locked offline and the GM gave me all the steps to get it back.

    I had to create a new Battlenet account, and then, submit a ticket from the account stating what happened. Now, it got replied by the same GM that answered everything online but, since I did not want to risk it, I went through the format first and setup everything.

    So, I open Battlenet and tried to login with the newly created account and guess what, it doesnt work. When I try tto recover the password it says the email/name combination doesn't exist...

    I have the ticket page open on the laptop and was able to submit a new ticket online however, if I try to access something else through the link I get "kicked" from the ticket service so I cannot turn it off if I want to be able to reply back and read answers.

    Another thing, I had a reservation confirmation on the very same email, from Ryannair and my question is, does anyone know if credit card details usually appear on the reservation confirmations? If they do, and the guy that took over the account saw it, it means I'm screwed up but if it doesn't I'm probably safe. Tomorrow I'm expecting a reply from Google and will also phone Ryanair in the morning...
     
  15. dfwny

    dfwny Guest

    Messages:
    3,048
    Likes Received:
    1
    GPU:
    EVGA GTX280 SSC Ed. 1GB
    I'd recommend you create a hotmail account that you don't use for anything except WoW, and I mean anything. Not to sign up on your guild website, not for the temporary porn password, nothing.
     

  16. killer_939

    killer_939 Guest

    Messages:
    2,597
    Likes Received:
    0
    GPU:
    Radeon 7950 @ 1100/1500
    Interesting, my friend had his Hotmail and wow hacked yesterday, they changed his Hotmail to Chinese but didn't change his password! lol
     

Share This Page