1
Forum Settings
       
« Previous 1 2 3 4 5
Reply To Thread

My account got hacked ;;Follow

#1 Nov 25 2007 at 3:02 PM Rating: Decent
*
150 posts
Yesterday I was playing on my blm 54 and suddenly got kicked out of the game cause someone else logged into my account. I relogged and he kept relogging to kick me out. I tried for 3 1/2 hours but never got the chance to change my password and the culprit eventually changed the password himself. I already reported the crime to the police since SE stated that they are going to assist the authorities in every way possible. I already figured out that someone selling all of my equipment that's of value atm. So far 7 pieces have been sold according to www.ffxiah.com. I'd like to get some information regarding what's SE is going to do about the items and gil I lost so far and about recovering my account. Can't do anything til tomorrow because the customer support isn't available during the weekend.

The password I used was a random mix of 8 numbers and letters which didn't have any pattern or made sense. I only played the game on my personal PC. Never gave anyone my password or playonline ID. Still don't have a clue how he got it besides trial and error.


Edit: I'm not using any 3rd party tool related to FFXI like Windower or FFXIApp or whatever it's called.

Edited, Nov 25th 2007 6:15pm by CaldorDarkKnight
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#2 Nov 25 2007 at 3:04 PM Rating: Default
Blue Footed Boobie
*****
10,687 posts
I bet SE did it
#3 Nov 25 2007 at 3:06 PM Rating: Excellent
Worst. Title. Ever!
*****
17,302 posts
I don't think Trial and Error works, isn't FFXI anti-"brute force"?
____________________________
Can't sleep, clown will eat me.
#4 Nov 25 2007 at 3:07 PM Rating: Good
Sage
***
1,181 posts
metinks you have/had a piece of malware which could've transmitted "sensitive information" to "third parties"
____________________________
Kegsay - 85SMN/85BLU/85SCH
Goldsmithing-60, Cooking-61, Synergy-60
Shaded Specs Obtained 20 June 2005

http://kegsay.livejournal.com/
#5 Nov 25 2007 at 3:11 PM Rating: Default
*
150 posts
kegsay wrote:
metinks you have/had a piece of malware which could've transmitted "sensitive information" to "third parties"


Hmm. I haven't installed anything suspicious on my PC lately. I had a problem with my Pol Viewer lately though. Whenever I logged out of Final Fantasy I got one of those Windows error messages and that Pol.exe caused it. Do you think this might be related to it?
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#6 Nov 25 2007 at 3:13 PM Rating: Excellent
Avatar
******
29,917 posts
Yes. Your computer probably has a keylogger on it. You'll want to run a complete antivirus scan at your earliest oppertunity.

try housecall.trendmicro.com for now, as well as download and install windows defender from microsoft.com and spybot search and destroy. Then go purchase an updated antivirus suite.
____________________________
Arch Duke Kaolian Drachensborn, lvl 95 Ranger, Unrest Server
Tech support forum | FAQ (Support) | Mobile Zam: http://m.zam.com (Premium only)
Forum Rules
#7 Nov 25 2007 at 3:14 PM Rating: Decent
***
2,189 posts
The obvious come to mind:
1) 3rd-Party Programs gave away your stuff.
2) You gave your info to someone.
3) You got keylogged by some sort of malware.

There are little other choices from the above 3, choose wisely.
____________________________
Viseziox wrote:
I think you're a forum ****

Fancy Shmancy Wiki

[ffxisig]186182[/ffxisig]
#8 Nov 25 2007 at 3:15 PM Rating: Decent
***
2,084 posts
If you didn't give your information to anyone, my guess is keylogger.
____________________________
What would happen if I hired two private investigators to follow each other?
#9 Nov 25 2007 at 3:17 PM Rating: Decent
*
150 posts
Dread Lörd Kaolian wrote:
Yes. Your computer probably has a keylogger on it. You'll want to run a complete antivirus scan at your earliest oppertunity.

try housecall.trendmicro.com for now, as well as download and install windows defender from microsoft.com and spybot search and destroy. Then go purchase an updated antivirus suite.


But if I got my password saved a keylogger shouldn't have worked since I never had to enter it.
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#10 Nov 25 2007 at 3:18 PM Rating: Excellent
Avatar
******
29,917 posts
there are some keyloggers that can extract the password cache file. Once they have that, they don't even need your password anymore, they just use it to log in as you and then change it.
____________________________
Arch Duke Kaolian Drachensborn, lvl 95 Ranger, Unrest Server
Tech support forum | FAQ (Support) | Mobile Zam: http://m.zam.com (Premium only)
Forum Rules
#11 Nov 25 2007 at 3:26 PM Rating: Default
*
150 posts
Dread Lörd Kaolian wrote:
there are some keyloggers that can extract the password cache file. Once they have that, they don't even need your password anymore, they just use it to log in as you and then change it.


I see. Thanks a lot for that information. I'm currently using that site you told me about and check for malware. Any idea though how I got into contact with a keylogger that was used by someone related to FFXI?

I'm neither using windower or that cheat tool FFXIapp or whatever it's called nor any other 3rd party apps.

I'm still hoping for a response what's SE probably going to do about lost equipment and gil.
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#12 Nov 25 2007 at 3:35 PM Rating: Decent
Scholar
*
53 posts
Well from clicking your name I found you are from the fenrir server, but when I went to ffxiah.com to check it shows that Caldor from the fenrir server has only sold 2 things very recently and that would be November 23, the day before you claimed you got hacked...the items sold being worth 25k in combined gil.

Maybe it just isn't showing the recent transactions, but I certainly am not seeing 7 valuable things sold between November 24 and November 25.

http://www.ffxiah.com/player.php?id=138794&sid=7
____________________________
~Poofykitty: 90 WHM || 90 THF || 90 BRD || 85 RDM || 90 BLM || 75 PLD || 75 SAM
Server: Quetzalcoatl
~*!Mithra!*~
=^-^=
#13 Nov 25 2007 at 3:44 PM Rating: Default
*
150 posts
Poofykitty wrote:
Well from clicking your name I found you are from the fenrir server, but when I went to ffxiah.com to check it shows that Caldor from the fenrir server has only sold 2 things very recently and that would be November 23, the day before you claimed you got hacked...the items sold being worth 25k in combined gil.

Maybe it just isn't showing the recent transactions, but I certainly am not seeing 7 valuable things sold between November 24 and November 25.

http://www.ffxiah.com/player.php?id=138794&sid=7


Well the reason is that he isn't using my character to sell my stuff.
I imagined that the whole point of taking over my account was to sell my whole equipment. I thought about which items would sell fast and looked for the last Haubergeon sales. I checked out what the people sold recently and ended up finding my stuff is being sold by Fenlo.

http://www.ffxiah.com/player.php?id=1085774&sid=7

Stuff sold on that character so far I had:
- Haubergeon
- potent belt
- tatami shield
- (spike necklace)
- unyielding ring
- rune chopper
- wyvern earring
- Amemet Mantle+1

- sipahi turban
- chivalrous chain
- morion tanthlum


Of course it might be a strange coincidence but I'm positive he's selling my stuff right now.

EDIT: Just noticed I made a mistake regarding the spike necklace. I got one on my account but he bought one and didn't sell. No idea why he'd do that if he actually took the items though.

2. EDIT: several items I had on my account and sold by Fenlo now have been added to the list above.
Edited, Nov 25th 2007 6:57pm by CaldorDarkKnight

Edited, Nov 26th 2007 12:22am by CaldorDarkKnight
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#14Adzieboy, Posted: Nov 25 2007 at 3:53 PM, Rating: Sub-Default, (Expand Post) Well that just sounds like you're trying to get that value of items from this player, who has sold these things legitimately.
#15 Nov 25 2007 at 3:54 PM Rating: Decent
**
362 posts

I think it's on a case per case basis but I don't think they'll be able to return your items or your gil. Someone that ran the longest running LS on Asura got hacked; lost everything and they didn't restore his stuff and he's been playing 4-5 years. I honestly don't see them doing it for you. If I got hacked I'd prolly walk away from the game. 3-4 years of work and going back and doing it all; not to mention losing all your r/ex stuff or AF they might've tossed. Nope; I'd prolly be thankful. They just saved me 3-4 more years of my life being wasted. I've heard people get gil back like from Casinos etc.

I hope you keep playing and overcome this like some have; the guy of 5 years started playing again regardless. Strong man. I don't think I could ever do that. But I haven't been put in that situation yet either. But yeah; if you didnt give out your password it's possible for a keylogger. But most of these account thefts are really simple. If you have autologin on any other machine then your computer that could ***** you. Hopefully that's not that case.
____________________________
Bleh @ Sigs
#16 Nov 25 2007 at 4:01 PM Rating: Default
*
63 posts
A keylogger may be what happened when I lost my account. That would explain such a situation. Best of luck.
#17 Nov 25 2007 at 4:02 PM Rating: Decent
*
150 posts
Adzieboy wrote:
Well that just sounds like you're trying to get that value of items from this player, who has sold these things legitimately.

I'm not being harsh here, but that's the impression given to an impartial outsider.


I just got the suspicion that he's selling my stuff but I got no prove really. I didn't want to name the items and name of the one selling until Pooffykitty pointed out that nothing sold on my account and I wanted to clear the confusion. But seriously it's kinda strange that all my money items I got are being sold by someone who never sold anything before and just started doing the day after my account was hijacked ;;

Edit: Since the account fight I lost to the hijacker took 3 1/2 hours I'm sure my IP as well as the IP of the one who took over my account should have ended up in a pretty long log and SE should be able to figure out easily about that.

2nd Edit: I get your point though that you might believe I just try to make some extra money. I've been playing FFXI since 2003 though and have got more than 300 RL days on my playtime and I'm sure you can imagine getting that stuff +300k gil that were on my account aren't really a problem to make in that kind of time. Furthermore if you can contact several people on Fenrir I know well(if you're really interested send me a pm and I'll give you 10+ people who know about the equipment I got) and have them confirm my claims.


Edited, Nov 25th 2007 7:06pm by CaldorDarkKnight

Edited, Nov 25th 2007 7:14pm by CaldorDarkKnight
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#18ravennkight, Posted: Nov 25 2007 at 4:36 PM, Rating: Sub-Default, (Expand Post) Windowes defender is what i use for spot checks after 1) let some one else use my PC 2) get a weird redirect or pop up that got past POP upblocker. Stuff that doesn't seem harmful at the time can hide others.
#19 Nov 25 2007 at 4:39 PM Rating: Decent
*
150 posts
MasterThief wrote:

I think it's on a case per case basis but I don't think they'll be able to return your items or your gil. Someone that ran the longest running LS on Asura got hacked; lost everything and they didn't restore his stuff and he's been playing 4-5 years. I honestly don't see them doing it for you. If I got hacked I'd prolly walk away from the game. 3-4 years of work and going back and doing it all; not to mention losing all your r/ex stuff or AF they might've tossed. Nope; I'd prolly be thankful. They just saved me 3-4 more years of my life being wasted. I've heard people get gil back like from Casinos etc.

I hope you keep playing and overcome this like some have; the guy of 5 years started playing again regardless. Strong man. I don't think I could ever do that. But I haven't been put in that situation yet either. But yeah; if you didnt give out your password it's possible for a keylogger. But most of these account thefts are really simple. If you have autologin on any other machine then your computer that could ***** you. Hopefully that's not that case.


Thanks for the encouragement MasterThief. If they really dropped all my rare/ex stuff I'd really consider leaving the game although I really like playing it. I'd be happy if they could restore all/most of my account but if I'm only losing the gil + items I can just buy back I'd probably get over it since I can farm it back at a decent speed with my Thief.

I'm still scanning my PC but so far I haven't found any malware that might have caused my problem as far as I can see.
Found Malware up til now
- FREELOADER_DRIVERCLEANER
- ADWARE_FUNWEBPRODUCTS
- FREELOADER_WINFIXER
- ADWARE_DOLLARREVENUE
- ADWARE_BESTOFFERS
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#20 Nov 25 2007 at 6:11 PM Rating: Decent
**
337 posts
That sucks. I hope you can get your account back at the least, and hopefully the items as well.

I keep my passwords saved on my comp, just in case I happen to get a keylogger somewhere. Even if you only played on your personal PC, its always a good idea to switch your password every couple of month anyways.
#21 Nov 25 2007 at 6:21 PM Rating: Decent
I would also recomend getting a firewall, like zone alarm.
There will stop any programs from getting on the net with out your say so. and will make you computer hidden to the usal port scanning and what not.
____________________________
"Beastmaster, looks death in the eyes and says... BRING IT ON!!!"


Crawlerbasher.NET
Crawlerbasher's Photo Album
#22 Nov 25 2007 at 6:23 PM Rating: Decent
Scholar
49 posts
To bad there isn't a ffxideliverybox.com to see who sent what online like ffxiah.com.
#23 Nov 25 2007 at 6:26 PM Rating: Default
*****
10,227 posts
CaldorDarkKnight wrote:
Dread Lörd Kaolian wrote:
Yes. Your computer probably has a keylogger on it. You'll want to run a complete antivirus scan at your earliest oppertunity.

try housecall.trendmicro.com for now, as well as download and install windows defender from microsoft.com and spybot search and destroy. Then go purchase an updated antivirus suite.


But if I got my password saved a keylogger shouldn't have worked since I never had to enter it.
Only third-rate keyloggers log only keystrokes.
____________________________
2001-2011, retired because Abyssea destroyed my enjoyment of FFXI.
Garuda/Lakshmi.
#24 Nov 25 2007 at 7:19 PM Rating: Good
Scholar
***
1,743 posts
There's something not being said here. The odds of someone downloading a keylogger that reports information to someone interested in FFXI while not downloading stuff related to FFXI must be astronomical. And as we all know, virtually all account thefts related to keyloggers involve third party cheat tools, or at the very least fraps.
____________________________
85 DRK, 85 RNG, 81 DRG, 85 MNK
589 Merit Points
Cooking 100 +7
All missions completed
Playing on Phoenix since December 28th, 2003.
#25 Nov 25 2007 at 7:45 PM Rating: Decent
*
150 posts
Brisko wrote:
There's something not being said here. The odds of someone downloading a keylogger that reports information to someone interested in FFXI while not downloading stuff related to FFXI must be astronomical. And as we all know, virtually all account thefts related to keyloggers involve third party cheat tools, or at the very least fraps.


Hmm. That's why I've been wondering how I could have come into contact with a keylogger in the 1st place. I know I haven't downloaded anything. Looking for recipes and stuff surfing on random websites featuring FFXI contents but no downloads at all.

BTW: It looks like there is at least one more with exactly the same problem.

http://ffxi.allakhazam.com/forum.html?forum=29;mid=119588689074441781;page=1;howmany=50#m119589023983216149

That's the link to another thread regarding the same matter on the FFXI Feedback forum.
____________________________
Why won't god heal amputees?
http://whywontgodhealamputees.com/

10 questions that every intelligent Christian must answer.
http://youtube.com/watch?v=zDHJ4ztnldQ&mode=related&search=

#26 Nov 25 2007 at 7:54 PM Rating: Decent
Scholar
49 posts
CaldorDarkKnight wrote:
Hmm. That's why I've been wondering how I could have come into contact with a keylogger in the 1st place. I know I haven't downloaded anything. Looking for recipes and stuff surfing on random websites featuring FFXI contents but no downloads at all.

BTW: It looks like there is at least one more with exactly the same problem.

http://ffxi.allakhazam.com/forum.html?forum=29;mid=119588689074441781;page=1;howmany=50#m119589023983216149

That's the link to another thread regarding the same matter on the FFXI Feedback forum.

He never said if he was or wasn't using 3rd-party tools though.
« Previous 1 2 3 4 5
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 5 All times are in CST
Anonymous Guests (5)