Guild Wars Forums - GW Guru
 
 
 

Go Back   Guild Wars Forums - GW Guru > The Outer Circle > Site Feedback

Notices

Reply
 
Thread Tools Display Modes
Old Jan 23, 2010, 03:12 PM   #1
JR
Administrator
 
JR's Avatar
 
Join Date: Nov 2005
Profession: W/
Advertisement

Disable Ads
Default Guild Wars Guru Security Notice

Late Friday night the GuildWarsGuru database was accessed by an unknown third party. We caught it as it happened, but in that short space of time it appears they may have managed to obtain tables of user account information.

Their point of entry was a flaw in the WordPress software used to run the GuildWars2Guru.com front page. How they managed to get from there to the other databases is unknown right now, as it involved bypassing other security measures we have in place.

We've spent the 24 last hours tirelessly investigating what happened, patching up the exploit, and further strengthening security. It was important to inform the community as soon as possible, but we couldn't do that any earlier without advertising the sites vulnerability to others who may have more malicious intent.

So, what does this mean to you?

With the high incident of RMT hackings and phishing across MMO's rising we understand how serious this problem is, and the possible implications arising from this incident. Right now we assume the hacker's motivation was simply to obtain the list of email addresses, for the purpose of sending spam. That may seem fairly mundane, but there's a big market for that information.

Anything more sinister would require the hacker attempting to crack encrypted passwords. The investment required to do that seems to far outweigh the questionable return, though we can't rule it out. As such, we urge you to change your Guru, Guru Auctions and Guru 2 passwords and/or emails as soon as possible. We also urge you to change passwords and emails for any other site or service you log in to with the same information you use on guru.

We apologize for this unprecedented breach, and can only assure that your security is of the utmost importance to us. We are gamers as well, and are doing everything in our power to minimize the damage from this by informing our community openly. If you have questions or concerns please feel free to post them here, and we will do our best to address them as swiftly as possible.

To further protect your account please see guides on Phishing, Security, PlaySmart and Passwords.
JR is offline   Reply With Quote
Old Jan 23, 2010, 03:14 PM   #2
Rampage
Jungle Guide
 
Rampage's Avatar
 
Join Date: Apr 2006
Default

Shit happens. I'm very glad to see that you aren't pulling an NCSoft and just denying everything. Thanks for informing the community, good job guys.
Rampage is offline   Reply With Quote
Old Jan 23, 2010, 03:15 PM   #3
Gigashadow
BASIC MEMBER
 
Gigashadow's Avatar
 
Join Date: Aug 2005
Location: Bellevue, WA
Profession: W/
Default

Did they also get the character name associated with the email account, if it was in the profile? (or even if it had been removed, and was being kept around somehow)
Gigashadow is online now   Reply With Quote
Old Jan 23, 2010, 03:17 PM   #4
JR
Administrator
 
JR's Avatar
 
Join Date: Nov 2005
Profession: W/
Default

Quote:
Originally Posted by Gigashadow View Post
Did they also get the character name associated with the email account, if it was in the profile? (or even if it had been removed, and was being kept around somehow)
Thankfully, no. We wiped all character names when we introduced the change a couple of months ago.
JR is offline   Reply With Quote
Old Jan 23, 2010, 03:20 PM   #5
Neo Nugget
Your living legacy
 
Neo Nugget's Avatar
 
Join Date: Jan 2006
Profession: R/
Default

Quote:
Originally Posted by Rampage View Post
Shit happens. I'm very glad to see that you aren't pulling an NCSoft and just denying everything. Thanks for informing the community, good job guys.
Agreed.

Thanks for the heads up.
__________________
"Even if the morrow is barren of promises,
nothing shall forestall my return."
Neo Nugget is offline   Reply With Quote
Old Jan 23, 2010, 03:21 PM   #6
lishi
Forge Runner
 
Join Date: Jul 2005
Default

Just wondering.

Do guru save the password(even if encrypted) or just its md5 hash?

As far I know even if you have the md5 hash of the password you cannot obtain the original password as the association its not 1:1.
lishi is offline   Reply With Quote
Old Jan 23, 2010, 03:23 PM   #7
Arduin
Furnace Stoker
 
Arduin's Avatar
 
Join Date: May 2005
Location: The Netherlands
Guild: Limburgse Jagers [LJ]
Profession: R/
Default

Hmm, good thing I changed all my email-addresses and passwords some time ago.

Thanks for the open communication to us forumites.
Arduin is offline   Reply With Quote
Old Jan 23, 2010, 03:27 PM   #8
JR
Administrator
 
JR's Avatar
 
Join Date: Nov 2005
Profession: W/
Default

Quote:
Originally Posted by lishi View Post
Just wondering.

Do guru save the password(even if encrypted) or just its md5 hash?

As far I know even if you have the md5 hash of the password you cannot obtain the original password as the association its not 1:1.
We do not store passwords as plain text. All passwords are md5 hashed with a salt on top.

To be clear, md5 hash is just a method of encryption.
JR is offline   Reply With Quote
Old Jan 23, 2010, 03:29 PM   #9
Twin Blade Warriror
Wilds Pathfinder
 
Twin Blade Warriror's Avatar
 
Join Date: Jan 2006
Guild: I was in a guild by myself with 2 of my other accounts..but im banned now
Profession: W/
Default

ty for informing us
Twin Blade Warriror is offline   Reply With Quote
Old Jan 23, 2010, 03:40 PM   #10
Shayne Hawke
Moderator Skillz (0)
 
Shayne Hawke's Avatar
 
Join Date: May 2007
Guild: Clan Dethryche [dth]
Profession: R/
Default

This is good to know, thanks.
Shayne Hawke is offline   Reply With Quote
Old Jan 23, 2010, 03:53 PM   #11
Chthon
Furnace Stoker
 
Join Date: Apr 2007
Default

1. This is exactly how you're supposed to handle a security breach. Honesty and transparency ftw. I wish NCSoft could learn from your example.

2. Did they get the PM's associated with each account. Those are sure to contain GW IGN's.

3. For folks changing the password and e-mail. Remember to use a password unique to Guru and (preferrably) an e-mail unique to Guru (or shared with other not-so-important accounts).
Chthon is offline   Reply With Quote
Old Jan 23, 2010, 03:54 PM   #12
JR
Administrator
 
JR's Avatar
 
Join Date: Nov 2005
Profession: W/
Default

Quote:
Originally Posted by Chthon View Post
2. Did they get the PM's associated with each account. Those are sure to contain GW IGN's.
Nope, PMs were not obtained.

Last edited by JR; Jan 23, 2010 at 03:59 PM..
JR is offline   Reply With Quote
Old Jan 23, 2010, 04:12 PM   #13
Raven2201
Frost Gate Guardian
 
Join Date: Apr 2008
Guild: The Spearmen
Profession: D/
Default

What about the people who have the same email used for their GW account tied to guru as well?. That seems like it could pose a security issue to those users GW account.
Raven2201 is offline   Reply With Quote
Old Jan 23, 2010, 04:16 PM   #14
Death By An Arrow
Frost Gate Guardian
 
Death By An Arrow's Avatar
 
Join Date: Jul 2009
Profession: R/
Default

Although I'll likely change my passwords now atleast temporarily,
does it appear the worst thing were going to get is just spam?
or are we more endangered (with important info, etc. etc.)?

Mainly im just concerned about hacks, cause im not great at remembering passwords so i try to keep some similar (blah blah i know its bad...) but if its a real concern ill just write it down

Thanks in advance ^^
Death By An Arrow is offline   Reply With Quote
Old Jan 23, 2010, 04:21 PM   #15
Inde
Administrator
 
Join Date: Dec 2004
Default

Raven and death this is why we as quickly as possible have informed our users of what happened. We can't know the intent of the hack. As we recommended in our notice please change your emails and passwords immediately. Please also change any info that you used that may be the same elsewhere as well.
Inde is offline   Reply With Quote
Old Jan 23, 2010, 04:21 PM   #16
bsoltan
Bath Salt
 
bsoltan's Avatar
 
Join Date: Dec 2005
Location: UK
Guild: [SoF]
Default

Quote:
Originally Posted by Raven2201 View Post
What about the people who have the same email used for their GW account tied to guru as well?. That seems like it could pose a security issue to those users GW account.
Change your GW Guru email address?


edit: ninjad
bsoltan is offline   Reply With Quote
Old Jan 23, 2010, 04:22 PM   #17
End
One usernote
 
End's Avatar
 
Join Date: Dec 2007
Location: Spamadan...ugh...
Guild: Guess...I betcha can :D
Profession: E/
Default

Quote:
Originally Posted by Inde View Post
We can't know the intent of the hack.
It was NCsoft...they wanted to be able to blame someone else and this was the easiest way for them to do it...

On a side note....how would changing our emails now prevent anything? I mean...they already have the information...what would change if we changed our emails on this site now?

Last edited by End; Jan 23, 2010 at 04:24 PM..
End is online now   Reply With Quote
Old Jan 23, 2010, 04:29 PM   #18
Lucci_Slevin
Academy Page
 
Join Date: Nov 2008
Guild: Liars Cheats and Thieves
Default

Thank you for informing us.

However, for over a month, I have been trying to call attention to the fact that this site(and incgamers) was being targeted since at least late October. I felt I was disregarded by various mods on both sites.

Some of my posts were even deleted though admittedly they were about very specific security issues.

I still think there are other avenues for hackers to use but I will keep it to pms out of respect for security. I think you guys should consider the fact that they may have or can still breach even without you knowing.

Forum software at its core is meant to be dynamic and mod-able, so there will always be new tricks. As I said in another post(that was deleted) the software is for chat not storing vital info.

bottom line: use a unique pw for gw.
Lucci_Slevin is offline   Reply With Quote
Old Jan 23, 2010, 04:37 PM   #19
Cheferos
Pre-Searing Cadet
 
Join Date: Feb 2009
Default

Sounds like you fixed it first, and quickly, and told us as soon as possible. Thank you.
Cheferos is offline   Reply With Quote
Old Jan 23, 2010, 04:43 PM   #20
Riot Narita
Jungle Guide
 
Join Date: Apr 2007
Default

Quote:
Originally Posted by JR View Post
Right now we assume the hackers motivation was simply to obtain the list of email addresses, for the purpose of sending spam.
Really? I would have thought there were much easier places to break into, to get email addresses just for spam.

My suspicion is they were after email addresses for GW- or Guru-specific phishing attempts...

...Or email addresses to attempt direct GW login (use forum name for the character name, and try the top 100 most common passwords as per the "RockYou" thread... they might get lucky, and it seems they are getting desperate enough to try anything)

My thanks to the Guru staff for their responsible attitude and reaction to this.
Riot Narita is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 03:40 PM.


Vote on the Guild Wars Top 200
Guild Wars Top 200 - Cheats Free Guides, Downloads, Fansites. The Gold standard

Powered by: vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
 
Guild Wars is a trademark of NCsoft Corporation. Copyright© NCsoft Corporation. All right reserved.
© 2004 ArenaNet, Inc. All content of this website is copyright ArenaNet, a wholly-owned subsidiary of NCsoft Corporation.
All rights reserved. ArenaNet, Arena.net and the ArenaNet logo, as well as Guild Wars, are trademarks or registered trademarks of NCsoft Corporation.
All other trademarks are the property of their respective owners.
GuildWarsGuru.com: Advertise | Privacy Policy | User Agreement
 
MMO Guru Network
MMO DB