Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Outer Circle > Site Feedback

Reply
 
Thread Tools Display Modes
Old Jan 23, 2010, 11:49 PM // 23:49   #21
Darcy
Never Too Old
 
Darcy's Avatar
 
Join Date: Jul 2006
Location: Rhode Island where there are no GW contests
Guild: Order of First
Profession: W/R
Advertisement

Disable Ads
Default

Luckily, my GW account ID is an obsolete address from before I belonged to guru. Thanks for the info. Good luck with your fight.
__________________
That's me, the old stick-in-the-mud non-fun moderator.
(and non-understanding, also)
Darcy is offline   Reply With Quote
Old Jan 23, 2010, 11:52 PM // 23:52   #22
Inde
Site Contributor
 
Join Date: Dec 2004
Default

Quote:
Originally Posted by Riot Narita View Post
Really? I would have thought there were much easier places to break into, to get email addresses just for spam.

My suspicion is they were after email addresses for GW- or Guru-specific phishing attempts...

...Or email addresses to attempt direct GW login (use forum name for the character name, and try the top 100 most common passwords as per the "RockYou" thread... they might get lucky, and it seems they are getting desperate enough to try anything)

My thanks to the Guru staff for their responsible attitude and reaction to this.

As we stated we can't know the reason for the hack. Any speculation you have is the same as ours. I can tell you that valid emails are not easily obtained, and fetch quite a price. I would never attempt to downplay this incident, but I believe we have honestly and openly given the best information we can.

Last edited by JR; Jan 23, 2010 at 11:56 PM // 23:56..
Inde is offline   Reply With Quote
Old Jan 24, 2010, 12:00 AM // 00:00   #23
shoyon456
Desert Nomad
 
shoyon456's Avatar
 
Join Date: Jul 2006
Profession: D/
Default

Well, I already get spam on my main email, not associated with ANY gaming. Apparently my Aion and WoW accounts are repeatedly being hacked and in danger of being perma banned.

I changed both guru accounts to a 3rd email long ago, and my passwords for Guru1 and 2 are unique to guru and other sites I don't care much about.

That being said, guru has responsive/open staffing.
shoyon456 is offline   Reply With Quote
Old Jan 24, 2010, 12:06 AM // 00:06   #24
mlandry
Krytan Explorer
 
mlandry's Avatar
 
Join Date: Jul 2006
Profession: W/Me
Default

I get at least 4 emails for WoW phising scams every week even though I've only ever had a trial account for that game when it was released. I started getting some for Aion recently even though I don't even have that game.

I doubt it's going to be much different for GW. I've already had my account stolen once because of NCSoft's incompetent website security, thinking I was safe using the same pass there as ingame, and I've learned from my errors and have no passwords that match anywhere anymore.
mlandry is offline   Reply With Quote
Old Jan 24, 2010, 12:21 AM // 00:21   #25
Martin Alvito
Older Than God (1)
 
Martin Alvito's Avatar
 
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
Default

As always, you (the admins) handled this like professionals.

I'm sure everyone appreciates both your forthrightness and your effort here.
Martin Alvito is offline   Reply With Quote
Old Jan 24, 2010, 12:23 AM // 00:23   #26
Dima The Killa
Ascalonian Squire
 
Join Date: Nov 2005
Guild: Mallyx And Friends [OhNo]
Profession: E/
Default

i used to have all my important passwords be the same. email, gw, steam, and ncsoft. but i have even differentiated those when the ncsoft hing happened. but no way am i going to have same pass on important stuff as id o on forums lol.

o and if i do use the same email on here as my gw account what risk is that to my gw account? i cant think of any since there is no way they can figure out my pass. i don't see any reason to fret if they have the username and pass for guru because they can't really do anything useful with that info. but i am wondering if just having my gw email could be a prob.
Dima The Killa is offline   Reply With Quote
Old Jan 24, 2010, 12:27 AM // 00:27   #27
Smarty
Krytan Explorer
 
Smarty's Avatar
 
Join Date: Mar 2008
Location: England
Profession: Me/
Default

Thanks JR et al, very clear and open message to the community there, much appreciated.
Smarty is offline   Reply With Quote
Old Jan 24, 2010, 12:30 AM // 00:30   #28
JR
Re:tired
 
JR's Avatar
 
Join Date: Nov 2005
Profession: W/
Default

Quote:
Originally Posted by Dima The Killa View Post
o and if i do use the same email on here as my gw account what risk is that to my gw account? i cant think of any since there is no way they can figure out my pass. i don't see any reason to fret if they have the username and pass for guru because they can't really do anything useful with that info. but i am wondering if just having my gw email could be a prob.
I'd agree with your assessment that there isn't much risk if you only use that password for your Guru account. Sure they might have the account email, but they still need to guess the password AND match it with a character name.

Keep in mind they can access your game account through your NCSoft Master Account too, and they can get to that through an email account. So really you need to make sure nothing is using that compromised password.

Last edited by JR; Jan 24, 2010 at 12:33 AM // 00:33..
JR is offline   Reply With Quote
Old Jan 24, 2010, 12:31 AM // 00:31   #29
Thargor
Lion's Arch Merchant
 
Join Date: Mar 2006
Default

Thanks for the heads up on the issue guys.

In response to all those asking about if their forum and gw account info is the same... ARE YOU SERIOUS?
How many times has this subject been drug through the forums?
Learn to read, read the forums, read security related stuff on the web.
If anyone gets their account hacked because of this i dare say it is their own fault for being ignorant.
Thargor is offline   Reply With Quote
Old Jan 24, 2010, 12:54 AM // 00:54   #30
Bob Slydell
Forge Runner
 
Join Date: Jan 2007
Default

Thanks for the heads up.
Bob Slydell is offline   Reply With Quote
Old Jan 24, 2010, 12:57 AM // 00:57   #31
Death By An Arrow
Jungle Guide
 
Death By An Arrow's Avatar
 
Join Date: Jul 2009
Guild: The Kurzick Mob [Mob]
Profession: R/
Default

Alright, thanks for clearing that up... mod who answered my question

Another Q:

I realized my GW email is diff than this one, cause my GW email was the email i used way before i ever joined guru. Im still gunna change my password, but since they dont have the current email linked to my account, im safe..er right?

Im not used to hacks and such, living in a small town and what not
Death By An Arrow is offline   Reply With Quote
Old Jan 24, 2010, 12:59 AM // 00:59   #32
JR
Re:tired
 
JR's Avatar
 
Join Date: Nov 2005
Profession: W/
Default

Quote:
Originally Posted by Death By An Arrow View Post
Another Q:

I realized my GW email is diff than this one, cause my GW email was the email i used way before i ever joined guru. Im still gunna change my password, but since they dont have the current email linked to my account, im safe..er right?

Im not used to hacks and such, living in a small town and what not
Your Guild Wars account is fairly safe, yes, though it's a lot easier to find out an email address than it is to find out a password. I'd definitely get the password changed as soon as possible.

Once you've done that, you will be fine, provided you have changed that password for any account that used it.
JR is offline   Reply With Quote
Old Jan 24, 2010, 01:22 AM // 01:22   #33
Sir Skullcrasher
Hall Hero
 
Sir Skullcrasher's Avatar
 
Join Date: Jun 2005
Location: California
Guild: 15 over 50 [Rare]
Profession: W/Mo
Default

thanks for the heads up Guru Mods!

To be honest.. who ever is stealing information on a game that is 4.. (FOUR) years old is freaking... smart as hell! lol

Either way, I'm changing everything here on guru and on gw just in case!
Sir Skullcrasher is offline   Reply With Quote
Old Jan 24, 2010, 01:34 AM // 01:34   #34
Tortoise
Frost Gate Guardian
 
Join Date: Dec 2005
Guild: Daunting Tempest
Profession: Mo/
Default

I tend to use 1 password for all the non-important internet stuff I sign up with (forums and such) and just went and changed most of those. The important stuff all has unique passes.

In any case, thanks for the heads-up and your honesty in the matter. It is much appreciated.
Tortoise is offline   Reply With Quote
Old Jan 24, 2010, 02:06 AM // 02:06   #35
Goddess Of Defense
Lion's Arch Merchant
 
Goddess Of Defense's Avatar
 
Join Date: Feb 2009
Location: United States
Guild: One Thirty Three Seven [ムるるで]
Profession: P/W
Default

As for the mystery to how they got from one forum, to the next. Guildwarsguru, and guildwars2guru are on the same server; which made it very easy. This flaw is good financially but bad in security. you didn't see this coming, therefore nobody is at blame, it's just that's the reason they got in easily.
Goddess Of Defense is offline   Reply With Quote
Old Jan 24, 2010, 02:16 AM // 02:16   #36
Inde
Site Contributor
 
Join Date: Dec 2004
Default

Goddess, we do not believe they had root access to our server so this wouldn't explain what happened as simplistic as you put it. Our security was in place on every website and database housed there. A company usually wouldn't purchase separate servers just to run each individual website they have so yes, financially it makes sense for us to put multiple websites on the same server.

Good thought though!
Inde is offline   Reply With Quote
Old Jan 24, 2010, 02:40 AM // 02:40   #37
Sookie
Lion's Arch Merchant
 
Sookie's Avatar
 
Join Date: Jan 2008
Location: NoCenTex
Guild: [AKA] Guild Leader
Profession: R/
Default

With all the hacking going on, I created an email address just for guru and the "other" fansite a week ago. This new email address is in no way related to my GW account...just for the two fansites. Hopefully this was enough of a precaution.
Sookie is offline   Reply With Quote
Old Jan 24, 2010, 02:59 AM // 02:59   #38
Alesa
Academy Page
 
Join Date: Mar 2006
Default

Thanks so much for letting us know so quickly. Top notch you guys.
Alesa is offline   Reply With Quote
Old Jan 24, 2010, 03:12 AM // 03:12   #39
glacialphoenix
Desert Nomad
 
glacialphoenix's Avatar
 
Join Date: Jul 2008
Location: Singapore
Guild: Royal Order of Flying Lemmings [ROFL]
Profession: Mo/
Default

Thanks for the headsup.
glacialphoenix is offline   Reply With Quote
Old Jan 24, 2010, 03:36 AM // 03:36   #40
jonnieboi05
Forge Runner
 
jonnieboi05's Avatar
 
Join Date: Mar 2006
Location: Mableton, Georgia
Guild: Guild Ancestors Reunited [ギルド]
Default

Thank you for the head's up. I am not too concerned, my GW account's email is completely private and no one in this world has except me (it's not registered or anything. It's just an email I used to create the account and never logged into it since then).
jonnieboi05 is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:36 PM // 19:36.


Vote on the Guild Wars Top 200
Guild Wars Top 200 - Cheats Free Guides, Downloads, Fansites. The Gold standard

Powered by: vBulletin
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.