PDA

View Full Version : GUYS PLEASE READ - YOU MAY BE IN DANGER!!!


Illustra
09-26-2006, 02:34 PM
Guys and gals..

I'm afraid I have some very disturbing news.

In doing research and investigating my situation.. account mishap and the like.. I've come to learn that curse-gaming.com may be part of the cause of all these recurring hacked accounts.

It has come to my attention.. that in Blizzard's attempts to track the culprits... these.. these.. bastards!! *cough* Hackers.. sorry.. got carried away there for a sec.. LOL Ok ok.. in all seriousness now..moving on..

As you can imagine, Blizzard has been getting numerous complaints of hacked accounts. They seem to be finding some similarities between one and the ohter. Now one of the factors may be.. as Addiarmadar mentioned.. a WoW video being compromised.. whether it be from Google.com.. or Youtube.com. However, I think it's far more serious than that.

While investigating said accounts.. trying to find what's causing all this, it's been reported that Curse-gaming.com may be the common denominator.

IT SEEMS THAT ONE OF CURSE-GAMING.COM'S SPONSORS.. HAS IMBEDDED A KEY-LOGGER PROGRAM INTO ONE OF THIER BANNERS!!!

UNDERSTAND THIS CLEARLY AND CAREFULLY.

See, Blizzard has narrowed the possiblities down to the fact that some mods dowloaded from numerous sites may be the overall cause. In doing futher research they found that ALOT of these users NEVER EVEN DOWNLOADED any mods... so - in continuing investigations found that yes, in one of these banners from a sponsor.. there was a program that logs keys stroked. Since this page and/or that of the sponsors may not be necessarily sanctioned by Blizzard there is no way in telling who and what has access and can manipulate the system.

GUYS,

Simply just UPLOADING the page itself is all it takes. You don't have to download anything.. you don't have to click on anything.. you don't have to login or anything to view the forums on this page... NOPE! NADA SINCH SILCH is required.. JUST typing http://www.curse-gaming.com and loading this page is ALL IT TAKES!!!

This came at a huge shock to me too.. and makes perfect sense.. seeing as how I never downloaded anything weird or off-based. Basically just UPLOADING the page - looking thru forums.. reading WoW info.. and then, of course, the infamous download of mods.. can very well put you at risk.

NOTE: Please note that this key-logger program ONLY works in conjunction with WoW... It will NOT track or log keys stroked for other internet accounts you may hold... JUST WOW.. for tracking anything else would be too large.. and they can't process all that information.

TIP:

One big tip I learned tho.. is that if you have the "Remember me" feature enabled.. that protects you a tad bit more.. only because if and when you load the page and if the program installs itself into your computer.. they won't be able to do much.. because you aren't typing in your log-in name.. just your password. They can't do much with one without the other.

Please all, I URGE this of you.. if you have loaded curse-gaming.com for any reason whatsoever.. change your passwords.. THIS INSTANT... enable the "Remember me" option for future use.. and just be careful.

I noticed Moldypudding also made a good point about the SVhost thingy magigy - just try at all costs to protect yourselves.. believe you me.. you do NOT want this to happen to you.

Be careful all.. and stay safe!!

Love you all to pieces,
ILLY[/color]

addiarmadar
09-26-2006, 03:32 PM
That is very possibly and can name many exploits in IE that would allow such to happen. Simply dropped by NOT USING IE! Use Maxthon or FireFox and use their add/pop-up blockers. I never see the adds from curese-gamming with Maxthon 8) Would doubt that these gold vender adds will have this bug in them.

Where did you get the report of curse-gaming.com maybe compromised?

Strong advice for those to NOT visit gold-farmer sites too for my AV slapped down a few trojans rigth off the homepage.

Seckks
09-29-2006, 04:28 AM
http://www.microsoft.com/technet/securi ... 6-055.mspx (http://www.microsoft.com/technet/security/Bulletin/MS06-055.mspx)

Recently released hotfix for IE to prevent these keyloggers from ever happening from curse gaming and the like.