A few comments on Blizzard's account fixes

Craig234

Lifer
May 1, 2006
38,548
350
126
I'm one of those people who expresses sympathy to someone whose account gets hacked, and looks for what they did wrong, and warns people. But because I don't share my password (one exception that's not a problem), and am careful about what I run off the internet, years and years were safe. Until a week ago.

I don't know how, but my account got hacked. I noticed in less than 24 hours; had to retrieve and change my password, and found most of my chars stripped (all mail gone, nearly all bank gone, nearly all bags empty, nearly all coin gone, but oddly most of the worn gear still intact). Two chars had been moved to new servers.

So, I bought a new spyware catcher, ran three of them, notified Blizzard.

Why can't a company with over 10 million subscribers, revenue larger than some nations, write reasonable backup and restore software? What they do, after agreeing to restore the chars, is to take several days where I got an e-mail saying they were done after one char was restored to the wrong server, other chars not restored; no response to multiple e-mails when they said they would respond; a second e-mail saying they're done even though one char they were repeatedly told about the gold on has not had it restored; and all the items are sent in these massive e-mails for the player to try to sort out, instead of restoring the chars as requested to their status items where they were - on a certain day. They warn you that they can't even keep track of the modifers some items had (e.g., that 'Eagle' item with INT and STA for your mage could become a useless item.)

Previously, they had a patch where they announced a bug cause some bank items to be destroyed, and said to petition to get the items back. I immediately petitions that every one of my chars had the last 4 bank spots wiped out and asked for a restore. They told me they lost the petition, and then said that they did not have the data to restore any items.

They do, however, send multiple e-mails how it's up to me to keep my account from being hacked. Well, ya, sorta, but that's not a reason for them not to have reasonable restore.

It would seem Blizzard might also be able to write some code where the game checks itself for a password trapper when it starts.

It's an event, having the account hacked, that raises the question about 'do I really want to be spending so much time in this game anyway'.

They won't share any info on the situation regarding the theft, such as info on the payment for your chars being moved, or whether they investigate who did it much.

Anyway, just thought I'd post this since I'm sure many are also WoW players, and the ideas here apply to other MMO's.
 

lupi

Lifer
Apr 8, 2001
32,539
260
126
They do have backup software in place. But since it requires the network engineers to access, their normal useless support/gm schmucks try to get by without accessing it to speed their ticket answering time.
 

coloumb

Diamond Member
Oct 9, 1999
4,069
0
81
I too was in the same boat about a month ago - account hacked, nearly everything in my inventory gone, none of my character's armor/gear was stripped/moved, but my rogue's gear was damaged and logged near shadow labs. I received the initial "worthless" items back immediately and the remainder of my valuable items back a few days later.

I suspect my hack was either from an inside job [I mistakenly changed my pw to the same pw to an MMO forum I infrequently visit] or via a flash exploit. There was nothing on my system to indicate anything that would help someone hack into my account.

It would be very easy [and more profitable] for Blizzard to implement a more secure login setup - RSA SecurID setup. I think most gamers would gladly pay a one time fee [$5-$10] or a montly fee [code is sent to your mobile phone] to have a more secure system.

Eh - whatever the case, I've learned to only use 1 unique password for my WoW account and take weekly [sometimes daily] screenshots of all of my character's inventory in case my account is hacked again.
 

nanobreath

Senior member
May 14, 2008
978
0
0
What good would taking screenshots serve you?
Screenshots are not proof of ownership due to the easily being photoshoped, in addition the screenshots can easily be taken before the sell of a major item.

Blizzard replaces your items simply based on the records in their servers of what was sold/traded when your account was hacked.

To me it just seems like a bunch of wasted time screenshotting so often.
 

Craig234

Lifer
May 1, 2006
38,548
350
126
Originally posted by: nanobreath
What good would taking screenshots serve you?
Screenshots are not proof of ownership due to the easily being photoshoped, in addition the screenshots can easily be taken before the sell of a major item.

Blizzard replaces your items simply based on the records in their servers of what was sold/traded when your account was hacked.

To me it just seems like a bunch of wasted time screenshotting so often.

Screenshots aren't helpful as proof, but they are helpful for the ridiculous question from Blizzard, when you need a restore, 'what exactly did you lose?'

Like when their bank-slot bug destroyed items and I asked for that restore, they asked, 'what exactly was lost?' Well I don't remember! If you have a backup, you don't need to ask.

Coloumb, sorry that happened to you. It'd be nice to figure out the cause. I just won't go to the hassle you are with the screenshots.

Lupi, maybe they do, but when they closed out the ticked as 'can't restore', they may as well not have them, since they didn't use them.

There are hours ahead of getting the items back to normal. It is discouraging to have that happen.
 

treetops

Junior Member
Jun 21, 2008
7
0
0
I feel for you people, but you kinda should have had that anti-spyware before hand. As far as forums go you should never use the same password you use for your e-mail wow account etc.
 

CorCentral

Banned
Feb 11, 2001
6,415
1
0
Originally posted by: treetops
I feel for you people, but you kinda should have had that anti-spyware before hand. As far as forums go you should never use the same password you use for your e-mail wow account etc.

I played D2 for 5 years and never had any problems. Had the same PW for those 5 years. Everyone around me tried those hack programs and then cried when all their stuff was gone :laugh:

Like you say, just use decent anti spyware/virus software (Kaspersky), and you'll never have problems, as long as you don't share your PW with your friends :laugh:

I got out of it a few years back and sold all my stuff to a friend when this was popular and not frowned upon. Got an easy $90. for my gear.......but...... I deleted the characters! ;)



Edit--- D3 FTW! (palms sweating)........ no MMO, no MMO, no MMO!
 

CKent

Diamond Member
Aug 17, 2005
9,020
0
0
Do you read the official forums? Like any good trainwreck, sometimes I can't resist... anyway, something I've noticed there lately is a lot of malicious URLs being linked which look similar to known safe URLs, including wor1dofwarcraft, worlbofwarcraft, warcraftmoviess, and worldofrdas (.com). If you click on links there it's possible one of those got you if you weren't paying attention. About the only links on those forums I ever follow are in the UI pic threads, and while I haven't seen anything suspicious in them yet, I double check everything just in case.
 

Craig234

Lifer
May 1, 2006
38,548
350
126
Originally posted by: treetops
I feel for you people, but you kinda should have had that anti-spyware before hand. As far as forums go you should never use the same password you use for your e-mail wow account etc.

I'd already bought ad-aware, but it didn't catch it, it seems. Then I ran spybot, and it didn't either, it seems. Then a friend who had this happened recommended Spyware Doctor, and that did seem to find it (found a 'Trojan'). I didn't test each (no way to test them but to see if the thief got the password again), but did run them all and that seemed to take care of it.

It wasn't related to using the same password; when it first happened, I changed the password to one I've never used, then logged on, and the thief got the password again.

Do you read the official forums? Like any good trainwreck, sometimes I can't resist... anyway, something I've noticed there lately is a lot of malicious URLs being linked which look similar to known safe URLs, including wor1dofwarcraft, worlbofwarcraft, warcraftmoviess, and worldofrdas (.com). If you click on links there it's possible one of those got you if you weren't paying attention. About the only links on those forums I ever follow are in the UI pic threads, and while I haven't seen anything suspicious in them yet, I double check everything just in case.

Good guess, but I didn't do that.

I still don't know how the trojan got in - there's always a chance I clicked something I didn't mean to. It would be nice to be able to find out and go after the distributor.

They still haven't restored several chars - it seems like I have to name every specific thing I want done, that saying 'restore all my chars that were stripped' is just ignored.
 

ultra laser

Banned
Jul 2, 2007
513
0
0
You guys are lucky blizzard is helping you at all. You being unable to run a secure computer is not their responsibility.
 

IEC

Elite Member
Super Moderator
Jun 10, 2004
14,582
6,012
136
YARINLPMMOs

Yet Another Reason I No Longer Play MMOs (besides the obvious one: time)
 

Craig234

Lifer
May 1, 2006
38,548
350
126
Originally posted by: ultra laser
You guys are lucky blizzard is helping you at all. You being unable to run a secure computer is not their responsibility.

Some with sense would say they're lucky to get the $15/month and this is an appropriate service.

They have plenty of restrictions on it, you are not going to get it done over and over, apparently.

Since there is a need and they do it, it'd be better for players and them to have better tools. But there's always someone who has to 'blame the victim' on message boards.
 

Beev

Diamond Member
Apr 20, 2006
7,775
0
0
OP you might have gotten hit with that Flash vulnerability. I hear it was pretty vicious.
 

Anubis

No Lifer
Aug 31, 2001
78,712
427
126
tbqhwy.com
Originally posted by: Beev
OP you might have gotten hit with that Flash vulnerability. I hear it was pretty vicious.

recently im sure most got hacked because of this

someone in my guild did, it can come from a non wow related site. millions of people play wow, id say 1/2 of them have no idea what flash is
 

Craig234

Lifer
May 1, 2006
38,548
350
126
Originally posted by: Anubis
Originally posted by: Beev
OP you might have gotten hit with that Flash vulnerability. I hear it was pretty vicious.

recently im sure most got hacked because of this

someone in my guild did, it can come from a non wow related site. millions of people play wow, id say 1/2 of them have no idea what flash is

I'm not familiar with the flash vulnerability, but I did play that 'hardest game' that was linked here recently, which might have been a flash game.