Ultimate Online Forums
Go Back   Ultimate Online Forums > Ultima Online > Ultima Online General Discussion

Ultima Online General Discussion Forum for general chat on UO.

Ultima Online General Discussion Thread, Hacking Warning!! in Ultima Online
 
Thread Tools
Old 1st January 2006, 03:06 AM   #1
Visiting from Robin Hood Country
 
Petra Fyde's Avatar
 
Join Date: Jul 2005
Shard: Europa
Posts: 179
Thanks: 1
Thanked 14 Times in 6 Posts
Petra Fyde is unknown
Hacking Warning!!

Multiple people on 2 shards have recently been hacked using the same method. Don't let it happen to you

If you are targetted you will recieve a mass icq message. This will in all probablity be coming from a hacked icq account, so someone on your list.

Message says (paraphased):

I'm quitting uo, selling stuff, visit this web site (link)

The link will contain a .wmf virus file which downloads a key logger.

So far this has happened on Origin and Atlantic. On Atlantic the RP community was targeted.

Please take this warning to heart. Follow NO LINKS that you aren't 100% sure of, even if they're sent to you by someone you think you know.
__________________
Petra Fyde is offline   Return to Top Reply With Quote
Old 1st January 2006, 05:59 AM   #2
 
viczerk's Avatar
 
Join Date: Dec 2005
Shard: chessy
Posts: 70
Thanks: 0
Thanked 2 Times in 2 Posts
viczerk is unknown
Re: Hacking Warning!!

tks for the warning , much appreciated here
__________________
viczerk is offline   Return to Top Reply With Quote
Old 1st January 2006, 06:19 AM   #3
Visiting from Robin Hood Country
 
Petra Fyde's Avatar
 
Join Date: Jul 2005
Shard: Europa
Posts: 179
Thanks: 1
Thanked 14 Times in 6 Posts
Petra Fyde is unknown
Re: Hacking Warning!!

I asked a few questions. Here they are, with the answers I got:
Quote:
Q Is it possible for this virus to be included in someone's board siggie?
AYes, and sig isn't the only way.

Q Or can you only use .jpg and .gif for those?
A ADoesn't matter. As for how to do it, I won't reveal, but it's seriously simple.

Q should we all turn off the ability to see siggies for the time being?
A Yes, avatars too.

Q he used a link. Was that because it's the only way it can be done?
A No.

Q because it's the only way that particular person could do it?
A Because it was probably the only way he was aware of doing it.

Going to Start / Run and typing "regsvr32 -u %windir%\system32\shimgvw.dll" without the quotes and OK'ing out helps a little. This disables the image/fax viewer in XP, but as said before, the problem isn't shimgvw.dll, it's the GDI32.DLL's faulty escape()-function which gets called, and this is a core part of Windows. Unregistering shimgvw.dll helps, but doesn't make you completely immune. To undo the change, simply remove the -u from the line, so type "regsvr32 %windir%\system32\shimgvw.dll" without the quotes, after Microsoft releases a fix.

Best is to unregister the shimgvw.dll, use a good antivirus program (check eWeek's yesterday's article here http://www.eweek.com/article2/0,1895,1907131,00.asp to see which antivirus softwares are doing well with this issue), turn DEP fully on with WinXP SP2 if you have it and then hope and pray. Instuctions on how to turn DEP on is at http://www.microsoft.com/technet/sec...nfxp.mspx#EFAA but remember, whatever you do, there currently is NO fix that will make you 100% immune to this. =/

Two different ways are known to exploit the vulnerability and a third possible way is not confirmed yet but seems likely.

Keep checking these sites for news with the issue:

http://www.us-cert.gov/current/current_activity.html

http://www.f-secure.com/weblog/

Quote from F-Secure's Mikko Hyppönen (one of world's leading virus experts) about this issue today: It's going to get worse.
On every board I post I've now turned off the options to see any kind of picture. Not that I don't trust the people currently on them, but because at least one account was purpose made on Stratics to try to infect people (the 'he' referred to in the questions Jarno answered for me). Sorry if the questions don't make sense, Jarno picked them out of the rest of the text I posted.
Petra Fyde is offline   Return to Top Reply With Quote
Old 1st January 2006, 06:23 AM   #4
 
viczerk's Avatar
 
Join Date: Dec 2005
Shard: chessy
Posts: 70
Thanks: 0
Thanked 2 Times in 2 Posts
viczerk is unknown
Re: Hacking Warning!!

isn't it amazing how or what CHEATER will do to prosper? it is getting to the point all i wanna do is scream lol, but wth can ya actually do to make these ppl stop? you might succeed to keep them away for awhile, but like a bad cold, it will eventually get ya....sorry for the rant.
__________________
viczerk is offline   Return to Top Reply With Quote
Old 1st January 2006, 06:32 AM   #5
El Mero Mero
 
Santi's Avatar
 
Join Date: Apr 2004
Shard: Legends
Posts: 592
Thanks: 0
Thanked 0 Times in 0 Posts
Santi the FairSanti the FairSanti the FairSanti the FairSanti the Fair
Re: Hacking Warning!!

I can't believe people spend so much time doing this sort of thing. I don't just mean these a** clowns but the ones that make viruses and worms and all that trash too. I can't understand the purpose.
Santi is offline   Return to Top Reply With Quote
Old 1st January 2006, 06:33 AM   #6
 
viczerk's Avatar
 
Join Date: Dec 2005
Shard: chessy
Posts: 70
Thanks: 0
Thanked 2 Times in 2 Posts
viczerk is unknown
Re: Hacking Warning!!

i believe ppl like that do it just for kicks, and to make our lives misreable
__________________
viczerk is offline   Return to Top Reply With Quote
Old 1st January 2006, 11:24 AM   #7
Pretty Nice Disguise, isn't it?
 
Snowy's Avatar
 
Join Date: Nov 2005
Shard: Lake Superior
Posts: 1,135
Thanks: 0
Thanked 0 Times in 0 Posts
Snowy the KindSnowy the KindSnowy the KindSnowy the KindSnowy the KindSnowy the KindSnowy the KindSnowy the Kind
Re: Hacking Warning!!

We are talking about 'antisocial' people here, probably combined with an ego the size of a house...... If they will do it for the sake of stealing a game code, they will do it in far worse ways if undiscovered over time. Just my opinion....
__________________
~
"It's definitely a Bubble Bath Day.". ~ Dove Promise
~
Snowy is offline   Return to Top Reply With Quote
Old 1st January 2006, 11:41 AM   #8
Visiting from Robin Hood Country
 
Petra Fyde's Avatar
 
Join Date: Jul 2005
Shard: Europa
Posts: 179
Thanks: 1
Thanked 14 Times in 6 Posts
Petra Fyde is unknown
Re: Hacking Warning!!

One of the players on Europa works in IT Security. He has provided this information:
Quote:
If you use internet explorer you could go to Tools -> Internet options -> Advanced, scroll down to the multimedia section and untick "Show pictures" and untick "play animations". Pictureless internet might be kinda boring, but it's safer

In Firefox, you go to tools -> options -> web features and can either untick load images, or tick the "from the originating website only". The second option will prevent most signatures, avatars etc displaying on forums, but still leave you with emoticons. Not quite as secure, but will still help a bit.

Potentially you could get send one of these malformed piccies in an e-mail too, so use a web-based browser with the pics turned off to read e-mails.
It makes the boards look kinda weird, but I feel safer having done this.
__________________
Petra Fyde is offline   Return to Top Reply With Quote
Old 1st January 2006, 05:36 PM   #9
Diablo@LLSGUILD.COM
 
Richard's Avatar
 
Join Date: Nov 2005
Shard: Atlantic
Posts: 83
Thanks: 0
Thanked 0 Times in 0 Posts
Richard is unknown
Re: Hacking Warning!!

just look at ebay u will see why they doin , is big r/l gold..
__________________
Richard is offline   Return to Top Reply With Quote
Old 1st January 2006, 05:42 PM   #10
El Mero Mero
 
Santi's Avatar
 
Join Date: Apr 2004
Shard: Legends
Posts: 592
Thanks: 0
Thanked 0 Times in 0 Posts
Santi the FairSanti the FairSanti the FairSanti the FairSanti the Fair
Re: Hacking Warning!!

Well, I know they are just some pimply faced scrwany nerds doing it so...I would love to catch one and beat the snot outta them. And, if it happens to be some big smart ogre...I would just have to make sure I had a pipe.

Gold. There are easy ways to make gold in the game where you don't have to risk getting in trouble over.
Santi is offline   Return to Top Reply With Quote
Old 2nd January 2006, 02:20 AM   #11
Wycorp--Dwarf Hunter
 
Ezekiel's Avatar
 
Join Date: Jul 2005
Shard: Area 52
Posts: 2,504
Thanks: 0
Thanked 8 Times in 6 Posts
Ezekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the HonestEzekiel the Honest
Re: Hacking Warning!!

Unfortunately, its a "Wny earn it when you can steal it?" mentality.

Is there a file thatll pop up thru task manager that would let someone know if they are infected?
__________________
Ezekiel is offline   Return to Top Reply With Quote
Old 2nd January 2006, 02:27 AM   #12
Visiting from Robin Hood Country
 
Petra Fyde's Avatar
 
Join Date: Jul 2005
Shard: Europa
Posts: 179
Thanks: 1
Thanked 14 Times in 6 Posts
Petra Fyde is unknown
Re: Hacking Warning!!

I understand most of the major anti virus people have it covered now.
Make sure your definitions are upto date, and that your checker is set to 'all files' rather than 'infectable files'. This file type was previously thought to be uninfectable.
Thought wrong didn't they?
__________________
Petra Fyde is offline   Return to Top Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hacking Dell: Overclocking the XPS 630 Solidchrome Tech Forum 0 3rd March 2008 08:24 AM
WARNING!!! Hackers sending out phishing attempts for accounts!!! WARNING!!! Tabbitha News & Developer's posts 1 5th September 2007 09:23 AM
why do i have a warning?? vanator Ultima Online General Discussion 11 7th August 2006 12:57 PM
Hacking of Account situations reported on Sonoma ... Queen Mum Sonoma 5 31st December 2005 03:35 PM


All times are GMT -6. The time now is 01:54 AM.


Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Template-Modifications by TMS