We have detected that cookies are not enabled on your browser. Please enable cookies to ensure the proper experience.
Page 2 of 3 FirstFirst 1 2 3 LastLast
Results 26 to 50 of 65
  1. #26
    Join Date
    Mar 2007
    Posts
    191

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Orca11 View Post
    Generally even weak passwords can sufficient is the host (Turbine) implements a lockout after several failed login attempts (even 50-100 protects all but the weakest password).
    While that is true for targeted attacks, it doesn't apply for other means of brute force or dictionary attacks. A common practice for systems with a large user base is to attack every username with the same password one time. The more users on the system, the more likely that someone will use that password. You can see how this can easily overcome a lockout policy and easily find weak passwords. If the majority of your password can be found in the dictionary, it's probably not safe.

  2. #27
    Join Date
    Feb 2007
    Posts
    29

    Re: Account Hacked? What did they Steal?

    The majority of the recent account compromises come from players using the same username and password across multiple games, forums, or websites. When any one of these locations are compromised, it can lead to any number of other sites, games, or forums being compromised for that user. This is why we suggest that all of our players use a unique username and password for our games, in addition to regularly running anti-virus software and being aware of phishing or spoofing websites and e-mails. If you are concerned about account compromises, make sure to change your password regularly and be vigilant for potential spoofing or phishing attempts.

    You may review our information about these compromises in our Account Support forum, and specifically in this forum thread.

  3. #28
    Join Date
    Jul 2009
    Posts
    331

    Re: Account Hacked? What did they Steal?

    Thanks for that Nod! I'll make sure to change and rotate all of my Passwords!
    .
    R.I.P. Nidor of Brandywine (1970-2012)

  4. #29
    Join Date
    Dec 2007
    Posts
    144

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by BetterOffDead-2 View Post
    While that is true for targeted attacks, it doesn't apply for other means of brute force or dictionary attacks. A common practice for systems with a large user base is to attack every username with the same password one time. The more users on the system, the more likely that someone will use that password. You can see how this can easily overcome a lockout policy and easily find weak passwords. If the majority of your password can be found in the dictionary, it's probably not safe.
    Huh... never considered that approach... you stay away from my box, k?
    [charsig=http://lotrosigs.level3.turbine.com/0b20c00000007f807/01001/signature.png]Dolgrath[/charsig]

    "You have no friends yet."

  5. #30
    Join Date
    Sep 2009
    Posts
    2,962

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Varenthor View Post
    I don't understand... how is an account hacked so easily? Is there any other way they can get to you other then a keylogger site or a download onto your computer from an unsafe site?
    A Windows PC doesn't have to visit known unsafe sites anymore. Most malware these days comes from legitimate sites that have been manipulated into serving out pieces of malware. The safety software makers are losing the battle for being up-to-date big time.

    Turbine in their wisdom has decided that you now use your in-game password for logging into the forums. That means that a keylogger attached to your web browser will get your in-game password. Previously that was only the case when you actually logged into your subscription account.

    I am not aware of a keylogger that has been specialized to attach itself to the LOTRO launcher, or any MMO launcher for that matter. I am aware of a bazillioquadrozuple keyloggers that attach to web browsers.

  6. #31
    Join Date
    Sep 2009
    Posts
    2,962

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Nod View Post
    The majority of the recent account compromises come from players using the same username and password across multiple games, forums, or websites.
    How do you know that?

    The only way you could know that is if you tried the LOTRO login on different games, websites or forums which I bet you did not do.

  7. #32
    Join Date
    Dec 2007
    Posts
    3,808

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Darmokk View Post
    How do you know that?

    The only way you could know that is if you tried the LOTRO login on different games, websites or forums which I bet you did not do.
    because a lot of people admit to doing that exact same thing. It's not an uncommon occurance, especially with the abundance of websites and places asking for logins. A lot of people will use 1-3 standard passwords for everything. And the numbers that use simple things for passwords (like "password", "12345", their names, or other simple things) is amazing.

    Brute force doesn't happen, people not being careful with their account information does.

    Phishing is also a major source of getting account info. I'm amazed at how many people get the poorly written emails that purport to be from Blizzard, Turbine, Facebook or some other company that says your account will be deactivated unless you click on the following link and enter in your account name and password- and then do it! One compromised account right there, and likely more than one with the way people repeat user names and passwords.

    The simple truth is that 99% of hacked accounts result from the account holder doing something stupid somewhere along the way, without realizing it. Not keeping their computer secure, scanned, and cleaned; getting caught by a phishing scam; not being careful with their usernames and passwords. It's almost always something the user did somewhere, sometime.
    Firefoot: Elendale (hunter) Galorlas (champ) Grimlaff (warden) Corny (warg)

  8. #33
    Join Date
    Sep 2009
    Posts
    2,962

    Re: Account Hacked? What did they Steal?

    Well, I've never seen anyone admit to it.

    And I highly doubt they admit it to a GM when they are trying to get their gear back.

  9. #34
    Join Date
    Oct 2007
    Posts
    219

    Re: Account Hacked? What did they Steal?

    This happened to me months ago, well before F2P, and I got cash given back to me by GM's, but they all told me never to keep my forum password the same as my game password, yet what does Turbine do, MAKE you use the same log in for both... kinda counter productive, and against what they themselves have advised of.

  10. #35
    Join Date
    Mar 2007
    Posts
    5,190

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Orca11 View Post
    Huh... never considered that approach... you stay away from my box, k?
    It's actually what happened to my steam account.

    I found out what happened.

    One of my ex roomates had taken my WoW account after I stopped playing, paid for it and such cause I wasn't planning on returning to play that game.

    He got phished, lost one of his accounts and my account before he got things fixed.

    Now my steamid was a different login name than my WoW account, but they DID happen to have the same password. I didn't change steam's password for quite some time because it autologs in on windows startup.

    Plus whenever I have to change passwords frequently I tend to forget them in this case I had forgotten that I already had used that password on another account.

    So what happened is the hacker brute forced it, trying the same password across as many steam accounts as they had names for, found the one it worked on, and hijacked it.

  11. #36
    Join Date
    Nov 2007
    Posts
    3,631

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Vedwed View Post
    This happened to me months ago, well before F2P, and I got cash given back to me by GM's, but they all told me never to keep my forum password the same as my game password, yet what does Turbine do, MAKE you use the same log in for both... kinda counter productive, and against what they themselves have advised of.

    Yeah, this really bothers me, but what are we going to do about it? Nothing, because they changed their system and if we want to be able to post we HAVE to use our account name and pw.....just seems counterproductive and very stupid that they did this to us.
    [COLOR=DeepSkyBlue][charsig=http://lotrosigs.level3.turbine.com/032020000000affe8/signature.png]Larriel[/charsig]
    Lifetime Member since November 2007
    [/COLOR]

  12. #37
    Join Date
    Sep 2010
    Posts
    5

    Re: Account Hacked? What did they Steal?

    My account has been Banned because I got Hacked ,I post with this f2p account because I cant even log in forum with my original account.


    Yesterday I replied and asked to turbine to lift the suspension , how much time I'll have to wait ? 4 - 6 days ?
    why me (the victim) got my account banned ??


    I dont understand ...


    I wanted to stop lotro after being hacked, then I just took the thing in the positive way (after all its just a game) but now, I cant play anymore because of this stupid ban and I'm very upset

  13. #38
    Join Date
    Apr 2007
    Posts
    1,744

    Re: Account Hacked? What did they Steal?

    Many many times accounts get hacked by being foolish enough to use your account log in
    info in the forum log in data.
    Forums are one of the most easily accessed things on the internet

    Oh wait, Turbine switched over to exactly that.


    BINGO!

  14. #39
    Join Date
    Jun 2007
    Posts
    2,313

    Re: Account Hacked? What did they Steal?

    I have 7 characters.

    2 that are L65 and 2 in their 30s that are major crafters - they were all picked clean. Everything that could possibly be sold was sold and all my gold was gone.

    I had three others that have never developed and are basically storage mules. 1 of those was picked clean and all his housing and cosmetic storage was gone. The last two only had their money gone but they never had much to begin with having never gotten to L20.

    I was unhappy at first that my stuff was not returned, I was only given gold. But it helped a great deal that they gave me more gold than each character had prior to the hack and all totaled it was more gold than I ever had at any time in the game. But I was never rich, I never had more than 20 gold between all 7 characters at any one time.

    The payout was scaled downward based on level of each character and what they lost. In the case of the two high-level characters they gave enough that I could equip and have cash left over to spare.
    Nobigar Proudbelly - L35 Grand Master Chef, 3 Myrtle Court, Cropfurrows, Southfarthing, Landroval; Gaelivor - L65 Hunter - Lorien; Raeph - L38 Historian - Breeland; Daintybelle Oakenchest - L 65 Midwife - Blue Mountains.

  15. #40
    Join Date
    Mar 2007
    Posts
    265

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Nod View Post
    The majority of the recent account compromises come from players using the same username and password across multiple games, forums, or websites. When any one of these locations are compromised, it can lead to any number of other sites, games, or forums being compromised for that user. This is why we suggest that all of our players use a unique username and password for our games, in addition to regularly running anti-virus software and being aware of phishing or spoofing websites and e-mails. If you are concerned about account compromises, make sure to change your password regularly and be vigilant for potential spoofing or phishing attempts.

    You may review our information about these compromises in our Account Support forum, and specifically in this forum thread.
    Nod, I'm sure we'd love to avoid using our game login information on any other game, forum, or website, yet you folks are forcing us to do exactly that. I can't bring myself to log in to the game forums from anywhere other than home now, for this very reason. I feel I would be jeopardizing my account, to do so.
    [COLOR=Cyan][B][charsig=http://lotrosigs.level3.turbine.com/08207000000005143/01000/signature.png]Lancelyn[/charsig][/B][/COLOR]

  16. #41
    Join Date
    Apr 2007
    Posts
    7

    Re: Account Hacked? What did they Steal?

    I just got my account hacked. I use the LOTRO forums so much that I didn't even know they had switched over the forums login. I did everything right. My computer is clean and my e-mail account was unhacked. How did they get my password? no clue. How did they change my e-mail with turbine when my e-mail was not hacked? clueless. My e-mail password is different than any other password to avoid trouble. I NEVER use gold sellers and the like. Heck, I have even been known to mess with gold farmers in-game if I find them. I HATE that kind of ****. Turbine really dropped the ball this time. How can I possibly continue to play when I know a hacker can steal it at any time? Please understand, I have been playing since open beta. I have every kind of crafter and spare toons full of crafting components.(did) What about my shards for making legendary items? Gold does not fix everything, it's just a bandage. Try buying rad gear with gold. I heard that WOW can roll your toon back so you get everything lost except the last few days/weeks. So, why can't turbine do more to protect us? I have spent between 3-4 hundred dollars on this game. You would think they could beef up security, not dumb it down. What were they thinking with the login thing? I have a lifetime account now (didn't in the beginning) and this is the first time I am seriously considering quiting the game. It seems such a waste, but I can't stomach the thought of all that work down the drain. I wish this kind of thing was punishable, but how do you arrest someone on an American law when they are in asia? I have an idea. Give the asians there own LOTRO server and then ban/block all aisa IPs from the American and European servers. Problem solved.
    P.S. yes I know there are ways to 'hide' your IP, but if the turbine launcher checked with windows it could see things like time zone and the language windows was installed in.

  17. #42
    Join Date
    Sep 2010
    Posts
    5

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by the_gaming_ogre View Post
    How can I possibly continue to play when I know a hacker can steal it at any time?
    I understand you and I feel the same ./..

    but as turbine wrote me before BAN my account

    'Please note that this does not indicate in any way that Turbine has been compromised; in most cases this indicates a security issue on the computer used to play the Lord of the Rings Online'

    I'm a clean PC user like you but It's my fault

  18. #43
    Join Date
    May 2007
    Posts
    1,889

    Re: Account Hacked? What did they Steal?

    I got my World of Warcraft account Hack. But the funny thing is. I never Had a War of Warcraft account :P. So I went to the company Blizzard.com reported it. Not the Hack Website that they wanted me to go to and reported it.
    .

  19. #44
    Join Date
    Aug 2009
    Posts
    13

    Re: Account Hacked? What did they Steal?

    Hiulariously, I surf the web like crazy. I go to joke sites, junk sites, news and blogs, everything. I've been MMPORGing since 199x. So has my wife. We've kept a home lan attached to the internet since there has BEEN an internet. Guess what? After dozens of accounts to play, not one time have we been hacked. Why?

    We're not kids. Kids do weird **** they don't mention in their emails. ALWAYS. It's always 'a friend I loaned the account to", "I bought the account on ebay","I have afriend you plays on my account" yada yada yada. Even childlike computer security, account security and password security can stop hackers without a backdoor randomly targeting misc. accounts. So please...no more whing about 'I lost everything , please help' stupidity. You gave you little brother the passowrd, you shared accounts with your "bro" (that affectation never ceases to keep me laughing), you were an idiot, and your lying now.

    There was like, one instance I've ever heard of, where real people without acting like ******s had accounts hacked, and they uploaded a trojan from a website by clicking bad links.

  20. #45
    Join Date
    Dec 2007
    Posts
    3,808

    Re: Account Hacked? What did they Steal?

    Ogre and others who've been hacked. I'm sorry your account has been hacked. Really. That sucks. But have you read through this thread and some of the advice given? It may be junk on your computer. It may not be. You may have been phished- received an email saying your account was going to be canceled unless you entered the information on a website- that turns out to be a hackers site who just stole your information. You may have given out your account name and/or password in other areas- to friends to share, used the same ones on other accounts, or a variety of different ways. And it may have actually happened months ago and you don't remember it.

    They don't need your email login and password to change your email address on your Turbine account. Turbine doesn't send out confirmation emails to change the email address on the account, even though they should.

    But all of that to say is that somewhere along the way you let a hacker have access to your information without knowing it. Not even necessarily recently, it could have been 6 months ago.

    Have you changed your password recently? You should every 30 days. 60 at the most.

    Do you use the same account and/or password in other places? Bad, bad, bad and makes it easy if someone gets one to get others from you. Don't do it.

    Are your passwords hard to guess or easy? Are they a single word or a date? To simple. Is it a mix of letters, numbers and symbols in a seemingly random fashion? That's what it needs to be.

    There are a lot of other things that you should be doing to protect yourself. Unfortunately the vast majority of people who get hacked haven't been doing even the basic things to keep themselves safe. Then they blame the game companies or others. The basic reality is- if you don't want to get hacked then you need to make it as hard as possible for the hackers to get your information. Be careful, be informed, be protected, don't fall to traps, and protect yourself.
    Firefoot: Elendale (hunter) Galorlas (champ) Grimlaff (warden) Corny (warg)

  21. #46
    Join Date
    Apr 2009
    Posts
    97

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Darmokk View Post
    A Windows PC doesn't have to visit known unsafe sites anymore. Most malware these days comes from legitimate sites that have been manipulated into serving out pieces of malware. The safety software makers are losing the battle for being up-to-date big time.

    Turbine in their wisdom has decided that you now use your in-game password for logging into the forums. That means that a keylogger attached to your web browser will get your in-game password. Previously that was only the case when you actually logged into your subscription account.

    I am not aware of a keylogger that has been specialized to attach itself to the LOTRO launcher, or any MMO launcher for that matter. I am aware of a bazillioquadrozuple keyloggers that attach to web browsers.
    I've been wondering about this issue myself since the F2P and new forums. I REALLY liked having the forums and game logins totally different. I seriously think we should go back to separate account names/passwords.

    Something else for people to think about is anyone else(college roommates, friends, etc) who might have access to your keyboard while you're at work, school, bathroom, etc. . Sometimes people think they are being "funny" and will access your computer and websites you normally wouldn't visit, thus exposing you (potentially) to keystroke loggers-programs that sit and wait for you to type anything, and then they send this info to data miners to find login names and passwords for anything and everything. Also, going to [insert monetary unit]-selling websites and making a purchase almost guarantees you're going to get a keystroke logging virus.

    Still, I think we need to go back to totally separate account names/passwords for forums and the game itself. PLEASE.

  22. #47
    Join Date
    May 2007
    Posts
    4,190

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by Nod View Post
    The majority of the recent account compromises come from players using the same username and password across multiple games, forums, or websites. When any one of these locations are compromised, it can lead to any number of other sites, games, or forums being compromised for that user.
    You mean like the move Turbine recently made to use a player's primary in-game account login and password to access all game related platforms like the Forums, which previously had a separate login and password?

    I have heard 18 cases since F2P just like that described by the OP. I have been playing this game for 3 years, and prior to F2P and the consolidated account login switch over, I had never heard of one case...not ONE. I do not believe it is a coincidence that players have started to use their primary account login and that the occurrence of these cases has increased.

    Browsers are extremely poor for reliable security. Not to mention that when these Forums were initially launched, the security was (and still is in many ways) extremely porous with constant errors and failed security certificates.

    My recommendation to my fellow players. If security is a concern for you, then I would refrain from participating on these Forums. I logged in today to comment in this thread simply due to the severity of the issue which can't simply be advised away with two-bit account security measures like those mentioned in the quote above. I have sworn off participating on these forums in large part. I now simply browse and read them on occasion. It's a shame, but an incident like that described by the OP is the risk you take whenever using your account login info for anything aside from directly playing the game.
    [center]Landy: [b]Alphanova 3.0[/b] - R10 RK [b][i]Hitman for Mother Nature[/i][/b]
    Brandy: [b]Rotoreaver[/b] - R9 Reaver [b][i]Chop-N-Cleaver[/i][/b]
    Firefoot-Retired: [b]Alphazen[/b] - R9 Hunt*rd (MoM); [b]Spankdush[/b] - R6 Warg (SoA)
    [/center]

  23. #48
    Join Date
    Apr 2007
    Posts
    42

    Re: Account Hacked? What did they Steal?

    I just got my account back from being hacked. They logged into all my characters, got all the gold, and got into my vault and took at least all my crafting materials too. I can't tell what else they might have got, because of the craptastic new vault.
    [charsig=http://lotrosigs.level3.turbine.com/0820700000000cbee/01003/signature.png]undefined[/charsig]

  24. #49
    Join Date
    Mar 2007
    Posts
    5,190

    Re: Account Hacked? What did they Steal?

    Quote Originally Posted by sirwillow View Post
    Ogre and others who've been hacked. I'm sorry your account has been hacked. Really. That sucks. But have you read through this thread and some of the advice given? It may be junk on your computer. It may not be. You may have been phished- received an email saying your account was going to be canceled unless you entered the information on a website- that turns out to be a hackers site who just stole your information. You may have given out your account name and/or password in other areas- to friends to share, used the same ones on other accounts, or a variety of different ways. And it may have actually happened months ago and you don't remember it.

    They don't need your email login and password to change your email address on your Turbine account. Turbine doesn't send out confirmation emails to change the email address on the account, even though they should.

    But all of that to say is that somewhere along the way you let a hacker have access to your information without knowing it. Not even necessarily recently, it could have been 6 months ago.

    Have you changed your password recently? You should every 30 days. 60 at the most.

    Do you use the same account and/or password in other places? Bad, bad, bad and makes it easy if someone gets one to get others from you. Don't do it.

    Are your passwords hard to guess or easy? Are they a single word or a date? To simple. Is it a mix of letters, numbers and symbols in a seemingly random fashion? That's what it needs to be.

    There are a lot of other things that you should be doing to protect yourself. Unfortunately the vast majority of people who get hacked haven't been doing even the basic things to keep themselves safe. Then they blame the game companies or others. The basic reality is- if you don't want to get hacked then you need to make it as hard as possible for the hackers to get your information. Be careful, be informed, be protected, don't fall to traps, and protect yourself.
    Passwords are no good if you can't remember your own, and when you need to have a different password for every game, every website, email, blackboard at your university, etc etc, and have to change it every 30 days.. it becomes impossible to remember them all. Writing them down is said to be a bad thng if you live in a house with other people in it that might see the passwords, storing them on your computer is outright not a good idea.

    So you're seriously expecting people to remember dozens of passwords that change every month and aren't familiar phrases or dates?

    It gets a little unrealistic.

  25. #50
    Join Date
    May 2007
    Posts
    1,889

    Re: Account Hacked? What did they Steal?

    That why there differnt medium you can write down your Password and Accound info Down. I been saving Password When there was 5 1/2 inch floppys and Bill Gates seid "640K ought to be enough for anybody" Boy was he wrong by a Long shot on that one.
    .

 

 
Page 2 of 3 FirstFirst 1 2 3 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

This form's session has expired. You need to reload the page.

Reload