[phpBB Debug] PHP Warning: in file [ROOT]/viewtopic.php on line 1583: file(http://www.cinemablend.com/games/Diablo-3-Session-Spoofing-Real-Do-Join-Public-Games-43162.html): failed to open stream: Unable to find the socket transport "ssl" - did you forget to enable it when you configured PHP?
[phpBB Debug] PHP Warning: in file [ROOT]/viewtopic.php on line 1583: implode(): Invalid arguments passed
[phpBB Debug] PHP Warning: in file [ROOT]/viewtopic.php on line 1583: file(http://www.cinemablend.com/games/Diablo-3-Account-With-Authenticator-Attached-Has-Been-Hacked-43138.html): failed to open stream: Unable to find the socket transport "ssl" - did you forget to enable it when you configured PHP?
[phpBB Debug] PHP Warning: in file [ROOT]/viewtopic.php on line 1583: implode(): Invalid arguments passed
Proof That Public Accounts Can Be Hacked : Diablo 3 General Discussions
taultunleashed logoProof That Public Accounts Can Be Hacked : Diablo 3 General Discussions
newtopic  postreply
 [ 7 posts ] 
blue large dot

Proof That Public Accounts Can Be Hacked : Diablo 3 General Discussions

Posted: June 4th, 2012, 10:19 am
 
Tault_admin

Total Posts: 29974
Joined: November 9th, 2002, 9:57 am
Tault_admin's Reps: 1444
User avatar
administrator
Mod in Training
This is pretty big. Cinema blend did a big story on how you can spoof session ids to hack accounts. Its what many people thought and all you do is join a game and open up a trade for the best bet. Then you can look at the session ids and spoof someones session which will boot them from the game and put you in control of that account. Then just mule the items to your other accounts.



Reply with quote
Posted: June 4th, 2012, 11:29 am
 
rsparrowk

Total Posts: 53
Joined: August 8th, 2005, 7:11 pm
rsparrowk's Reps: 5
User avatar
premium
I think people should just get the authenticator...you will never have to worry about your account getting hacked...unless they have your cellphone or authenticator lol.


Reply with quote
Posted: June 4th, 2012, 11:56 am
 
Tault_admin

Total Posts: 29974
Joined: November 9th, 2002, 9:57 am
Tault_admin's Reps: 1444
User avatar
administrator
Mod in Training
WEll it shows that doesnt matter. Thats the problem. Because the authenticator stops people from logging into your account. The article says that your account is not technically being logged into it. They are just tricking the server to think that its someone elses account logged in because of how session ids work. Thats the scary part, now this might prove to be false, but it seems pretty believable.

Here is a story they posted on a staff member getting his account hacked.



Reply with quote
Posted: June 6th, 2012, 2:07 am
 
fadeous

Total Posts: 264
Joined: September 22nd, 2011, 8:19 pm
fadeous's Reps: 727
User avatar
Active User > 50 Posts
premium
it happened to me they cleaned me out blizzard didnt question anything on the roll back surpisingly i had just sold all my gold so i got to double my money in a sense they helped me out in other words at 4 am when i woke up i shaat all over myself first time in my life of gaming i got hacked i dont add any friends to my list and i block all communications with people when im done playing with them lol


Reply with quote
Posted: June 6th, 2012, 2:58 pm
 
carefoot

Total Posts: 541
Location: In a Tree
Joined: August 21st, 2004, 4:41 pm
carefoot's Reps: 890
User avatar
Active User > 50 Posts
premium
The session ID gives you access to the character they played with and all your gold (because gold is shared). I know its possible to execute something like this but the question is retroactively fitting people with all their gold is fine but the problem is does this use up one of your two strikes against RLAH?

ie. I understand that once you get compromised twice you are disabled from accessing the real life auction house.


Reply with quote
Posted: June 6th, 2012, 5:16 pm
 
Spitt

Total Posts: 745
Joined: January 29th, 2007, 7:46 pm
Spitt's Reps: 718
User avatar
premium
There is an alternative theory. However either is plausible. Most of the people who have been hacked, in fact all that I know of, had pre-purchased WoW's 1 year sub, to get the free copy of D3. Those are the only ones I have heard of getting hacked. Which implies that when Blizzard was DDOSed, and their Database hacked, that Blizzard lost passwords to upgraded accounts. AFAIK those are the only accounts which have been hacked. Of the 8 accounts we are farming gold on, that was the only account which was hacked as well.

So, if you bought the 1 year of service and got the Free D3 attached to your account - change your password.

I do agree with the article, Blizzard will downplay anything, in order to keep their money flowing.


Reply with quote
Posted: June 7th, 2012, 12:32 pm
 
Tault_admin

Total Posts: 29974
Joined: November 9th, 2002, 9:57 am
Tault_admin's Reps: 1444
User avatar
administrator
Mod in Training
Yea thats another big idea too. However if that was the case wouldnt authenticators top that? The big thing is how a respected game writer had an authenticator and got his account hacked, which gives more validity that authenticators arent stopping whatever is going on.


Reply with quote
Want Advertisements After The Last Post Removed? Create A Free Account!

blue large dot Who is online
Users browsing this forum: No registered users and 10 guests

Popular Sections
SWTOR Cheats
Guild Wars 2 Cheats
Guild Wars 2 Hacks
Guild Wars 2 Bots
Diablo 3 Cheats
Guild Wars 2 Mods

Popular Sections
WoW Cataclysm Cheats & Exploits
WoW Cataclysm Hacks & Bots
Star Wars The Old Republic Cheats
SWTOR Mods
Torchlight 2 Cheats
SWTOR Space Mission Bots
Site Nav and RSS
RSS Feed of Diablo 3 General Discussions RSS Feed 
Sitemap of Diablo 3 General Discussions Sitemap 
SitemapIndex SitemapIndex
RSS Feed RSS Feed
Channel list Channel list
Diablo 1/2/LOD/3Vote on the Diablo 3 Top 200diablo 3 private serverMPOGTOP
left bottom corner Site and Contents Copyright 2001-2012 All Rights Reserved TaultUnleashed.com bottom corner
top left
top right
createaccount
Username:   Password:   Remember Me?