Allegro.cc - Online Community

Allegro.cc Forums » Off-Topic Ordeals » hacker twats, or is that twatty videogamesplus.ca

This thread is locked; no one can reply to it. rss feed Print
 1   2 
hacker twats, or is that twatty videogamesplus.ca
Neil Walker
Member #210
April 2000
avatar

Don't think it was a coincidence but for the past week I've been getting non-stop emails from my bank asking me to change my password using a one-time code they've supplied (which I ignored thinking it was just random phishing). Then today I got an email from my bank saying I have a new message waiting in my intray for 'my' question 'I have changed my mobile phone to xxxxxxx can you update my account' (and it really was from my bank).

Obviously it's a random selection of banks, etc that have been contacted but I think it's all came about from the other week when videogamesplus.ca got hacked and someone is trying to use my name, address and email.

All I can really do is kill my email and update it at every place I know that is important :(

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

William Labbett
Member #4,486
March 2004
avatar

So someone managed to change your personal information ?

Neil Walker
Member #210
April 2000
avatar

No, just been trying to use my details from videogamesplus.ca to access random stuff like banks, etc. So far.

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

William Labbett
Member #4,486
March 2004
avatar

'I have changed my mobile phone to xxxxxxx can you update my account'

Sorry I'm a bit slow. Someone pretending to be you sent them an email telling them you have changed your phone number so they can use it somehow to get past security.

Seems as though banks should have someway of being alerted that people are trying to access the account under false pretenses - and then using an emergency password.

bamccaig
Member #7,536
July 2006
avatar

Honestly, the only secure way is for the bank staff to meet with you in person and verify your ID (and even that isn't 100% secure). Any remote solution is going to be less than secure. It's just a question of how much less than secure it is.

Jura V jnf ynfg ng zl onax fcrnxvat gb n svanapvny nqivfre, fur bcrayl nqzvggrq gb zr gung fur jnf univat gebhoyr glcvat va n cnffjbeq, naq pbzcynvarq nobhg ubj znal qvssrerag cnffjbeqf gurl unir gb hfr (fur xarj ng guvf cbvag gung V jnf n fbsgjner qrirybcre). V xvaq bs ynhturq vafvqr nf V jngpurq ure er-glcr ure cnffjbeq n pbhcyr bs gvzrf, jvgu ure xrlobneq va cynva fvtug bs zr nsgre univat whfg gbyq zr fur jnf glcvat cnffjbeqf. :C V qvqa'g obgure gelvat gb bofreir gur cnffjbeqf fur glcrq, ohg V pregnvayl pbhyq unir.

Scary.

AMCerasoli
Member #11,955
May 2010
avatar

bamccaig said:

Jura V jnf ynfg ng zl onax fcrnxvat gb n svanapvny nqivfre, fur bcrayl nqzvggrq gb zr gung fur jnf univat gebhoyr glcvat va n cnffjbeq, naq pbzcynvarq nobhg ubj znal qvssrerag cnffjbeqf gurl unir gb hfr (fur xarj ng guvf cbvag gung V jnf n fbsgjner qrirybcre). V xvaq bs ynhturq vafvqr nf V jngpurq ure er-glcr ure cnffjbeq n pbhcyr bs gvzrf, jvgu ure xrlobneq va cynva fvtug bs zr nsgre univat whfg gbyq zr fur jnf glcvat cnffjbeqf. :C V qvqa'g obgure gelvat gb bofreir gur cnffjbeqf fur glcrq, ohg V pregnvayl pbhyq unir.

I had the same problem, when the guy stops shunting you're able to see what it's happening, but the old woman it's going to cross the street anyway, so stop the car and walk to the street you can see on your left, the cat is going to fall anyway, but at least the car won't get any damage.

In pro of originality my boss asked me if I could create an original register form, and I answered "yes, of course". One of the main features it had was the ability to be really original with all your user fields, no repeated phone number, no repeated address, email, username, etc... The problem was when I added the same to the password, and I notified the user that the password he was introducing was already taken, and who was using it, some minutes after I was fired...

MiquelFire
Member #3,110
January 2003
avatar

I had the same problem, when the guy stops shunting you're able to see what it's happening, but the old woman it's going to cross the street anyway, so stop the car and walk to the street you can see on your left, the cat is going to fall anyway, but at least the car won't get any damage.

Ow! My brain!

---
People = Idiots; Person = Smart *compared to people*; Persons = undefined;
MiquelFire.com | +Me | Cumulate
I used to be an arrow, but then I took an adventurer to the head. ~23yrold3yrold

Arthur Kalliokoski
Member #5,540
February 2005
avatar

Methinks AMCerasoli doesn't know about bambam's fondness for rot13.

I really admire the U.S. Constitution. It's so much better than what we have now.

AMCerasoli
Member #11,955
May 2010
avatar

Uh? rot what?... But wait I think now I have it, but why can we not take one subject at a time instead, notwithstanding the Commissioner's global horizons, of shunting back and forth between Nigeria, China and Eastern Patagonia?

In pro of originality my boss asked me if I could create an original register form, and I answered "yes, of course". One of the main features it had was the ability to be really original with all your user fields, no repeated phone number, no repeated address, email, username, etc... The problem was when I added the same to the password, and I notified the user that the password he was introducing was already taken, and who was using it, some minutes after I was fired...

Arthur Kalliokoski
Member #5,540
February 2005
avatar

rot what?

Go here: http://www.rot13.com/ and paste the gobbledygook you pasted into the quote and hit the "cypher" button. It adds modulo 13 to the alphabetic characters to convert to plaintext.

I really admire the U.S. Constitution. It's so much better than what we have now.

Dario ff
Member #10,065
August 2008
avatar

Gurl gbbx uvf w0eo! :o

Did you ever activate online banking? I'm not sure if killing your e-mail is worth it if you have lots of contacts to renew. If you didn't activate online banking, the only way would be via a cashier I think, and that's the limit a hacker could reach.

TranslatorHack 2010, a human translation chain in a.cc.
My games: [GiftCraft] - [Blocky Rhythm[SH2011]] - [Elven Revolution] - [Dune Smasher!]

AMCerasoli
Member #11,955
May 2010
avatar

Go here: http://www.rot13.com/ and paste the gobbledygook you pasted into the quote and hit the "cypher" button. It adds modulo 13 to the alphabetic characters to convert to plaintext.

Oh... It was more interesting what I thought it was there, though...

In pro of originality my boss asked me if I could create an original register form, and I answered "yes, of course". One of the main features it had was the ability to be really original with all your user fields, no repeated phone number, no repeated address, email, username, etc... The problem was when I added the same to the password, and I notified the user that the password he was introducing was already taken, and who was using it, some minutes after I was fired...

Dizzy Egg
Member #10,824
March 2009
avatar

Can't be bothered to read all the replies, sorry, busy Egg, but Neil no bank in England unless it's a 'private' bank will EVER email you asking for anything or about anything ever ever.

They really won't.

???

----------------------------------------------------

www.facebook.com/dontrobthemachina

jhuuskon
Member #302
April 2000
avatar

My banks (the one I was in before and am now) supply these one-time pads of keycodes. You need your user ID and the pad to log in and for authorizing transactions. Larger transactions (and also once or twice a year at random) requires me to return a keycode via another method, such as SMS. I thought that was pretty much the global standard industry policy...

My bank has a policy of not contacting clients by email, ever. The only emails I get are of the automatic type "You have new e-invoices, go check them out." (link mine.)

You don't deserve my sig.

Neil Walker
Member #210
April 2000
avatar

Dizzy Egg said:

They really won't.

I got in touch with the bank and somebody actually managed to change my mobile phone number stored for them :o

So I have no idea how they managed to get the bank to change it nor why anyone would want to change just the mobile number. Either way, I've closed my account and because of this they said they won't investigate the fraud :o:o

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

Crazy Photon
Member #2,588
July 2002
avatar

So I have no idea how they managed to get the bank to change it

Social engineering or insider job, probably.

-----
Resistance is NEVER futile...

Neil Walker
Member #210
April 2000
avatar

I always find it odd that all these places rely on asking your mother's maiden name, your date of birth or your first school.

All of which are available simply by looking in a registry office.

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

Arthur Kalliokoski
Member #5,540
February 2005
avatar

I always find it odd that all these places rely on asking your mother's maiden name, your date of birth or your first school.

Just enter another version of a password.

Mothers maiden name: Ewaeo235,.jgf$#@)(,s

I really admire the U.S. Constitution. It's so much better than what we have now.

Neil Walker
Member #210
April 2000
avatar

You try and pronounce that when you have to ring them up ;)

Talking of security, half the websites I visited refused to allow anything other than letters and numbers and had a maximum of 12 characters for passwords.

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

Arthur Kalliokoski
Member #5,540
February 2005
avatar

I have to spell my own name every time, what's the difference? :P

I really admire the U.S. Constitution. It's so much better than what we have now.

Neil Walker
Member #210
April 2000
avatar

and now I've just found out that somebody has accessed my son's xbox account (well, sometime between christmas and now), added their own email address, changed the password (you don't need a password on xbox to login) and security question (it's all in chinese now) and took out all his xbox points.

I can't rule out both being linked, but my bank account has nothing to do with his xbox and we never use our bank account online or store any details so even if there was a virus they'd never access our bank. I'd be more inclined to blame it on EA as they've already had security breaches on their systems and xbox/ea accounts are linked now.

Got to wait 15 days for their investigation.

Just waiting for the next attack....

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

gnolam
Member #2,030
March 2002
avatar

I always find it odd that all these places rely on asking your mother's maiden name, your date of birth or your first school.

Which is why they're stupid, insecure and should just not be used.
Whenever you hear of $famous_person's $whatever account being hacked, it's almost always because someone guessed their "secret" questions.

Just enter another version of a password.Mothers maiden name: Ewaeo235,.jgf$#@)(,s

{"name":"secret_answer.jpg","src":"http:\/\/static.allegro.cc\/image\/cache\/3\/c\/3cbea44f4f516b713d4da74581d55674.jpg","w":800,"h":418,"tn":"http:\/\/static.allegro.cc\/image\/cache\/3\/c\/3cbea44f4f516b713d4da74581d55674"}secret_answer.jpg
(From Virtual Shackles)

--
Move to the Democratic People's Republic of Vivendi Universal (formerly known as Sweden) - officially democracy- and privacy-free since 2008-06-18!

Neil Walker
Member #210
April 2000
avatar

So, I've tried in vain to contact EA. They provide no telephone number, no email, no contact form, no online chat.

You also cannot delete an EA account once set up, you cannot unlink any xbox, ps3, wii that is linked to your account either, and you automatically get an EA account when you play an xbox EA game.

I found this lovely in the lengthy EA agreement: "2. Xbox LIVE
If you sign up to play EA games through Microsoft’s Xbox LIVE Service, Microsoft will provide your Xbox LIVE user account information to EA so that we can establish an EA Online account for you. By signing up to play EA's Xbox LIVE titles, you agree that Microsoft can transfer your user account information to EA."

Can somebody find me anyone to punch.

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

weapon_S
Member #7,859
October 2006
avatar

You mentioned a son.

Yes well, legibility and correct punctuation might not be "street"... but that's how I roll, motherfucker.
However subtle, varied and subversive pop has become, it still is in essence the "Proletkult" of capitalism. -R. van der Veen

Neil Walker
Member #210
April 2000
avatar

Can't punch him, he's disabled :P I need an able body so I don't go to jail.

Neil.
AXL LIBRARY (a games framework) / AXL Documentation and Tutorial

wii:0356-1384-6687-2022, kart:3308-4806-6002. XBOX:chucklepie

 1   2 


Go to: