Tag: hacking
Google stops censoring Chinese search results, moves HQ to Hong Kong
Google have stopped censoring their users search results in China, after relations between the US company and Chinese officials rapidly deteriorated in the past few months. Google have now moved their Chinese-language search engineers to new offices away from mainland…
Authorities close in on Chinese Google hackers
US authorities have moved one step closer to finding the hackers behind the recent attacks on search giants Google. Teams of investigators have tracked the source of the attack to two educational facilities in China. With one institution closely linked…
Lost and Naked: A tale of hacking in World of Warcraft
What would you do if you woke up half-way across the world with no clothes on, and just a mining pick in your possession? That was the virtual reality that faced Luke Maskell when he logged into his World of Warcraft character, Häwk, one morning. His character had been hacked into and everything of value had been removed and sold.
“They must have stolen around ten to fifteen thousand gold worth of goods and cash,” says Luke, “they probably would have earned around £50-£80”. That might not sound like much, but for his character it represents months and months of play in the massively-multiplayer online world where one of the most controversial topics is that of gold farmers and selling equipment for real cash.
Selling gold and virtual items in World of Warcraft is very strictly against the rules set by developer Blizzard. The terms of use for the game state, quite firmly, that “you may not sell in-game items or currency for “real” money, or exchange those items or currency for value outside of the Game”.
But is it a crime? Well, a spokesperson for the Metropolitan Police told us that it was a very tricky one – it would need a test case to be determined, and it would depend on many factors. Complicating the matter is the fact that the virtual thief might not be resident in the UK, and Blizzard’s servers might be sitting in yet another country again. I put this to the Police spokesperson who sucked his teeth and told me that a court-case spanning three countries would be “absolute madness”.
“I certainly see it as a crime,” states Luke, defiantly, “the online assets are in the end, property of Blizzard, and someone is selling this property for real-world money without permission, they should be treated as any other criminal.”
It’s not completely clear how the attacker managed to gain access to Luke’s characters: “Virus scanners and anti malware software found a few stray cookies from websites I was unsure about, but nothing major like a trojan or virus. I don’t think I’ll ever find out how my details were stolen.”
Blizzard, for their part, offer plenty of advice on how to keep accounts secure. On their compromised accounts page they recommend you change passwords regularly and warn against installing dodgy-looking game modifications or using power-levelling services.
They also sell a device called an ‘authenticator’, which hooks up with your account and generates a second password that operates alongside your main one. This password changes every five minutes, so it’s impossible to log in if the authenticator isn’t in your possession.
Luckily, this story has a happy ending for Luke: “Blizzard were great with the issue. I went through both the in-game ticketing system and their online support site to get my items and account back under my control, and they responded quickly and professionally.”
“They advised me on steps to take to prevent any further hacks, fully restored all my items and gold, and even gave everything that was taken from the guild bank back, all within 3 days of the hack occuring. I was very impressed.”
His guild – a group of players that he plays with on a regular basis – were also very supportive, too: “From my guild, I got a general response of sympathy and people wishing me luck in getting all my items and money back from the game moderators. I had a lot of people in the guild offering me some cash to get me back on my feet and replace my items”
If you’re a player of World of Warcraft, or any other online game, put yourself in Luke’s shoes for a minute. Think about how long it took you to acquire the items that you’re using in-game, and how long it would take to replace them. Then go change your account password and buy an authenticator – in the long run, you’ll be very pleased you did.
Internet Explorer 8 hacked within 24 hours
If you’re going to announce that your new browser is the safest on the market, you’d best be damned sure you’re right. It seems Microsoft releasing Internet Explorer 8 out of open beta yesterday was a red flag to a bull (or a challenge to a hacker), because within 24 hours a new exploit has been found in the browser.
The feat occurred at the annual CanSecWest security conference, which hosted its PWN2OWN hacking contest, where the exploit was found. A German hacker going by the name of Nils found it and claims a prize of $5000 in cash and a Sony Vaio laptop as a prize.
It’s only fair to mention that the same hacker managed to claim an additional $10,000 for successfully hacking Safari and Firefox. There’s still two days left for more browsers to succumb to the hacker’s codey wiles – perhaps Chrome and Opera will let their guard slip as well.
Quick! Encrypt your hard drives now: Euro police could be hacking your PC
It’s very easy to become alarmed by some of the scaremongering stories which appear in certain sections of the UK press when it comes to technology and privacy, but this one – if abused – could be pretty serious indeed.
According to The Times, The Home Office has developed plans to give the UK police force the power to remotely hack into the personal computer of anyone it suspects might be involved with something dodgy — you know, terrorism, paedophilia, drug trafficking, that kind of thing — without a warrant, with the additional joyous notion that police forces from across the European Union can request information on any British Citizen.
Yes, it does all sound a bit Daily Mail, but unsurprisingly it’s raised the hackles of the human rights group Liberty, which has said that it will mount a legal challenge.
WPA Wi-Fi security gets cracked
There are several ways to crack a wireless network’s security. The weakest, WEP, can be easily cracked using customized Linux software, but until today, Wi-Fi Protected Access (or WPA) had been considered secure. Not any more. Researchers have announced that they’ve developed a way to partially crack the encryption standard, but I warn you, it’s not easy.
The researchers, Erik Tews and Martin Beck, have found a way to break the Temporary Key Integrity Protocol (or TKIP) in as little as 15-12 minutes. They have not yet, however, managed to crack the encryption keys used to secure the data that travels from the PC to the router.
iPhone Dev Team releases PwnageTool 2.0.1 for iPhone 2.0 jailbreaking
The iPhone Dev Team yesterday announced the release of their PwnageTool 2.0.1, allowing any iPhone to be “jailbroken” in order to run unsanctioned third-party applications.
Seems there are a huge number of people who want to hack into their iPhone, as demand took down their servers for a period of time.
The software will jailbreak and unlock any first generation iPhone or iPod Touch running either version 1 or version 2.0 firmware, and will jailbreak the iPhone 3G. They’re still working on a way to unlock the newest iPhone so that it can be used on any other network…
Hackers can exploit ISPs quest for cash by spoofing non-existent web sites
For a while now, some Internet Service Providers have been taking advantage of unused domain names and subdomains in order to make some cash by displaying advertising when someone types in a non-existent web site address.
A recent study by IOActive security researcher Dan Kaminsky proves there’s a security flaw that could let malicious hackers set up authentic-looking web sites in order to fool Web users…
Apple fixes prize-winning Safari bug
Apple has issued a patch to fix the loophole identified by the winner in the recent CanSecWest security conference PWN 2 OWN competition…
Hackers attack pro-Tibet websites – ScanSafe saves the day
Hackers have attacked pro-Tibet websites…