It seems like the GOM player had stored SQL pass/user within the code of the player. Easy to read with a hex-editor and connect to the database.
Always reroute through php/asp... never direct access, Gom. Please.
| Forum Index > SC2 General |
|
Qzy
Denmark1121 Posts
It seems like the GOM player had stored SQL pass/user within the code of the player. Easy to read with a hex-editor and connect to the database. Always reroute through php/asp... never direct access, Gom. Please. | ||
|
phANT1m
South Africa535 Posts
| ||
|
tuestresfat
2555 Posts
| ||
|
NuKedUFirst
Canada3139 Posts
| ||
|
Miraju
Germany235 Posts
. | ||
|
FinnGamer
Germany2426 Posts
On August 13 2011 08:26 Antoine wrote: Show nested quote + On August 13 2011 08:21 Integra wrote: On August 13 2011 08:18 warbean wrote: I also just got this email from Blizzard for my WoW account that has been inactive for 9 months now. Looks like somehow got into my character and got himself banned. I use the same email for GomTv and Battle.net, although I usually sign in through SNS Twitter. Seems to be too much of a coincidence. + Show Spoiler + English speaking customers: Please refer to the start of this mail Para los clientes españoles: Por favor vayan hasta el fin de este email ***Notice of Account Closure*** Account Name: WARBEAN1 Reason for Closure: Terms of Use Violation -- Exploitative Activity: Abuse of the Economy This account was closed because one or more characters were identified exchanging, or contributing to the exchange of, in-game property (items or gold) for "real-world" currency. This exchange process negatively impacts the World of Warcraft game environment by detracting from the value of the in-game economy. Even if this is the result of account sharing, the account owner can still be held responsible for the penalty because of the impact it had on the game environment. We've found the above behavior is many times directly related to groups responsible for compromising World of Warcraft accounts; we take these issues very seriously. To better understand our position against exploitative activity and the risks involved, please review this article: http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455 The exploitative activity that took place on this account violates the World of Warcraft Terms of Use. We ask you take a moment to review these terms at http://us.blizzard.com/company/legal/index.html. Note that additional Terms of Use violations may result in more severe actions against this account, up to and including permanent closure. If you believe your account was compromised, please submit an in-game petition or fill the contact email form at http://us.blizzard.com/support/webform.xml?locale=en_US. Our support staff will assist you as soon as possible. If you are unable to access your account due to the password being changed, please visit our Login Support site here: https://us.battle.net/account/support/password-reset.html For any disputes of this action or further information on Exploitive Activity, please visit the Exploitative Activity FAQ and contact page here: http://us.blizzard.com/support/article/exploitfaq Regards, Customer Services Blizzard Entertainment http://us.battle.net/wow/en/ ------------------------------------------------------- ***Notificación de Clausura de Cuenta*** Nombre de Cuenta: WARBEAN1 Razón por la Clausura: Violación de las Condiciones de Uso – Actividad Explotadora: Abuso de la Economía Esta cuenta fue clausurada porque uno o más personajes se identificaron comerciando, o contribuyendo al comercio de, la propiedad dentro del juego (objetos u oro) por moneda “real.” Este proceso de comercio negativamente impacta al ambiente de World of Warcraft por detraer del valor de la economía dentro del juego. Aunque esto sea a resultado de la compartición de la cuenta, el dueño de la cuenta aun puede ser responsable por la penalización debido al impacto que tuvo en el ambiente del juego. Hemos conseguido que el comportamiento superior muchas veces sea directamente relacionado a los grupos responsables por comprometer las cuentas de World of Warcraft; nosotros tomamos estos asuntos muy seriamente. Para mejor entender nuestra posición sobre la actividad explotadora y los riesgos involucrados, por favor revise este artículo: (http://us.blizzard.com/support/article.xml?locale=en_US&articleId=25455). La actividad explotadora que ocurrió en esta cuenta está en contra de las Condiciones de Uso de World of Warcraft. Le pedimos que se tome un momento para revisar estos términos: (http://us.blizzard.com/company/legal/index.html). Note que cualquier violación adicional de las Condiciones de Uso pueden resultar en más severas medidas en contra de esta cuenta, hasta e incluyendo la clausura permanente. Si cree que su cuenta haya sido comprometida, por favor abra una petición dentro del juego o llene el formulario de contacto por email: (https://us.blizzard.com/support/webform.xml?locale=es_MX). Nuestro equipo de soporte le asistirá lo más pronto posible. Si no puede acceder a su cuenta debido a un cambio de contraseña, por favor visite nuestro sitio de Asistencia de Ingreso aquí: (https://us.battle.net/account/support/password-reset.html). Para cualquier disputa sobre esta medida, o para más información sobre la Actividad Explotadora, por favor visite la página de contacto y Preguntas Frecuentes (FAQ) aquí: (http://us.blizzard.com/support/article.xml?locale=es_MX&tag=exploitfaq). Saludos, Atención al Cliente Blizzard Entertainment http://us.battle.net/wow/es/ I've just recieved emails, note not email but EMAILS from Blizz as well. They all seem to be fake though. they are all claiming various stuff, like I have to give away my bank account info to prove that i am the holder of the wow account etc. My information has been leaked, that's for sure. i would say you've probably gotten these emails a lot longer than 1 day, i've had them slamming my spambox for like 5 years now I'm getting emails from games I don't even play, my Bulk is 50% noreply@blizzard.com ,WoWAccountservices@blizzard.com or WoWAccountAdmin@Blizzard.com. | ||
|
T-oastbro-T
Germany378 Posts
But for the most part I'm disappointed in their failure to acknowledge the leak and inform their users about it. As far as I know, there is no official statement on the homepage as of yet and I have received no email either. Timing is crucial for users, who made the ill-advised choice of using their gomtv-mail-pw-combination on sites like paypal, amazon etc. as well. Leaks will always happen. How damaging they are, depends on the effort necessary to obtain the data (i.e. how much thought and work the company invested in their security-mechanisms) and the manner in which the company deals with the incident (i.e. fixing the vulnerability and inform their user-base about their compromised accounts). At the moment, GomTV scores an "unprofessional"-rating under both aspects. ![]() | ||
|
getSome[703]
United States753 Posts
Yes I think I used the same username/pw for GOM as I use for PayPal... fail I know. Just changed it though | ||
|
Slakter
Sweden1947 Posts
On August 13 2011 22:01 Kiyo. wrote: Show nested quote + On August 13 2011 21:53 Slakter wrote: I´ve always used my twitter account to watch GSL, does anyone know if this affected that aswell? Probably didnt but even if I´ve already changed the passwords. Easily done since I use a lot of different passwords for different things. Show nested quote + On August 13 2011 03:14 R1CH wrote:Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.. Read the first post. I skimmed through it, thanks for pointing that out! | ||
|
Zato-1
Chile4253 Posts
On August 13 2011 03:14 R1CH wrote: You should also change your GomTV password to prevent unauthorized account access Changing passwords has been disabled it seems. | ||
|
skAnarky
Canada140 Posts
| ||
|
KiNGxXx
7928 Posts
On August 13 2011 23:28 skAnarky wrote: the system let me change my password, but the password I changed it to, plus the password I used to use, now both dont work. I suggest not changing your password until GOM gives word now, as I am locked out of my account. You have to verify the change of the password via email. You got one from Gom after changing the password. I forgot it the first time and was like "wtf?" because no password worked. | ||
|
Twistacles
Canada1327 Posts
| ||
|
ondik
Czech Republic2908 Posts
| ||
|
hugman
Sweden4644 Posts
On August 13 2011 23:46 ondik wrote: FUCK I used the same mail I used for my bnet account. Luckily passwords for my e-mail and for my bnet acc are all different, am I 100% safe? Yes, worst case is that you get lots of spam | ||
|
RusHXceL
United States1004 Posts
| ||
|
lurked
Canada918 Posts
At least I dont use important passwords on gaming sites... But really? No encrytpion for the passwords? Son, I am disappoint... : \ | ||
|
skAnarky
Canada140 Posts
You have to verify the change of the password via email. You got one from Gom after changing the password. I forgot it the first time and was like "wtf?" because no password worked. I hit the verification link in the email unfortunately. | ||
|
Rorra
Australia1066 Posts
| ||
|
RoyalCheese
Czech Republic745 Posts
| ||
| ||
StarCraft 2 StarCraft: Brood War Britney Dota 2Calm Rain GuemChi Stork Soma Dewaltoss Leta Movie yabsab [ Show more ] Counter-Strike Heroes of the Storm Other Games FrodaN2581 DeMusliM532 ceh9418 Fuzer KnowMe167 QueenE159 Hui .149 Liquid`VortiX142 ArmadaUGS110 Trikslyr71 fpsfer Organizations Dota 2 Other Games StarCraft: Brood War StarCraft 2 StarCraft: Brood War
StarCraft 2 • poizon28 StarCraft: Brood War• Hinosc • Reevou • Kozan • IndyKCrew • sooper7s • AfreecaTV YouTube • Migwel • intothetv • LaughNgamezSOOP Dota 2 League of Legends Other Games |
|
BSL: GosuLeague
PiGosaur Cup
The PondCast
Replay Cast
RSL Revival
herO vs Zoun
Classic vs Reynor
Maru vs SHIN
MaxPax vs TriGGeR
BSL: GosuLeague
RSL Revival
WardiTV Korean Royale
RSL Revival
WardiTV Korean Royale
[ Show More ] IPSL
Julia vs Artosis
JDConan vs DragOn
RSL Revival
Wardi Open
IPSL
StRyKeR vs OldBoy
Sziky vs Tarson
Replay Cast
Monday Night Weeklies
Replay Cast
Wardi Open
|
|
|