Author Topic: Trojan succesfully hacks Authenticator Protected Accounts  (Read 162 times)

Nakata

  • Hero Member
  • *****
  • Posts: 1017
Trojan succesfully hacks Authenticator Protected Accounts
« on: March 01, 2010, 12:45:47 AM »
Trojan succesfully hacks Authenticator Protected Accounts
A new virus spawned on the internet a few days ago and seems to be the first trojan capable of hacking a WoW account protected by an Authenticator. It was confirmed by Blizzard a few hours ago.

Quote
Quote from: Kropacius (Source)
After looking into this, it has been escalated, but it is a Man in the Middle attack.

http://en.wikipedia.org/wiki/Man-in-the-middle_attack


This is still perpetrated by key loggers, and no method is always 100% secure.

Basically, what the virus does is fairly simple after you're infected :

    * The next time you log in World of Warcraft, the game asks for your Authenticator code.
    * The virus intercepts it, send it to another server, and sends a wrong one to Blizzard = You get an error.
    * The people behind the virus now have a few seconds/minutes to use the "real" code while it's valid to change your password / empty your account / guild bank.


How to check if you're infected
Just search for a file named "emcor.dll" on your computer, it is most likely located in "C:\Users\(Your user name)\AppData\Temp" but I suggest that you check everything just to be sure. If you do find the file, delete it and make sure you update your anti-virus to prevent any further problem.

To be honest, if you found this file your account is probably already compromised.

What does it mean exactly?

    * Yes, you can get hacked even if you have an authenticator, the chances are MUCH lower but you're not invulnerable.
    * It definitely isn't an excuse to not have an authenticator. We're talking about a single virus here and the authenticator will save your ass 99% of the time.
    * Get a decent anti-virus, buy an authenticator, you'll be safe.

Freeshaman

  • Website Guy
  • ****
  • Posts: 308
  • less QQ more pew pew
    • my website :)
Re: Trojan succesfully hacks Authenticator Protected Accounts
« Reply #1 on: March 01, 2010, 01:35:52 PM »
* Get a decent anti-virus, buy an authenticator, you'll be safe.

no need to panic, cus there's no method is always 100% secure



* The people behind the virus now have a few seconds/minutes to use the "real" code while it's valid to change your password / empty your account / guild bank.

if any hacker took the time to do your account (no matter it's a human or a piece of script), you must have done something reali bad or reali stupid (to actually go to those websites included in those spam messages, with a windows machine that has no antivirus or a internet browser that has no protection), so you deserve it.
« Last Edit: March 01, 2010, 01:45:10 PM by Freeshaman »