Massive hack last night Why it must be a bug

First of all, this is my opinion.

This massive "Hack" last night has gotten me aswell. Orbs etc have disapeared.

But looking at the huge amount of people affected this can't have been a hack.

It would take about 15+- seconds to actually fully login to a character. Then another 30 seconds to look trough the stash and empty it. Then the trade has to been done with another character wich would take atleast another 30 seconds. Considering you have to teleport to the right area etc.

That means you easily spend around 1 minute 15 seconds to fully hack 1 account.

Reading trough the forums more then hundreds of accounts have been affected.

So either this was a really dedicated hacker that could bring up the time + the concentration to pull off a stunt like this (Wich I consider impossible considering he has to manually type all emails and passwords)

Just to say this: My PC is not infected. I've not logged into any POE website, since my account has been remembered since I created it. I do not have a virus or visited any malicious website (Avast webrep) The e-mail that I use has and still is, only being used for POE. My password is a random amount of letters with numbers.


I hope this will be looked into, since I don't think this is a problem with the users but more likely a problem with the latest patch that caused items to disappear.
IGN: Bluewy
It was an automated bot hacking us, 100% sure because it only took certain items and didnt bother looking in my stashes called 1ex+, 2ex+ and uniques....
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I'm gonna throw this out there too, hacking is not the same as theft.

I'm also going to say Chris was right about everything. He said hundreds of passwords were stolen from users, not the servers, and it's a small drop in the bucket targeting random people instead of the top percentage of wealthy players.

You don't really know if or how you've been compromised, while it's actually Chris' job to be able to prove that he hasn't.
"
ionface wrote:
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I'm gonna throw this out there too, hacking is not the same as theft.

I'm also going to say Chris was right about everything. He said hundreds of passwords were stolen from users, not the servers, and it's a small drop in the bucket targeting random people instead of the top percentage of wealthy players.

You don't really know if or how you've been compromised, while it's actually Chris' job to be able to prove that he hasn't.


Yes but I wonder how they got our passwords because I really never even opened anything outside the poe website and google as starting page...

It really mustve been a security breach. A friends mule account got hacked as well, and he made that account 2 days ago to stash his valuables incase he got hacked, well GG because only that account got hacked and his main account is still intact LOL
Phishing Links/PMs:
Nope, only used this website + google and never had a phishing email

Malware in Cheat Programs:
Of course not

Posting Config Files:
Nope

Non-unique Password:
No my password is not password1 or 123456

Already Compromised PC or Email account:
Payed firewall and anti-virus

Power-levelling Services:
Of course not
"
ionface wrote:


Those are super basic things.

This is my first account ever that's compromised.

I use a random password generator wich generates an unique random password 16 digits long.
The e-mail that i use for my POE account is also only being used for POE.

None of those ways are valid to explain why i've been hacked.

I'm extremely carefull with security, I never go to a random link since I simply don't trust those links. besides, I got Avast Webrep running and that would warn me for any malicious website id enter. It even sometimes warns me for google stealing my info.
IGN: Bluewy
Have you ever shared your config files with anyone?
"
ionface wrote:
Have you ever shared your config files with anyone?


Why would anyone do that? Passwords get stored there :S

Like I said, few weeks ago there was a bug that could let you login on someone else's account with your id+password I think a similar replicated breach happened. I think the hacker(s) dont need our passwords to log in.
Last edited by Struyk#7686 on Feb 20, 2013, 4:25:14 AM
http://www.pathofexile.com/forum/view-thread/48708/page/15#p743847

People need tech support because they don't know how to computer. It's pretty easy to fire one off to a guy helping you in a support thread too. I'm not sure that's ever happened to me, but I've never asked for one.
Last edited by ionface#0613 on Feb 20, 2013, 4:27:49 AM

Report Forum Post

Report Account:

Report Type

Additional Info