Cracked, NOT hacked.

Alot of accounts have been cracked lately, mine as well, with uniques and orbs missing.

When i first logged in, my password was changed, i thought this was wierd because they would need access to my email to change it, alas i immediately go check my email.. nothing comprised.. no one ever logged in.

The only explantion is someone has a program that can crack into our accounts and manipulate the information to whatever they want.

Not hard to do since POE offers your account name on thier websits.

A good cracker doesn't even need your password, just your account name. And time.
"
chronosoul wrote:
Alot of accounts have been cracked lately, mine as well, with uniques and orbs missing.

When i first logged in, my password was changed, i thought this was wierd because they would need access to my email to change it, alas i immediately go check my email.. nothing comprised.. no one ever logged in.

The only explantion is someone has a program that can crack into our accounts and manipulate the information to whatever they want.

Not hard to do since POE offers your account name on thier websits.

A good cracker doesn't even need your password, just your account name. And time.


I highly doubt your account was "cracked". More likely is that you re-used a password for your email or something else which was put on a list and allowed the hacker into your email (which allows them access to PoE pretty easily)... or the other alternative is that your PC is compromised.

You can be in denial all you want, but it won't change reality. There have been no confirmed cases of account access that weren't a result of the hacker knowing the login information directly. And we're not talking about brute-force attempts here either. They were able to successfully log in the first time... which means they know your passwords to at least your PoE account and probably your email.
then by posting here i have risked my account...i think not.
True they could do it but it is far far far easier to get the details other ways none of which are considered hacking in the proper use of the word.
Ancestral Bond. It's a thing that does stuff. -Vipermagi

He who controls the pants controls the galaxy. - Rick & Morty S3E1
"
chronosoul wrote:
Alot of accounts have been cracked lately, mine as well, with uniques and orbs missing.

When i first logged in, my password was changed, i thought this was wierd because they would need access to my email to change it, alas i immediately go check my email.. nothing comprised.. no one ever logged in.

The only explantion is someone has a program that can crack into our accounts and manipulate the information to whatever they want.

Not hard to do since POE offers your account name on thier websits.

A good cracker doesn't even need your password, just your account name. And time.


this happened to me but i didnt lose anything because i disconnected him in time
but yeah it is just like you said the IP locking thing didnt go off
i have scanned for viruses and found nothing

i currently have a thread going about this and drakier seems to be completely against the possibillity of some bug or exploit which could allow someone to bypass this IP locking thingy
"
xkegisx wrote:
this happened to me but i didnt lose anything because i disconnected him in time
but yeah it is just like you said the IP locking thing didnt go off
i have scanned for viruses and found nothing

i currently have a thread going about this and drakier seems to be completely against the possibillity of some bug or exploit which could allow someone to bypass this IP locking thingy


You are correct. I'm against pretty much all possibility that a bug allows direct access and allows bypassing the lock.

Just for fun, check your email trash can. Is there an Unlock Code email in there that lists someplace like China or wherever the hacker was from (IE: somewhere other than where you live)? A lot of times they delete the email from the inbox, but not from the trash.
u didnt have any message on e mail becouse its area ip, so some was trying to log in from same city maybe?

it means it could be some1 who u know, just think if u didnt share ur password to any1 ;)

i dont know what is ur password but it only show how stupid u are if u use same password for e mail and any other game accounts etc.

imagine u have same PIN for ur credit card, and u lost all ur 4 card on each 20 k $, and some know ur PIN. congratz u just lost 80 k $, instead of 20.
if u are smart u will probably have other PIN number on every card.
if u know what i mean.

do not use any name sub name birdhday "password" which can be conected to ur personal information.

u got hacked and this can be only ur fault in 99% of cases.

just read on web about safety information

ign: @Szczerbaty_wonsz
A lot of email services have something like this, a list of IP addresses which have recently logged in to your account. If this is enabled, it may shed light on how you were compromised.

It's possible the attacker can not only steal your password, but play from your IP address. That isn't normal though. They normally log in using a password and email you've lost previously somehow, then they hide their tracks.

Your virus scanner is useless.
"
lagwin1980 wrote:
then by posting here i have risked my account...i think not.
True they could do it but it is far far far easier to get the details other ways none of which are considered hacking in the proper use of the word.



You are wrong buddy, w/o someonoes account name, your account is like a shadow.

My account name is the first thing you need to access my account, its the MAIN thing you need.

Now if you're a good cracker, you already made up a program that will manipulate GGG's client Data.

BAM - Success -

This person or people can now steal your account, and they only need 5 out of 6 IF NOT LESS! letters of your account. Or whatever method they use now adays *Wink*

Normally this wouldn't make sense, but GGG has a big black market. currency is worth real money.

Now what makes sense is, why don't they target bigger accounts?

Too hard to move that much currency unnoticed i'd say.

Yes there are phishing divices and other things out there that get people. Trojans, Keyloggers. But thats not what got me.

If it was, my ISP is lieing to me.

Last edited by chronosoul#2658 on May 16, 2013, 4:29:03 PM
"
chronosoul wrote:
"
lagwin1980 wrote:
then by posting here i have risked my account...i think not.
True they could do it but it is far far far easier to get the details other ways none of which are considered hacking in the proper use of the word.



You are wrong buddy, w/o someonoes account name, your account is like a shadow.

My account name is the first thing you need to access my account, its the MAIN thing you need.

Now if you're a good cracker, you already made up a program that will manipulate GGG's client Data.

BAM - Success -

This person or people can now steal your account, and they only need 5 out of 6 IF NOT LESS! letters of your account. Or whatever method they use now adays *Wink*

Normally this wouldn't make sense, but GGG has a big black market. currency is worth real money.

Now what makes sense is, why don't they target bigger accounts?

Too hard to move that much currency unnoticed i'd say.

Yes there are phishing divices and other things out there that get people. Trojans, Keyloggers. But thats not what got me.

If it was, my ISP is lieing to me.










It's possible and i hear stories of people getting their accounts brute forced in a way that baffles them since they have NO trojans, keyloggers,viruses, and have very secure systems. I think some people are in denial and swiftly ignore the possibility of these things taking place.
Last edited by DrSteveBrule#4164 on May 16, 2013, 5:14:43 PM
"
DrSteveBrule wrote:
It's possible and i hear stories of people getting their accounts brute forced in a way that baffles them since they have NO trojans, keyloggers,viruses, and have very secure systems. I think some people are in denial and swiftly ignore the possibility of these things taking place.


I'm not in denial that there is a slim possibility... but that is far out-weighed by the denial of the people who have been hacked and still maintaining their "clean" system. Talk about denial... everyone wants to assume that they had no part in being hacked and assume that it was always because of something else (like a database breach, etc)... rather than the more realistic possibility that their machine could possibly be compromised, or their password was re-used at some point in time.

Just because you think your machine is clean, and your AV says you have no infections, does NOT mean that you aren't still compromised. It's a false sense of security, and anyone in the computer security business can tell you that there is no 100% guarantee that your machine isn't compromised... short of VERY few configurations. For people playing internet games, the chance is much greater that their machines will at some point be compromised without their knowledge.

Report Forum Post

Report Account:

Report Type

Additional Info