View Full Version : Attempted Hack of Forums AGAIN!?
Tunst
10-19-2011, 01:55 AM
all 50-some of those comments went off at once.
looks definately like scripts if not anything else.
Mastese
10-19-2011, 01:58 AM
Check out this guy's My DDO page, under the player name: Usc_bt_test_02
Page Link (http://my.ddo.com/usc_bt_test_02/2011/10/17/bt-test/)
It appears as if this guy is trying to hack My DDO somehow. I don't think I'm being paranoid here, and I don't know anything about hacking or running scripts, but this looks blatently suspicious. I've reported many of his comments under the post entitled BT_TEST. His page is even complete with gallery images of the infamous anonymous hacker group.
We lost the forums already once, with the threat of stolen personal or account information. They need to do something about this.
-Mastese
Hephaistor
10-19-2011, 02:00 AM
May be a whitehat testing whether the forum/myDDO is save now. Maybe someone from Turbine testing... or you are right.
Angelz_Fire
10-19-2011, 02:02 AM
Maybe its time for turbine to add a character name (chosen by you) into the game login screen, without knowing that less chance hackers can gain access. If hacking becomes problematic people tend to drop games, at least I know thats why I've left other games in the past.
Tunst
10-19-2011, 02:02 AM
^^
ninja post
Mastese
10-19-2011, 02:08 AM
There would be no need for the Anonymous logo if it were a legitimate test. Maybe it's somebody's idea of a bad joke...but I don't like seeing that kind of stuff. I'll be changing my account password again shortly just in case.
-Mastese
grgurius
10-19-2011, 02:16 AM
It looks like a bad joke to me, but i'm changing my passwords anyway.
Edit: But his ddo blog post and comments are interesting, hm. Good thing i'm paranoid.
badbob117
10-19-2011, 02:22 AM
Very strange stuff!
MsEricka
10-19-2011, 02:43 AM
It's not strange, it's simply a script kiddie who's trying to see if he can inject javascript onto the page.
Judging by the number of posts and the time, it's most likely a bot doing the posting.
If the injection proves successful, he would get the bot to post on multiple blogs.
tl;dr
script kiddie searching for wordpress exploits
Yes Turbine, I'm still available for hire. Perhaps I should just add that to my signature.
grgurius
10-19-2011, 02:44 AM
Hm, if you enter the script part of his post in your address bar, it takes you to a Cross Site Scripting example site. Starting to think this is a hacker wannabe.
And if it is Anonymous, what are they doing here, shouldn't they be taking down Facebook, 5th November is just around the corner.
Cendaer
10-19-2011, 02:56 AM
Check out this guy's My DDO page, under the player name: Usc_bt_test_02
Page Link (http://my.ddo.com/usc_bt_test_02/2011/10/17/bt-test/)
OK. ^^THAT^^ MyDDO page is scary.
I'm not clicking on it again, and am sorry I even looked at it once.
I feel dirty, and like I need to change my passwords AGAIN.
How did you find that? Explain yourself.
Were you just scrolling through lists of names on MyDDO?
OR
Are YOU the culprit, and I just fell for your trap?
Whatever that is, it needs to go away.
MsEricka
10-19-2011, 03:17 AM
There is no trap on that page, get over your paranoid self.
grgurius
10-19-2011, 03:35 AM
There is no trap on that page, get over your paranoid self.
Paranoia is the wind beneath my wings.
dunklezhan
10-19-2011, 03:50 AM
There is no trap on that page, get over your paranoid self.
But... but... but they are out to get me! Look! There's an MiB - right there!
scottmike0
10-19-2011, 04:22 AM
But... but... but they are out to get me! Look! There's an MiB - right there!
something about newest posts, your able to easily find the person :)
karnokvolrath
10-19-2011, 04:41 AM
yikes.
nerdychaz
10-19-2011, 04:58 AM
There is a report button to hit.
Zeruell
10-19-2011, 08:46 AM
Could be Turbine outsourcing their security testing: http://whois.domaintools.com/usc-bt.com
A related job posting (https://tbe.taleo.net/NA9/ats/careers/requisition.jsp?org=BT&cws=1&rid=3179)? Note the recruiter contact info. (EDIT: For the paranoid: the recruiter's e-mail domain is usc-bt.com.)
Tolero
10-19-2011, 10:58 AM
Thanks for the reports! This was one of our security testers kicking the tires. He's cleaned up his leftovers now.
llevenbaxx
10-19-2011, 11:07 AM
There is no trap on that page, get over your paranoid self.
Or you're in on it! :)
smatt
10-19-2011, 11:12 AM
I smell a conspiracy to cover up the death of many cute little puppies and kittens... :eek::D
Tolero
10-19-2011, 11:21 AM
I smell a conspiracy to cover up the death of many cute little puppies and kittens... :eek::D
No puppies or kitties were harmed in the making of this test. Though I can't say the same for Kobolds >>
smatt
10-19-2011, 11:27 AM
No puppies or kitties were harmed in the making of this test. Though I can't say the same for Kobolds >>
:eek: Oh pawr whittle Kobolds.... Little guys never get a break..... First it's Crystal Cove slave driving and now this... :(
:D
Missing_Minds
10-19-2011, 11:28 AM
I smell a conspiracy to cover up the death of many cute little puppies and kittens... :eek::D
You aren't the only one. Sticking anon stuff in a related test?
Only a good idea if you wanted to see how much your user base is active and willing to report stuff. Turn about this scare tactic often backfires as well.
Or if anything now some anon or admirer will want to hack Turbine just because of it.
Powered by vBulletin® Version 4.2.3 Copyright © 2025 vBulletin Solutions, Inc. All rights reserved.