Notice: You have been identified as a bot, so no internal UID will be assigned to you. If you are a real person messing with your useragent, you should change it back to something normal.

Minichan

Topic: Someone hacked my Diablo III account

Fake anon !ZkUt8arUCU started this discussion 14 years ago #19,734

They got rid of all the items in the first tab of my stash (they missed the 2nd tab full of gems), all the items on my lvl 58 demon hunter including my legendary bow a friend gave me, and somehow got rid of all my gold. I opened a ticket with blizzard and hopefully they'll do a character reset but it still sucks. I put 44+ hours into this guy already, fuck.

Oh, also I was severely under-geared as it was. The legendary bow was a lvl 51 bow, and i'd found level 53 rares that were only slightly worse than it. I didn't have anything good on me, but they still fucking took it all. I would be really buttmad if Blizzard didn't have excellent customer service, but for now I am just irritated that I can't play my character with my friends.

(Edited 4 minutes later.)

Anonymous B joined in and replied with this 14 years ago, 23 minutes later[^] [v] #323,131

Damn, I don't even play diablo, but that's gotta suck some serious dick. Do you have any ideas as to why you were specifically targeted?

(Edited 25 seconds later.)

HaikerensGuide !0VegJ9Jl.Q joined in and replied with this 14 years ago, 6 minutes later, 30 minutes after the original post[^] [v] #323,132

I'm so glad I didn't buy that steaming pile of shit.

Anonymous D joined in and replied with this 14 years ago, 4 minutes later, 35 minutes after the original post[^] [v] #323,133

@OP

You said you were sick. Perhaps you downloaded a Virus?

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 35 seconds later, 35 minutes after the original post[^] [v] #323,134

@323,131 (B)
No. I did send in my laptop for repair so it's conceivable that the repair guy somehow got into my game somehow. That doesn't seem to be incredibly likely, but neither is being the target of some random account phisher or whatever.
@323,132 (HaikerensGuide !0VegJ9Jl.Q)
The game is great if you like dungeon crawl RPGs. It's really fun when playing with friends too. You're just jelly.

HaikerensGuide !0VegJ9Jl.Q replied with this 14 years ago, 1 minute later, 37 minutes after the original post[^] [v] #323,135

@previous (Fake anon !ZkUt8arUCU)
> You're just jelly.
Not really. Half the time, the game is down. The amount of hacking is insane. It's like a parody of PSN.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 5 minutes later, 42 minutes after the original post[^] [v] #323,136

@323,133 (D)
Lol, i don't think so.
@previous (HaikerensGuide !0VegJ9Jl.Q)
The game was down for like 4 hours total on launch day, and allegedly the number of hacked accounts is small.

Anonymous D replied with this 14 years ago, 49 seconds later, 43 minutes after the original post[^] [v] #323,137

@323,134 (Fake anon !ZkUt8arUCU)
Fucking Wot? Look at this timely bit on you not being the only ONE!!! May 22 2012

http://www.gamerevolution.com/news/reports-of-account-hacking-strike-diablo-iii-blizzard-responds-13079


Diablo III has been in a slight state of disarray since it came out last week, and not all of it has come from the server issues. Nope, a handful of reports have surfaced of Battle.net accounts being hacked along with Diablo III gold and loot being stolen. Given how strong Blizzard's stance on Diablo III's online-requirement has been, which was intended to provide security, it didn't take long for every single Diablo forum on the net to blow up with discussion.

Rumors have surfaced as a result, and one rumor places blame on a possible glitch where a player can join a recent public game and have access to an account or character. While no evidence has been given to support this claim, Rift suffered from an eerily similar problem that was denied by its developer first before a hacker released details and the issue was addressed through a patch.

Blizzard—being the community-friendly group that they are—quickly dispatched Community Manager Micah Whiple, also known as Bashiok, to do the dirty work.

Anonymous E joined in and replied with this 14 years ago, 17 seconds later, 43 minutes after the original post[^] [v] #323,138

@323,134 (Fake anon !ZkUt8arUCU)
It's not a good game for him, with him not having friends or good taste in games.

HaikerensGuide !0VegJ9Jl.Q replied with this 14 years ago, 3 minutes later, 47 minutes after the original post[^] [v] #323,139

@323,136 (Fake anon !ZkUt8arUCU)
down for 8 hours on tuesday

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 9 seconds later, 47 minutes after the original post[^] [v] #323,140

@323,137 (D)
Hah, I like how they dismiss the "recently joined public game" thing when i have a player in my recent players list even though I've never played a public game that wasn't with 3 friends. He is a level 1 female wizard who's played like 17 hours. I bet that's exactly what it is but Blizzard is trying to save face. Lame.

Fake anon !ZkUt8arUCU (OP) double-posted this 14 years ago, 1 minute later, 48 minutes after the original post[^] [v] #323,141

@323,139 (HaikerensGuide !0VegJ9Jl.Q)
The whole game or just the auction house? The auction house goes down pretty regularly, but the game itself has been pretty stable.

Anonymous D replied with this 14 years ago, 1 minute later, 49 minutes after the original post[^] [v] #323,142

@323,140 (Fake anon !ZkUt8arUCU)
Anytime you get hacked - Check the web. Just to be sure that only that one account was hacked. Keep your eye on the web for a few weeks re this attack.

Anonymous F joined in and replied with this 14 years ago, 1 minute later, 51 minutes after the original post[^] [v] #323,143

> that feel when you agree with walter somewhat

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 2 minutes later, 54 minutes after the original post[^] [v] #323,144

@previous (F)
> agreeing with walter
> 2012

HaikerensGuide !0VegJ9Jl.Q replied with this 14 years ago, 15 seconds later, 54 minutes after the original post[^] [v] #323,145

@323,143 (F)
Whom are you quoting?

Anonymous F replied with this 14 years ago, 3 minutes later, 58 minutes after the original post[^] [v] #323,147

@323,144 (Fake anon !ZkUt8arUCU)
I know. I'm not proud of it but it is what it is.

@previous (HaikerensGuide !0VegJ9Jl.Q)
Myself.

HaikerensGuide !0VegJ9Jl.Q replied with this 14 years ago, 1 minute later, 1 hour after the original post[^] [v] #323,151

itt: fake-anon reeks of buyer's remorse

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 4 minutes later, 1 hour after the original post[^] [v] #323,153

@previous (HaikerensGuide !0VegJ9Jl.Q)
Hardly. I don't regret buying this game at all because I had fun playing it, and I'll have fun playing it once my account is reset. Where do you get these wacky ideas from?

Anonymous F replied with this 14 years ago, 7 minutes later, 1 hour after the original post[^] [v] #323,156

@previous (Fake anon !ZkUt8arUCU)
He's a /v/-goer. Arguing that a game was worth your time because you had fun with it simply isn't going to work.

HaikerensGuide !0VegJ9Jl.Q replied with this 14 years ago, 6 minutes later, 1 hour after the original post[^] [v] #323,158

http://us.battle.net/d3/en/forum/topic/5149013410

Anonymous G joined in and replied with this 14 years ago, 20 minutes later, 1 hour after the original post[^] [v] #323,159

@323,140 (Fake anon !ZkUt8arUCU)
how the fuck can you play a game for 17 hours and still be at lvl 1?

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 2 minutes later, 1 hour after the original post[^] [v] #323,160

@323,158 (HaikerensGuide !0VegJ9Jl.Q)
> implying i have any plans of spending real world money to buy items in this game
@previous (G)
Exactly. Clearly this fucker is responsible for me losing my account. I reported him and I filled out a ticket but so far I haven't heard a thing.

Anonymous G replied with this 14 years ago, 9 minutes later, 1 hour after the original post[^] [v] #323,163

@previous (Fake anon !ZkUt8arUCU)
i mean dam, ether this guy has no business playing da vidya or hes an expert at procrastination

(Edited 38 seconds later.)

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 5 minutes later, 1 hour after the original post[^] [v] #323,164

@previous (G)
lol no, there apparently is a way for someone to join your game and steal your account info. Blizzard has denied it but it's the only way I can explain how the guy named "bbbbbbbbbbbbbb" showed up in my recently played list with his level 1 wizard named jfkjkfjkjl that he's put 17 hours into right before my account info got stolen. Fuck this shit.

Anonymous H joined in and replied with this 14 years ago, 3 hours later, 5 hours after the original post[^] [v] #323,181

Your account couldn't have been hacked. One of the main reasons for choosing to make even single player games dependent on Battle.net servers was to keep the game totally secure. To even imply this was a fucking retarded design decision doomed to failure is preposterous.

Lee O'Nidas !nBpim1wazU joined in and replied with this 14 years ago, 58 minutes later, 6 hours after the original post[^] [v] #323,186

I would express my sympathies, but you'd just insult me.

realdw !jdTkvovFCQ joined in and replied with this 14 years ago, 2 hours later, 8 hours after the original post[^] [v] #323,194

@323,136 (Fake anon !ZkUt8arUCU)
Blizzard did say like yesterday that their servers weren't compromised but that the hacking was due to 'traditional password-stealing methods'
@previous (Lee O'Nidas !nBpim1wazU)
that is because nobody likes you and you should end your life
@323,181 (H)
lol this

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 5 hours later, 14 hours after the original post[^] [v] #323,231

@323,186 (Lee O'Nidas !nBpim1wazU)
How will I ever live without your sympathy?
@previous (realdw !jdTkvovFCQ)
I know what the official Blizzard statement is, but it's simply false. I would screencap this guy's account that's fishy but since I can't find my phone atm, I can't log into my account. Yay! This is the only PC game in the history of the world where if you lose your cell phone, you can't play it. Derp. Who the fuck thought this phone-dependent authenticator shit was a good idea? Probably the same people who thought that making a single player game online-only was a good idea.

Anonymous D replied with this 14 years ago, 35 minutes later, 15 hours after the original post[^] [v] #323,243

@previous (Fake anon !ZkUt8arUCU)
> How will I ever live without your sympathy?

You will because the last thing you need when sick is being stalked by him.

Anonymous F replied with this 14 years ago, 23 minutes later, 15 hours after the original post[^] [v] #323,264

@323,231 (Fake anon !ZkUt8arUCU)
I'm disappointed that you didn't tell him to kill himself. Feels like a letdown.

At least call him autistic.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 1 minute later, 15 hours after the original post[^] [v] #323,265

@previous (F)
I only tell him to kill himself when I really mean it. Otherwise it just feels forced. I'm too sick to really hate anyone, but once i feel better i will insult him. I promise, anon f.

(Edited 8 seconds later.)

Killer Lettuce !!iNo3FkiZx replied with this 14 years ago, 23 minutes later, 16 hours after the original post[^] [v] #323,274

@previous (Fake anon !ZkUt8arUCU)
Okay. I'll hold you to that.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 29 minutes later, 16 hours after the original post[^] [v] #323,279

Slight update fora. The guy who hacked my account was banned, and I sent blizzard an angry response on my ticket, even though they didn't do anything wrong. lolol time to apologize.

realdw !jdTkvovFCQ replied with this 14 years ago, 30 seconds later, 16 hours after the original post[^] [v] #323,280

@323,231 (Fake anon !ZkUt8arUCU)
couldnt he just have brute-forced your account?

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 4 minutes later, 16 hours after the original post[^] [v] #323,282

@previous (realdw !jdTkvovFCQ)
If he did, there's no reason he would have showed up in my recent players list. Unless he like used that account as temporary storage or something. Also, apparently Blizzard's passwords are case insensitive. What kind of fucking company does that? With case insensitive passwords, and no penalty for failing to log in X times, yes it is very possible that he bruteforced my password, since there's fucking no security. Good job being a fucking failure blizzard.

(Edited 30 seconds later.)

Anonymous B replied with this 14 years ago, 1 hour later, 17 hours after the original post[^] [v] #323,297

Externally hosted image@previous (Fake anon !ZkUt8arUCU)
Have you considered that it wasn't some random l33t h4x0r, and was really just one of your buddies? :/ Maybe one of them social engineered your password out of you, and you don't even know it. Also, see the image.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 8 minutes later, 18 hours after the original post[^] [v] #323,300

@previous (B)
Lol that image is funny. No, I only play with people I've known IRL since 6th grade or earlier, and since we always play as a group of 4, there's no benefit to fucking over 1/4th of the team. I'm sure it was just some script kiddie brute forcing my password or something lame like that. Which would be blizzard's fault for not implementing basic security features (like having some penalty for failing to login 9999999 times in 3 minutes or something like that).

r04r joined in and replied with this 14 years ago, 3 hours later, 22 hours after the original post[^] [v] #323,353

@previous (Fake anon !ZkUt8arUCU)
I think it's really unlikely that your password got brute-forced, unless it was painfully simple or you specifically were targeted. Seeing as it sounded like your gear wasn't great the latter is unlikely, people would instead target far more successful players. Anyway, let's discuss the math of brute-forcing a password over the web, but first:
In @323,231 (Fake anon !ZkUt8arUCU) you mention using the blizzard authenticator (2-factor authentication is awesome, and using it on your phone is win because less devices required. For WoW they have dedicated hardware if you prefer that, look into it if you think it would be worth it, it's not expensive). Did you use it when you were "hacked"?

As for the actual math, I'll be assuming you weren't using dictionary words or anything predictable (If you did, it's still unlikely but you deserve it anyway). Let's go with fdisl1, which is relatively short and contains a number but no capital letters (Because you mentioned passwords not being case sensitive). The minimum 'character set' for this is 36. a-z is 26 characters, and 0-9 is 10 characters. The password length is 6.

It is important to remember that this is a brute force attack on a remote service, so for each attempt they have to connect to it and try it. This is slow, as opposed to just matching against something local. We'll be optimistic and assume each login attempt takes 100ms.

So, let's start with the total possible amount of passwords they will have to try. Keep in mind that we're assuming the character set of abcdefghijklmnopqrstuvwxyz0123456789. So, it starts with "a" and ends with 999999. This is 36^1 + 36^2 + 36^3 + 36^4 + 36^5 + 36^6 = 2,238,976,116 possible combinations to try. At 100ms per attempt that will take 223,897,612 seconds, or a little over 2591 days.

An attacker will be able to try multiple combinations at once, and a realistic number for that would be somewhere between 25 and 100 per IP address, if blizzard does not employ any counter measures. So let's again be optimistic and say that they can 100 attempts/second. This cuts our waiting time down a lot, but still leaves us with ~26 days. Of course the techniques described here can be improved and implemented better for higher speeds, but I sincerely doubt that this is what happened.

Disclaimer: I am tired, and my math can be wrong.

Anonymous L joined in and replied with this 14 years ago, 20 minutes later, 22 hours after the original post[^] [v] #323,355

ib4 his password was "biscuits" and he just got caught in some random hacker's lame dictionary attack.

Anonymous H replied with this 14 years ago, 12 minutes later, 22 hours after the original post[^] [v] #323,356

Image went missingI'll say it again: The server-side processing of all games (even single player) makes Diablo 3 100% secure. Stop whining because you gave your friend the password while playing gay chicken. Blizzard is infallible!

Anonymous M joined in and replied with this 14 years ago, 4 minutes later, 22 hours after the original post[^] [v] #323,357

@OP

Shitty game made by the cancer of the gaming world long with EA. Enjoy your AIDS

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 13 minutes later, 22 hours after the original post[^] [v] #323,361

@323,353 (r04r)
Neat. My password was nondictionary words with only 1 number but it was decently long. I'm going to wait for the official blizzard explanation and see what they have to say. Even if it wasn't a dictionary attack, it was still really shitty security on their part to not have case sensitive passwords or at least some penalty for failing to login a certain number of times. The authenticator is neat, but I only found out about it via a friend after I told him I was hacked. That's not a good way or time to find out about a preventative measure against being hacked.
@323,355 (L)
It was actually biscu1t. now I changed it to b1scuit so it's much safer.
@previous (M)
It's really fun if you have friends, actually.

Fake anon !ZkUt8arUCU (OP) double-posted this 14 years ago, 4 hours later, 1 day after the original post[^] [v] #323,462

@323,353 (r04r)
Weirdly, I can't sleep without offering this criticism. You seem to be assuming that a hacker will need to try every possible combination before getting one that hits. Assuming that they will only need to guess 51% of the possible combinations before thy get it right, that cuts the time down to 13 days. And assuming they use 1000 IPs (granted its kind of a stretch, but since this is a game that has items which sell for real currency, it's not out of the question completely) that cuts the time down to 1.3 days. That doesn't seem like it's impractical at all, and if you limit your attempts to only players who are level 50 or above, you can get serious gear for minimal cost.

Passwords susceptible to dictionary attacks would be even quicker, possibly cracking in minutes. If I were trying to hack into accounts, I would do this, unless there's some easier way I don't know about.

(Edited 4 minutes later.)

Lee O'Nidas !nBpim1wazU replied with this 14 years ago, 6 hours later, 1 day after the original post[^] [v] #323,555

@OP

http://us.battle.net/d3/en/blog/6020037
Make sure you have an authenticator. You can get one free for your phone.

r04r replied with this 14 years ago, 6 hours later, 1 day after the original post[^] [v] #323,630

@previous (Lee O'Nidas !nBpim1wazU)
You didn't read the thread. Go kill yourself, you pathetic excuse of a human being.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 2 hours later, 1 day after the original post[^] [v] #323,708

@previous (r04r)
lol I love you.

Anonymous N joined in and replied with this 14 years ago, 1 hour later, 1 day after the original post[^] [v] #323,718

Your account was most likely phished.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 6 minutes later, 1 day after the original post[^] [v] #323,719

@previous (N)
I'm curious as to exactly how it happened though, and if there was anything (besides being unaware of the authenticator) I should have known or done beforehand to prevent it from happening.

Lee O'Nidas !nBpim1wazU replied with this 14 years ago, 17 hours later, 2 days after the original post[^] [v] #323,910

I was curious if you people would still attack me when I try my best to help. Confirmed.

Killer Lettuce !!iNo3FkiZx replied with this 14 years ago, 12 minutes later, 2 days after the original post[^] [v] #323,913

@previous (Lee O'Nidas !nBpim1wazU)
Since Mark has been going easy on you ITT I'll have to pick up the slack.

You are autistic and should end your own life.

Green !BEERiVqJJw joined in and replied with this 14 years ago, 1 hour later, 2 days after the original post[^] [v] #323,952

@previous (Killer Lettuce !!iNo3FkiZx)
I have a complex from childhood trauma where I'm nice to people who treat me cruely and I go out of my way to please certain types of bullies (this is all thanks to my childhood). And while a certain person's cyberbullying spread vicious lies about me, no two people who believed them treated me exactly the same way, but you and jump. All others treated me differently.

Handel joined in and replied with this 14 years ago, 51 minutes later, 2 days after the original post[^] [v] #323,955

Hacked ≠ Phished

Lee O'Nidas !nBpim1wazU replied with this 14 years ago, 1 day later, 3 days after the original post[^] [v] #324,291

http://www.forbes.com/sites/insertcoin/2012/05/30/the-horror-of-being-hacked-in-diablo-3/'

> No, I am not saying Blizzard’s servers necessarily got hacked, but there is more to this than they’re letting on. This isn’t just “user error” when you look at the details of the hack. My monk was actually my lower level alternate while my high level barbarian and mid level witch doctor were left completely alone with all their equipment intact. The monk however, was the last character that was logged in. Also, my password wasn’t changed, and if someone had access to it, they could strip ALL my characters with ease, which they didn’t. Something else is going on here. This is the exact same thing that happened to my wizard friend, as his other characters were left untouched, meaning it appears hackers may be stealing session keys. If so, this IS on Blizzard’s side, and there’s more to it than someone simply acquiring logins and passwords.

Fake anon !ZkUt8arUCU (OP) replied with this 14 years ago, 44 minutes later, 4 days after the original post[^] [v] #324,310

@previous (Lee O'Nidas !nBpim1wazU)
Thanks for telling me absolutely nothing of value, as usual.

squeegee !firstkPE1Q joined in and replied with this 14 years ago, 13 minutes later, 4 days after the original post[^] [v] #324,312

@323,231 (Fake anon !ZkUt8arUCU)
actually i played WoW before and after the Battle.net authenticator was released, it was highly anticipated and well received. it's a little dongle with a push button that generated a 6 digit code. then, like a year later, the iPhone came out or whatever and battle.net or blizzard or someone made an app that did the same thing for free, and Blizzard ran with it.
Honestly it was the best thing ever. if you had an account with maxed out characters then you'd routinely have your account raped. shit is worth real money to the chinese. it all comes from phishing and the like, really. but some of their little scams look legit as fuck. even if you were careful it was easy to click the wrong email and login to battlenet.com/WoW or some bullshit and not know it.
Luckily authenticators.
:

Please familiarise yourself with the rules and markup syntax before posting.