[Theory] Account Scam using realmlist switch. menu
100% Up to 1000$
4.9/5
150% Up to 200$ & 20 Freespins
4.8/5
Up to 1 BTC
4.9/5
20% Cashback
4.8/5
Up to 5 BTC
4.8/5
100% Up to 1 BTC
4.7/5
Up to 5 BTC
4.7/5
110% Up to 1 BTC
4.6/5

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 18
  1. #1
    Gamer's Avatar Active Member
    Reputation
    239
    Join Date
    Jan 2007
    Posts
    198
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [Theory] Account Scam using realmlist switch.

    [Theory] Account Scam using realmlist switch.
    Note 1: I couldn't see anything similar to this, but if it has been posted please delete.
    Note 2: I don't know whether this should go in this section or the questions section, please move accordingly.


    When I was building my awesomely original (:P) realm list switcher, I recognized the potential of a similar program to be used for devious purposes.

    The idea:

    Get the user to download and run a exe file. (doesn't seem hard based on the number of gamecard duplicators etc. are using).

    In the background, this program will modify the user's realmlist.wtf file to a private server. Not your average private server though, one specially designed just to capture all password attempts sent in. It doesn't actually need to have the game, just record login attempts to a file and always return invalid password.

    They will feel safe, as they didn't need to enter their password/gamecard details, they are just playing WoW as usual. The program will also test negative to keyloggers.

    "So, if I don't have a keylogger, and I don't type my password/info into someone elses app I'm fine right?" Not if your WoW client is sending info to another server.

    Implementation:

    Now the realmlist program is very easy to make. The part I have no experience with is the private server part. But if people can make fully functioning servers, then just making a login server that writes all attempts to a file shouldn't be too hard.

    Please post feedback/criticism. Basically if anyone knows how/can be arsed/thinks its worthwhile making this work, I'm happy to provide the program.
    Last edited by Gamer; 12-11-2008 at 04:11 AM.

    [Theory] Account Scam using realmlist switch.
  2. #2
    Apoc's Avatar Angry Penguin
    Reputation
    1388
    Join Date
    Jan 2008
    Posts
    2,750
    Thanks G/R
    0/13
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Actually a pretty damned good idea. Easily coded, and the server is easily made.

  3. #3
    Gamer's Avatar Active Member
    Reputation
    239
    Join Date
    Jan 2007
    Posts
    198
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Apoc View Post
    Actually a pretty damned good idea. Easily coded, and the server is easily made.
    Why thank you. What an honour coming from you

    As I said, if anyone wants to make a server, I'm happy to make the program. Just tell me what you want it to be disguised as.

  4. #4
    Apoc's Avatar Angry Penguin
    Reputation
    1388
    Join Date
    Jan 2008
    Posts
    2,750
    Thanks G/R
    0/13
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Already wrote the program

    (Took some already existing code, and just changed it a bit )

    The server part is easy. Just check the login logs for the server. (Maybe change it a bit to output the password too)

  5. #5
    Gamer's Avatar Active Member
    Reputation
    239
    Join Date
    Jan 2007
    Posts
    198
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Ahh well, I'm sure a legendary user such as yourself could pull it off.


    About the server, I think I fully fledged private server would be overkill, you only really need th e login server.

    And another thought about this I had. If they panic, see their pwd isn't working, they might check on the WoW site and find it still works. Which will confuse the hell out of them, and may lead to them changing this password before it can be used.

    So if possible, rather than returning invalid password, just return server down, or unable to connect.

  6. #6
    Apoc's Avatar Angry Penguin
    Reputation
    1388
    Join Date
    Jan 2008
    Posts
    2,750
    Thanks G/R
    0/13
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I'm thinking of making it return unable to connect, then "throwing an error" (just killing the process), then putting the realmlist back to what it was, and letting them think it was just a weird bug. ^^

  7. #7
    Gamer's Avatar Active Member
    Reputation
    239
    Join Date
    Jan 2007
    Posts
    198
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yeah, thats a much better idea. It's best if they never knew what hit them xD...


    Then as they cry for help, all virus scans will strangely return blank, and they will claim that they didn't enter their password anywhere but the official WOW Client :P

  8. #8
    Opalis's Avatar Member
    Reputation
    10
    Join Date
    Dec 2008
    Posts
    10
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    changing the realmlist back to the original might be helpful, if they ever think to look at the realmlist afterwards; you don't want your server address incriminating you lol

    @Apoc: did you get this to work at all?

  9. #9
    MrNothing's Avatar Member
    Reputation
    32
    Join Date
    Mar 2007
    Posts
    143
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    epic idea!!! very nice!!

  10. #10
    Rec Alpam's Avatar Contributor CoreCoins Purchaser
    Reputation
    125
    Join Date
    Mar 2007
    Posts
    304
    Thanks G/R
    3/1
    Trade Feedback
    2 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    So someone planning to make it and release it to public ;D?

  11. #11
    Anotherfox's Avatar Contributor
    Reputation
    91
    Join Date
    Apr 2008
    Posts
    222
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I've been using something similar for a wee while now, and it gives MASSIVE results.

    On New Years Eve I'll post 2008 accounts (though no idea how to post that many!)

    +Rep from me.

  12. #12
    Gamer's Avatar Active Member
    Reputation
    239
    Join Date
    Jan 2007
    Posts
    198
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by didadonny View Post
    So someone planning to make it and release it to public ;D?
    You can already do the server part as Apoc said, by reading the login logs, although it may require modification for displaying the password. As for the program, very easy to create, simply write one line to a file.

    Which part did you need help with? The program I can release if required, the server modification is a bit out of my league


    Originally Posted by Anotherfox View Post
    I've been using something similar for a wee while now, and it gives MASSIVE results.

    On New Years Eve I'll post 2008 accounts (though no idea how to post that many!)

    +Rep from me.
    Haha, that's great to hear. Are you using a modified private server? Or a application that just collects login attempts?

  13. #13
    way2evil's Avatar Contributor
    Reputation
    171
    Join Date
    Mar 2007
    Posts
    394
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

  14. #14
    xsunwellx's Avatar Member
    Reputation
    6
    Join Date
    Nov 2008
    Posts
    111
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    My friend actually do this

  15. #15
    Bannersbomb's Avatar Member
    Reputation
    22
    Join Date
    Sep 2007
    Posts
    77
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Awesome idea... will you release this to the public to use?

Page 1 of 2 12 LastLast
All times are GMT -5. The time now is 08:23 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search