[Alert] Blizzard Authenticator Compromised! menu
100% Up to 1000$
4.9/5
150% Up to 200$ & 20 Freespins
4.8/5
Up to 1 BTC
4.9/5
20% Cashback
4.8/5
Up to 5 BTC
4.8/5
100% Up to 1 BTC
4.7/5
Up to 5 BTC
4.7/5
110% Up to 1 BTC
4.6/5

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 16
  1. #1
    Sneakylemons's Avatar Contributor
    Reputation
    121
    Join Date
    Aug 2008
    Posts
    605
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    [Alert] Blizzard Authenticator Compromised!

    [Alert] Blizzard Authenticator Compromised!
    Anyone who has an authenticator attached to their account should run a search (and probably an antivirus scan in case it's on the threat list already) immediately and ensure the file emcor.dll does not exist on your computer. This file is one reported to be allowing hackers to access World of Warcraft accounts that have authenticators attached to them. It's also possible there are other variations of these suspicious files, so if anyone has additional information please respond in the comments.

    Based on this thread, the file may be found in /users/username/appdata/Temp. Since the file is fairly new (first mentions of it are only a few days ago), and the common source is unknown, I urge everyone to not log in to World of Warcraft or the account management site until you've run a scan. Confirm your computer is secure before using your authenticator, because this DLL file is allowing hackers to crack through it and access your account.

    A warning sign that you're currently infected with this keylogger is that WoW will say your authentication code is incorrect, even if you know for sure you typed in the correct code.

    Here are some additional follow up details about the authenticator situation.

    First of all, Blizzard has confirmed this as a man in the middle attack:

    Official Blizzard Quote:
    [Blizzard Source]

    After looking into this, it has been escalated, but it is a Man in the Middle attack.
    Man-in-the-middle attack - Wikipedia, the free encyclopedia

    This is still perpetrated by key loggers, and no method is always 100% secure.

    Additionally, Cameron, a World of Raids user, has done some digging into the file and discovered the following information to potentially help you if you've been infected. Here are the details from his digging:

    Firewall IP Block
    You may be able to block the IP 205.209.181.111 to help prevent your information from reaching the hackers. This is of course something that may change after they find out they've been discovered, but it should offer some temporary help while you get rid of all the files.

    Quote:
    This info is preliminary. If you use it you should also take the steps you do normally

    The keylogger will send the data to:
    Host: 205.209.181.111
    Port: 1068

    The keylogger data file can be found in /users/username/appdata/Temp along with the DLL

    Update 1:

    The keylogger sends the "current tick" to the server. Presumably so it can tell how long it has to use the code.

    Brought to you by bored geek.
    Keylogger Server Details
    This information was also discovered by Cameron, and is essentially the "known" location of the server collecting data sent by the keylogger.

    Quote:
    The keylogger is a standard windows based keylogger which uses SetWindowsHookEx hooking as a debug hook (WH_DEBUG) so it gets first dibbs on typed data (Although for some reason it does pass on the data to other hooks and not block them...)

    The data is set to:
    Host: 205.209.181.111
    Port: 1068

    OrgName: Managed Solutions Group, Inc. (Known spamming server)
    OrgID: MSG-48
    Address: 45535 Northport Loop East
    City: Fremont
    StateProv: CA
    PostalCode: 94538
    Country: US
    This was taken straight from the arena junkies front page, i just wanted everyone to know about this so they can keep their accounts safe, because i am not sure how many people actually visit AJ. Hope this helps

    -Sneakylemons
    I WAS DRILL ROLLED BY GZ. AND I LOVED IT.


    [Alert] Blizzard Authenticator Compromised!
  2. #2
    kys89012345's Avatar Member
    Reputation
    1
    Join Date
    Jan 2008
    Posts
    9
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    thankx be safe

  3. #3
    Nightfinger's Avatar Member
    Reputation
    5
    Join Date
    Dec 2007
    Posts
    85
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Their is no safety.. Their is nothing left..What now!?!!

  4. #4
    Woodlauncher's Avatar Member
    Reputation
    6
    Join Date
    Jan 2009
    Posts
    98
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Nightfinger View Post
    Their is no safety.. Their is nothing left..What now!?!!
    What is that supposed to mean?

  5. #5
    void07's Avatar Member
    Reputation
    1
    Join Date
    May 2008
    Posts
    9
    Thanks G/R
    0/0
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    The title of this thread is incorrect and misleading.

    Authenticators have not been compromised in any way. Computers have been infected with a trojan/keylogger that intercepts your authenticator code and immediately sends it off to the hacker.

    Systems will almost always be subject to Man-in-the-middle attacks.

    Any computers running a decent antivirus should have this on pop on them.

  6. #6
    ragex1980's Avatar Member
    Reputation
    1
    Join Date
    Jan 2009
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    in lamens terms man in middie is actualy a situation like this


    enter data---> sent to hacker----> relayed to corect destination

    hacker just logs etc etc

    thats the correct design of man in the middle attack

    it is different to logging and sending the logs to hackers server, thats just plain loging

    kthx

  7. #7
    Raskel's Avatar Member
    Reputation
    10
    Join Date
    Sep 2007
    Posts
    129
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    With this method the hacker will only have access to your account until you login or he disconnects though. The code changes every 30 seconds so he only has a 30 second gap. When he logs out he will have to guess or hijack the code again.

    He will also never be able to remove the authenticator as it needs 2 codes to be removed.

    Basically he has time until you cleaned your pc and access your account again.
    :wave:twocents:confused::yuck:6):

  8. #8
    SpaZMonKeY's Avatar Contributor
    Reputation
    106
    Join Date
    May 2007
    Posts
    192
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Raskel View Post
    With this method the hacker will only have access to your account until you login or he disconnects though. The code changes every 30 seconds so he only has a 30 second gap. When he logs out he will have to guess or hijack the code again.

    He will also never be able to remove the authenticator as it needs 2 codes to be removed.

    Basically he has time until you cleaned your pc and access your account again.
    This is perfectly accurate. +Rep!

  9. #9
    Raskel's Avatar Member
    Reputation
    10
    Join Date
    Sep 2007
    Posts
    129
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by SpaZMonKeY View Post
    This is perfectly accurate. +Rep!
    Mighty thanks

    I'm still sticking to my authenticator
    :wave:twocents:confused::yuck:6):

  10. #10
    asherbourne's Avatar Member
    Reputation
    2
    Join Date
    Sep 2009
    Posts
    14
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    anything is possible >.<

  11. #11
    Azylum's Avatar Corporal
    Reputation
    6
    Join Date
    Nov 2009
    Posts
    23
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thought about this when i got mine. Knew it was possible but wth... The authenticator provides some extra security anyways.

  12. #12
    mmodame's Avatar Member
    Reputation
    1
    Join Date
    Mar 2010
    Posts
    28
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I was hoping this thread might have some info on what's going on because there must be some way around the autheticator. I had an authenticator on my account and was hacked after I hadn't played for over a month so it couldn't have been a man in the middle attack...how is that possible?

    Of course all Blizzard said was that autheticators aren't guarenteed and I should check my PC for keyloggers etc etc...

  13. #13
    dwsj's Avatar Private
    Reputation
    1
    Join Date
    Mar 2010
    Posts
    11
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I do not see any problem with this, because of the fact that the authenticator cannot be removed, and that the haxxzor needs time to bypass through everytime, theres not much he can do, and besides 11million WoW accounts and max of 100 haxxors means its probably going to be awhile until your even considered a target

  14. #14
    Oloty's Avatar Member
    Reputation
    8
    Join Date
    Jun 2009
    Posts
    57
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanx! +rep for you!

  15. #15
    Tranquility [X]'s Avatar Sergeant
    Reputation
    7
    Join Date
    Apr 2010
    Posts
    46
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This doesn't worry me too much tbqh because of various points made above.
    MMOwned V2 FTW

Page 1 of 2 12 LastLast

Similar Threads

  1. Blizzard Authenticator Security Token- an end to scamming ?
    By shadowfox47 in forum World of Warcraft General
    Replies: 5
    Last Post: 07-30-2008, 06:02 PM
All times are GMT -5. The time now is 02:27 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search