The Blizzard Authenticator - not 100% secure menu

User Tag List

Results 1 to 12 of 12
  1. #1
    tekstorm's Avatar Active Member
    Reputation
    56
    Join Date
    Jan 2007
    Posts
    232
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    The Blizzard Authenticator - not 100% secure

    With the current rumors going around that Blizzard is planning on shipping cataclysm with an authenticator and making it mandatory to use you may be thinking, "I don't have to worry about my account ever being hacked with my handy authenticator!"

    Wrong.

    Why you ask? Most scammers are adapting to the use of authenticators. These scammers would just pray that you download their keyloggers or malware and download the logs from your PC at a later time. The days of the lazy scammer are over. These individuals are now using massive botnets to infect for not only your wow accounts but your financial information as well.

    How does it work? A botnet is a collection of compromised boxes that can be collectively used to launch attacks and infect even more computers. These botnets use IRC (Internet Relay Chat) to gather data from malware and keyloggers.

    Here is how they get your WoW account, the hacker sits in an IRC channel let's say on undernet's network and from there his botnet has logged into the channel as well and is sending him streams of data. First he sees you log in and he gets your account name and password. He already has battle.net loaded up on another screen waiting for you to log in again. The next time you log in he steals your new authenticator code and immediately copy pastes it into battle.net.

    Authenticator codes are valid for 30 seconds!! That is all the time they need to get into your wow account and change the password, plus remove your existing authenticator.

    This same method can be used with banking accounts. Several banks use authenticators as well.

    Don't give in to a false sense of security. Never enter your account e-mail address on a gold selling site or account trading site. Even if just for a quote! All they need is your account name and they can run a cracker to figure out the password. If not they can just use some social engineering with blizzard to get it.

    Free Software tools to use:
    malwarebytes
    AVG anti virus
    hijackthis - learn how to use this!! there is many guides available on google.

    One last thing! Don't login to battle.net on a public network, like free wifi at a cafe or restaurant. SSL encryption is not that secure, I can strip ANY SSL encryption on ANY public network. In a day I can have every customers banking information or other personal information if I wanted to.

    I know this is a long read but I hope this information helps you in protecting your WoW account and your personal information.

    The Blizzard Authenticator - not 100% secure
  2. #2
    milonix's Avatar Member
    Reputation
    1
    Join Date
    Sep 2009
    Posts
    1
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This all false the code only last's for 15 seconds i have one there is really no way to get i myself tried to hack my own and my brothers its not happening...

    Originally Posted by tekstorm View Post
    With the current rumors going around that Blizzard is planning on shipping cataclysm with an authenticator and making it mandatory to use you may be thinking, "I don't have to worry about my account ever being hacked with my handy authenticator!"

    Wrong.

    Why you ask? Most scammers are adapting to the use of authenticators. These scammers would just pray that you download their keyloggers or malware and download the logs from your PC at a later time. The days of the lazy scammer are over. These individuals are now using massive botnets to infect for not only your wow accounts but your financial information as well.

    How does it work? A botnet is a collection of compromised boxes that can be collectively used to launch attacks and infect even more computers. These botnets use IRC (Internet Relay Chat) to gather data from malware and keyloggers.

    Here is how they get your WoW account, the hacker sits in an IRC channel let's say on undernet's network and from there his botnet has logged into the channel as well and is sending him streams of data. First he sees you log in and he gets your account name and password. He already has battle.net loaded up on another screen waiting for you to log in again. The next time you log in he steals your new authenticator code and immediately copy pastes it into battle.net.

    Authenticator codes are valid for 30 seconds!! That is all the time they need to get into your wow account and change the password, plus remove your existing authenticator.

    This same method can be used with banking accounts. Several banks use authenticators as well.

    Don't give in to a false sense of security. Never enter your account e-mail address on a gold selling site or account trading site. Even if just for a quote! All they need is your account name and they can run a cracker to figure out the password. If not they can just use some social engineering with blizzard to get it.

    Free Software tools to use:
    malwarebytes
    AVG anti virus
    hijackthis - learn how to use this!! there is many guides available on google.

    One last thing! Don't login to battle.net on a public network, like free wifi at a cafe or restaurant. SSL encryption is not that secure, I can strip ANY SSL encryption on ANY public network. In a day I can have every customers banking information or other personal information if I wanted to.

    I know this is a long read but I hope this information helps you in protecting your WoW account and your personal information.

  3. #3
    wowpew's Avatar Active Member
    Reputation
    27
    Join Date
    Jul 2006
    Posts
    121
    Thanks G/R
    0/3
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Authenticator codes are one-off. As soon as one is used it can't be used again. Try logging in with an incorrect password and a correct authenticator code, and then login with the correct password and the same authenticator code. It won't work because the authenticator code has been used once.

    Basically the hacker would have to not only eavesdrop on your traffic, but stop the authenticator code from reaching Blizzards servers.

  4. #4
    DragoHorse's Avatar Contributor
    Reputation
    153
    Join Date
    May 2009
    Posts
    223
    Thanks G/R
    10/2
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    To remove an Authenticator, you need to fill in 2 Authenticator codes...

  5. #5
    SpaZMonKeY's Avatar Contributor
    Reputation
    106
    Join Date
    May 2007
    Posts
    192
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by DragoHorse View Post
    To remove an Authenticator, you need to fill in 2 Authenticator codes...
    This is correct. Maybe the OP should have read my detailed post about Blizzard's Authenticators before posting: http://www.mmowned.com/forums/world-...-security.html

  6. #6
    machaa's Avatar Sergeant
    Reputation
    34
    Join Date
    Oct 2010
    Posts
    43
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by wowpew View Post
    Basically the hacker would have to not only eavesdrop on your traffic, but stop the authenticator code from reaching Blizzards servers.
    I'm sure if someone is that determined to hack your account that they would go to such lengths as to record what authenticator code you put in, they would be able to stop WoW.exe from accessing the internet.

  7. #7
    Grymsko's Avatar Private
    Reputation
    1
    Join Date
    Oct 2010
    Posts
    6
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    As said, Authenticators are not 100% safe, but it's usually a "Man in the middle attack" Here's a thread about it.

    World of Warcraft (en) Forums -> Hacked with authenticator

  8. #8
    4L3X's Avatar Member
    Reputation
    14
    Join Date
    Aug 2010
    Posts
    81
    Thanks G/R
    11/0
    Trade Feedback
    1 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This is a fail. Firstly, if you want to remove the authenticator, you need to enter 2 more. Additionally, it's only about 15 seconds, maybe 20 and even so that's only when it's just fresh. Sometimes you'll get your authenticator and it's half way for the new code. Also, someone can easily recover their account by asking blizzard to restore it, and proof that they had the authenticator by telling blizzard the authenticator serial number. And if they know that they got keylogged, they just phone blizzard instead. I doubt by now the hacker, however lazy they are will tap into the phone convo for a GAME account...

  9. #9
    AmyW's Avatar Member
    Reputation
    1
    Join Date
    Jun 2009
    Posts
    6
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by wowpew View Post
    Authenticator codes are one-off. As soon as one is used it can't be used again. Try logging in with an incorrect password and a correct authenticator code, and then login with the correct password and the same authenticator code. It won't work because the authenticator code has been used once.

    Basically the hacker would have to not only eavesdrop on your traffic, but stop the authenticator code from reaching Blizzards servers.
    This is incorrect.

    Me and my partner have (and still are) shared one single authenticator since the start of last year. We sometimes logs in with the same code as we usually start WoW at the same time. Also I can re-use the same code if I fail to login (mistyped password). The code might however be locked to a certain IP for a few min after it's been used though allowing this IP to use the code again.

  10. #10
    Duplicity's Avatar Contributor
    Reputation
    282
    Join Date
    Mar 2007
    Posts
    596
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Necro posting is necro.

    Anyways. Blizzard has a new authentication option: Call in authenticator.
    I'm not 100% sure about how long the code works. Maybe it's the same thing. But it's much safer because you can only call with a designated number to get the code. The only possible way someone can actually remove the authenticator or anything is to hold you at gun point for a WoW account.

  11. #11
    AmyW's Avatar Member
    Reputation
    1
    Join Date
    Jun 2009
    Posts
    6
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Duplicity View Post
    Necro posting is necro.
    Before I posted in this topic this was one of the top topics on the page. This is not a very active sub forum and most posting in here would then be considered "necro posting". So you may as well just shut this place down or nobody will be able to post anything..

  12. #12
    Pancrazio6689's Avatar Banned
    Reputation
    1
    Join Date
    Apr 2011
    Posts
    86
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This is a fail. Firstly, if you want to remove the authenticator, you need to enter 2 more. Additionally, it's only about 15 seconds, maybe 20 and even so that's only when it's just fresh. Sometimes you'll get your authenticator and it's half way for the new code. Also, someone can easily recover their account by asking blizzard to restore it, and proof that they had the authenticator by telling blizzard the authenticator serial number. And if they know that they got keylogged, they just phone blizzard instead. I doubt by now the hacker, however lazy they are will tap into the phone convo for a GAME account...

Similar Threads

  1. Replies: 14
    Last Post: 11-25-2014, 06:17 AM
  2. - The Blizzard Authenticator - Ultimate Security -
    By SpaZMonKeY in forum WoW Scam Prevention
    Replies: 106
    Last Post: 07-10-2010, 01:08 AM
  3. Blizzard Authenticator Security Token- an end to scamming ?
    By shadowfox47 in forum World of Warcraft General
    Replies: 5
    Last Post: 07-30-2008, 06:02 PM
  4. Get around the Blizzard downloader.
    By Threndil in forum World of Warcraft Exploits
    Replies: 20
    Last Post: 12-06-2006, 02:27 AM
  5. kill the enemy when not in PVP
    By Warto in forum World of Warcraft Exploits
    Replies: 0
    Last Post: 06-11-2006, 07:44 PM
All times are GMT -5. The time now is 03:45 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search