Forum

> > Unreal Software > My account got hijacked!
Forums overviewUnreal Software overviewLog in to reply

English My account got hijacked!

62 replies
Page
To the start Previous 1 2 3 4 Next To the start

old Re: My account got hijacked!

Nekomata
User Off Offline

Quote
Well, yes, there could be other means of getting access to your account. But seriously, user Mami Tomoe, are you going to believe someone who got access to your account and banned everyone on your server?

old Re: My account got hijacked!

Yates
Reviewer Off Offline

Quote
@user Mami Tomoe: So the person that logged into your account, who stole your details and ruined your server is telling you to not reset your PC because he will tell you how to remove it? (By the way I already told you it will never be marked as a virus).

Haha dude do you even believe that?

You know what, do whatever you want to. I gave you a good solution, if you don't use it and Gajos fucks with your server again it's your own fault. Think about that before you post again because right now I'm getting pretty damn tired of you asking for help but ignoring everything I say - which other people said was the best option for you.

old Re: My account got hijacked!

VADemon
User Off Offline

Quote
user Raisun Asus has their own cloud storage, you should have a few gigabytes free there.

I might be able to help you, if you contact me very soon. Requirement: ~1 hour time, Skype screensharing/Teamviewer + ProcessExplorer (a better task manager). I do not guarantee that I will find that exact virus, but I'm pretty sure though that you will have unwanted shit in your system.
PM me your skype address in case of interest.

old Re: My account got hijacked!

MikuAuahDark
User Off Offline

Quote
While reading all of the comments, I remember something in w0w citylife server before.

w0w citylife has few-steps verification system for admins. I added this verification because I disabled cs2d cmd sv_checkusgnlogin in w0w citylife(I can't enter the server with that enabled).

1. USGN ID check
2. IP check
3. Password

So, example:
1. Player login with USGN ID that is registered as admin in that server. That means point 1 passed and server will try to do point 2. If point 2 fails, it goes to point 3 instead.
2. The server performs IP check. If it matches the first and the second number of the IP(<number>.<number>.*.*) then point 2 passed and that player given an admin access
3. Show message "Sorry, we don't know that you've been logged in with this IP before(<user IP here>). Type !verify <password> to gain admin access".

I hope my explanation can give you idea how to protect your admin access.

old Re: My account got hijacked!

DC
Admin Off Offline

Quote
Here's a quick guide on how to not getting "hacked" by kids:

Precautions

• Don't run any program unless you're 100% sure that it's safe. Attachments from mails or exe files sent by "friends" shouldn't be executed. Also most CS2D hacks are designed to steal passwords. Run them and your account is lost.

• Never use the same password for different websites/services. Use very different and safe passwords for everything. This is especially true for the e-mail account which should have a very different and very safe password because it's required for account recovery.

• For CS2D server admins please note: http://www.cs2d.com/security.php

• Use good protective software with proper setup. Firewall and anti virus.

• Only download my games from the official download links. Do not use modified versions.

• Needless to say: Never tell anyone (not even me! PLEASE! I don't want to know it) your password. Also always double check the internet address before entering your password on websites. There might be fake clone sites to harvest passwords.


When you already have problems

• Check running programs in your task manager. Google them. Consider to remove stuff you don't know (after verifying that it's not part of Windows or any other software you installed).

• Check your PC for malware with anti virus and malware software (but make sure to download the latest definitions first)

• Change all passwords. Again: NEVER USE THE SAME PASSWORD FOR MULTIPLE THINGS!
Read this (or comparable articles) to learn more about safe passwords: http://www.lockdown.co.uk/?pg=password_guide
× If you're too lazy to change all passwords (bad idea) then please at least change your email password(s) and your account password.

You assume that you have malware which is sending stuff to the attacker?

This can be handled in at least three ways:

1. Check the task manager / running processes (see above).

2. Install a good software firewall which always asks for permission before allowing any traffic (annoying in long term but cool to find the bad program)

3. (this is for advanced users) Install software which allows you to read out all internet traffic. e.g.: https://www.wireshark.org/
edited 1×, last 14.10.15 07:22:23 pm

old Re: My account got hijacked!

Mami Tomoe
User Off Offline

Quote
He didn't hack my actual account and no I don't have a virus.

Gajos has a hack that he can use to fake USGN IDs on CS2D.
edited 1×, last 14.10.15 09:17:44 pm

old Re: My account got hijacked!

oxytamine
User Off Offline

Quote
user Mami Tomoe has written
Gajos has a hack that he can use to fake USGN IDs on CS2D.

You could before (when I was active in CS2D), don't know whether it's still possible. Better ask user DC about that - how many handshakes are there, etc.

old Re: My account got hijacked!

Yates
Reviewer Off Offline

Quote
So, why has Gajos not targeted any other server than FWS? Why has Gajos not logged in as DC? Why has Gajos not just changed his ID to an administrator USGN which is used on the server?

It makes no sense. If I would have made a working USGN ID changer and I were going to target servers I'd change my USGN ID to the owner of the server. Not a mod and a member. Come on.

By the way:
user sheeL has written
Stop using cheats and Gajos won't hack your usgn anymore. Problem solved

user Slovjan has written
Yup, just ban him.

SheeL stated you were using hacks, Gajos even said "yup" to confirm this. The first sign he has a tool on your PC.

user Slovjan has written
Do you remember Gajos hisotry? he also got hacked and now he want to do it some else.

"He also got hacked" (Gajos is referring to himself), indicates he didn't hack his way into USGN, but again that he just has a tool on your PC.


And then there's this:
Quote
[16:11:44] Adrian Gajos: dont tell to he do hardreset
[16:11:52] Adrian Gajos: it's unnecessary

Implying that he has a tool on your PC which sends him data. If he could really change his USGN ID he'd say:

Quote
[16:11:44] Adrian Gajos: dont tell to he do hardreset
[16:11:52] Adrian Gajos: it won't help

Which he didn't. So reset your PC already, Gajos won't tell you where the tool is.

old Re: My account got hijacked!

Nekomata
User Off Offline

Quote
Here are some corrected facts

Fws isn't targetted. The only targeted areas are -Hawk-s' and user Mami Tomoe's server.

The one who hacked these two people's USGNs
• Dark Night / Darklight
• Memories
was user Slovjan. (IP matched)

And lastly, user BlackBuLL is not hacked. ×

In short terms;
Gajos affected => {user Mami Tomoe}
user Slovjan affected => {DarkNight & Memories}


Both have different IPs. There's a probability that they're either the same people or that they're acquaintances.

old Re: My account got hijacked!

DC
Admin Off Offline

Quote
Faking U.S.G.N. IDs in-game is possible if the server is not secured properly. See cs2d cmd sv_checkusgnlogin to learn more. The requirement to make this work (over a longer period of time) is to fake the IP of the actual logged in user though / to have the same IP.
This is not tested in all detail because it's really difficult to test. So there might be ways to trick the system.

It's not possible to simply login into the website account though - unless you have the password of course.

old Re: My account got hijacked!

Mami Tomoe
User Off Offline

Quote
@user DC: This, Is, Gajos.
ok lets read what i said above again k?
This, Is, Gajos.
also the password verify is on... it was always on and always be on...

old Re: My account got hijacked!

DC
Admin Off Offline

Quote
He then found a security leak. That's bad but maybe he'll stop some day
I'm sorry for the inconvenience. I don't know how he does it so I can't fix it.
To the start Previous 1 2 3 4 Next To the start
Log in to replyUnreal Software overviewForums overview