<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: F_ck Again</title>
	<atom:link href="http://www.bigredkitty.net/2007/12/24/f_uck-again/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/</link>
	<description>World of Warcraft Hunter Blog</description>
	<lastBuildDate>Thu, 16 Apr 2009 19:59:36 -0600</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: The Lords of Nordrassil &#187; Blog Archive &#187; WoW Account Security</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-14270</link>
		<dc:creator>The Lords of Nordrassil &#187; Blog Archive &#187; WoW Account Security</dc:creator>
		<pubDate>Mon, 21 Jan 2008 01:16:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-14270</guid>
		<description>[...] there have been a number of posts detailing account hack horrors, most notably BRK&#8217;s guild bank being cleared out twice in the same day and a similarly traumatic account hack incident for Gun Loving Dwarf Chick&#8217;s [...]</description>
		<content:encoded><![CDATA[<p>[...] there have been a number of posts detailing account hack horrors, most notably BRK&#8217;s guild bank being cleared out twice in the same day and a similarly traumatic account hack incident for Gun Loving Dwarf Chick&#8217;s [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Freejack</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12374</link>
		<dc:creator>Freejack</dc:creator>
		<pubDate>Sat, 29 Dec 2007 11:56:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12374</guid>
		<description>@Fio

&quot;He either got unlucky enough to get snagged by a zero-day exploit, or accounts can somehow be compromised regardless of precautions taken by the user.&quot;



Please keep us informed if there is any insight as to how this was done.</description>
		<content:encoded><![CDATA[<p>@Fio</p>
<p>&#8220;He either got unlucky enough to get snagged by a zero-day exploit, or accounts can somehow be compromised regardless of precautions taken by the user.&#8221;</p>
<p>Please keep us informed if there is any insight as to how this was done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to Improve your WoW Account Security &#124; Altitis</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12215</link>
		<dc:creator>How to Improve your WoW Account Security &#124; Altitis</dc:creator>
		<pubDate>Thu, 27 Dec 2007 13:57:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12215</guid>
		<description>[...] about one thing, keeping your PC secure isn&#8217;t anybody but your own business. And as this story from BRK&#8217;s guild shows, when you&#8217;re an officer and have guild bank access, you are a particularly fat goose to pluck [...]</description>
		<content:encoded><![CDATA[<p>[...] about one thing, keeping your PC secure isn&#8217;t anybody but your own business. And as this story from BRK&#8217;s guild shows, when you&#8217;re an officer and have guild bank access, you are a particularly fat goose to pluck [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fiordhraoi</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12133</link>
		<dc:creator>Fiordhraoi</dc:creator>
		<pubDate>Wed, 26 Dec 2007 18:13:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12133</guid>
		<description>Oh, and for the record, immediately after locking his account, Tweeden is proceeding to do a full reformat on both his WOW computers.</description>
		<content:encoded><![CDATA[<p>Oh, and for the record, immediately after locking his account, Tweeden is proceeding to do a full reformat on both his WOW computers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fiordhraoi</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12131</link>
		<dc:creator>Fiordhraoi</dc:creator>
		<pubDate>Wed, 26 Dec 2007 18:02:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12131</guid>
		<description>@Someone - 

No offense, but as things pertain to this situation, you have no idea what you&#039;re talking about.

He cleaned the computers that he use.  I walked him through it.  And no offense, I do this for a living.  I know how to make sure something isn&#039;t infected, at least if it&#039;s hit the radar on any of the major sites yet.

Symantec, AVG (Grisoft), TrendMicro, all came up negative.  Spybot, Windows Defender, negative.  The one odd thing was that his hosts file was missing - but if it was missing, that means it can&#039;t have been used to send him to a spoofed website.  Unless a virus magically removed itself after the second hack attempt, after somehow avoiding the existing (and maintained) AV software on the computer.

He doesn&#039;t use wireless to game.  The computer he plays wow on 99% of the time, he ONLY uses to play WoW.  He does not use .exe installers for mods, and gets the base files from curse.com or wowace.com.  He has a second account that he has used on the same computer, with the same password, that was not hacked.

So, where does this leave us for possibilities?

1) It is a new keylogger of some sort that infected his machine, therefore none of the above mentioned programs picked up on it.  Also, for whatever reason, the jackass who stole the stuff decided only to access one account - if it was a keylogger, he had the username and password to both accounts.

2) The UN/PW was obtained by some means other than a virus/wireless sniffing.  What that may be, I don&#039;t know.  Social engineering is unlikely given that only one person knew the UN/PW and he didn&#039;t give it to anyone, period.

So, I don&#039;t know how this happened, honestly.  Tweeden did all the right things, kept his computer safe, etc.  He either got unlucky enough to get snagged by a zero-day exploit, or accounts can somehow be compromised regardless of precautions taken by the user.</description>
		<content:encoded><![CDATA[<p>@Someone &#8211; </p>
<p>No offense, but as things pertain to this situation, you have no idea what you&#8217;re talking about.</p>
<p>He cleaned the computers that he use.  I walked him through it.  And no offense, I do this for a living.  I know how to make sure something isn&#8217;t infected, at least if it&#8217;s hit the radar on any of the major sites yet.</p>
<p>Symantec, AVG (Grisoft), TrendMicro, all came up negative.  Spybot, Windows Defender, negative.  The one odd thing was that his hosts file was missing &#8211; but if it was missing, that means it can&#8217;t have been used to send him to a spoofed website.  Unless a virus magically removed itself after the second hack attempt, after somehow avoiding the existing (and maintained) AV software on the computer.</p>
<p>He doesn&#8217;t use wireless to game.  The computer he plays wow on 99% of the time, he ONLY uses to play WoW.  He does not use .exe installers for mods, and gets the base files from curse.com or wowace.com.  He has a second account that he has used on the same computer, with the same password, that was not hacked.</p>
<p>So, where does this leave us for possibilities?</p>
<p>1) It is a new keylogger of some sort that infected his machine, therefore none of the above mentioned programs picked up on it.  Also, for whatever reason, the jackass who stole the stuff decided only to access one account &#8211; if it was a keylogger, he had the username and password to both accounts.</p>
<p>2) The UN/PW was obtained by some means other than a virus/wireless sniffing.  What that may be, I don&#8217;t know.  Social engineering is unlikely given that only one person knew the UN/PW and he didn&#8217;t give it to anyone, period.</p>
<p>So, I don&#8217;t know how this happened, honestly.  Tweeden did all the right things, kept his computer safe, etc.  He either got unlucky enough to get snagged by a zero-day exploit, or accounts can somehow be compromised regardless of precautions taken by the user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Macciatto</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12123</link>
		<dc:creator>Macciatto</dc:creator>
		<pubDate>Wed, 26 Dec 2007 15:24:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12123</guid>
		<description>Wouldn&#039;t it be nice if officers could demote themselves? This dude could demote himself and immediately have another officer demote him again to the lowest rank possible until the problem is resolved, aside from the /gkick solution.</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t it be nice if officers could demote themselves? This dude could demote himself and immediately have another officer demote him again to the lowest rank possible until the problem is resolved, aside from the /gkick solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OMG FD FTW</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12120</link>
		<dc:creator>OMG FD FTW</dc:creator>
		<pubDate>Wed, 26 Dec 2007 15:01:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12120</guid>
		<description>BRK - let us know the conclusion to the gbank drama...feel like we have been left hanging.</description>
		<content:encoded><![CDATA[<p>BRK &#8211; let us know the conclusion to the gbank drama&#8230;feel like we have been left hanging.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Someone</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12113</link>
		<dc:creator>Someone</dc:creator>
		<pubDate>Wed, 26 Dec 2007 12:50:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12113</guid>
		<description>Everyone can fall to a keylogger... ONCE!

If he goes on without ABSOLUTELY making sure his computer is clean, then *HE* is a liability for your guild.

If nothing else, he has proved he doesn&#039;t deserve to have such a position in the guild: he doesn&#039;t look to be responsible enough to treat his computer with the proper care and it will be a question of TIME until he compromises you guys again...

I wouldn&#039;t be surprised if Blizzard refused to return the items this time: I surely wouldn&#039;t blame them...</description>
		<content:encoded><![CDATA[<p>Everyone can fall to a keylogger&#8230; ONCE!</p>
<p>If he goes on without ABSOLUTELY making sure his computer is clean, then *HE* is a liability for your guild.</p>
<p>If nothing else, he has proved he doesn&#8217;t deserve to have such a position in the guild: he doesn&#8217;t look to be responsible enough to treat his computer with the proper care and it will be a question of TIME until he compromises you guys again&#8230;</p>
<p>I wouldn&#8217;t be surprised if Blizzard refused to return the items this time: I surely wouldn&#8217;t blame them&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Perkins</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12035</link>
		<dc:creator>Perkins</dc:creator>
		<pubDate>Tue, 25 Dec 2007 10:36:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12035</guid>
		<description>A little off subject but what&#039;s in Dire Maul worth farming?


And, great site BRK.  This is my first post but I&#039;ve been coming here almost daily for a few months now.  Keep up the excellent job and very sorry to hear about hacked account :(

Perkins &amp; Mandu</description>
		<content:encoded><![CDATA[<p>A little off subject but what&#8217;s in Dire Maul worth farming?</p>
<p>And, great site BRK.  This is my first post but I&#8217;ve been coming here almost daily for a few months now.  Keep up the excellent job and very sorry to hear about hacked account <img src='http://www.bigredkitty.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Perkins &amp; Mandu</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Freejack</title>
		<link>http://www.bigredkitty.net/2007/12/24/f_uck-again/comment-page-1/#comment-12003</link>
		<dc:creator>Freejack</dc:creator>
		<pubDate>Tue, 25 Dec 2007 00:00:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.bigredkitty.net/2007/12/24/f_uck-again/#comment-12003</guid>
		<description>&lt;a href=&quot;http://www.lavasoft.de/ms/ad_aware_free.php&quot; rel=&quot;nofollow&quot;&gt;Ad-Aware&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://www.lavasoft.de/ms/ad_aware_free.php" rel="nofollow">Ad-Aware</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
