| | Guild Wars Guru Security Notice! | |
|
| Author | Message |
|---|
TideSwayer
Administrator

Posts: 3382 Registered: 2009-03-17
 | Subject: Guild Wars Guru Security Notice! 2010-01-23, 8:40 pm | |
| Guild Wars Guru Security Notice!This Is A Direct Quote From A *VERY IMPORTANT* Guru Thread: Guild Wars Guru Security Notice | Quote: | Late Friday night the Guild Wars Guru database was accessed by an unknown third party. We caught it as it happened, but in that short space of time it appears they may have managed to obtain tables of user account information.
Their point of entry was a flaw in the WordPress software used to run the GuildWars2Guru.com front page. How they managed to get from there to the other databases is unknown right now, as it involved bypassing other security measures we have in place.
We've spent the 24 last hours tirelessly investigating what happened, patching up the exploit, and further strengthening security. It was important to inform the community as soon as possible, but we couldn't do that any earlier without advertising the site's vulnerability to others who may have more malicious intent.
So, what does this mean to you?
With the high incident of RMT hackings and phishing across MMO's rising we understand how serious this problem is, and the possible implications arising from this incident. Right now we assume the hacker's motivation was simply to obtain the list of email addresses, for the purpose of sending spam. That may seem fairly mundane, but there's a big market for that information.
Anything more sinister would require the hacker attempting to crack encrypted passwords. The investment required to do that seems to far outweigh the questionable return, though we can't rule it out. As such, we urge you to change your Guru, Guru Auctions and Guru 2 passwords and/or emails as soon as possible. We also urge you to change passwords and emails for any other site or service you log in to with the same information you use on guru.
We apologize for this unprecedented breach, and can only assure that your security is of the utmost importance to us. We are gamers as well, and are doing everything in our power to minimize the damage from this by informing our community openly. If you have questions or concerns please feel free to post them here, and we will do our best to address them as swiftly as possible. To further protect your account please see (the Guild Wars Guru) guides on Phishing, Security, PlaySmart and Passwords. |
______________________ 
Last edited by TideSwayer on 2010-01-24, 9:24 am; edited 2 times in total |
|
 | |
TideSwayer
Administrator

Posts: 3382 Registered: 2009-03-17
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-23, 8:48 pm | |
| Obviously, this means that if your Guild Wars Guru password is the same or anywhere near what your actual Guild Wars Account(s) passwords are, CHANGE IT IMMEDIATELY!
Hell, CHANGE IT IMMEDIATELY! regardless. This is a very serious security breach. Guru is the #1 GW fansite so you should undoubtedly be using an alternate email and/or password for that site.
You don't have to worry about them stealing your IGNs from Guru or any information that was disclosed in any Guru PMs that you sent. According to the Guru Security Notice thread, the IGNs in profiles got wiped when they removed them from view a couple of months ago, and user PM boxes weren't accessed. This is why I've suggested removing the IGNs from these forums, but as of now they are only set to where registered members can read them (so we're not in much danger). If I get the feeling that our profile IGNs are ever being used in malicious ways, they are GONE. ______________________  |
|
 | |
Reave
Administrator

Posts: 1877 Registered: 2009-03-17
Age: 20 Location: Connecticut
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-23, 9:11 pm | |
| | TideSwayer wrote: | Guild Wars Guru Security Notice!
This Is A Direct Quote From A *VERY IMPORTANT* Guru Thread: Guild Wars Guru Security Notice
| Quote: | | With the high incident of RMT hackings and phishing across MMO's rising we understand how serious this problem is, and the possible implications arising from this incident. Right now we assume the hacker's motivation was simply to obtain the list of email addresses, for the purpose of sending spam. That may seem fairly mundane, but there's a big market for that information. |
|
The Guru network has around million+ e-mails on there database. Companies would pay lots of money for that list and spam everyone with advertisements. Nothing is safe on the internet.______________________  |
|
 | |
TideSwayer
Administrator

Posts: 3382 Registered: 2009-03-17
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-23, 9:15 pm | |
| | Reave wrote: | | The Guru network has around million+ e-mails on there database. Companies would pay lots of money for that list and spam everyone with advertisements. Nothing is safe on the internet. |
That's fine to me. I was just thinking the other day how I wasn't getting as many penis pills emails as I once used to.
In any case, Google's GMail spam filter rocks. The email I use for fan sites is my spam email address (which I also use for communication as well), but it's not directly connected to any of my game accounts or credit card/bank/business accounts.______________________  |
|
 | |
Mio
Level 6 Member

Posts: 1077 Registered: 2009-04-05
Age: 19 Location: Del's Secret Dirty Basement
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-24, 4:12 am | |
| Its most likely the germans ... :p |
|
 | |
Grace
Level 6 Member

Posts: 1060 Registered: 2009-11-25
Location: a garden
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-25, 10:44 am | |
| | TideSwayer wrote: | | Reave wrote: | | The Guru network has around million+ e-mails on there database. Companies would pay lots of money for that list and spam everyone with advertisements. Nothing is safe on the internet. |
That's fine to me. I was just thinking the other day how I wasn't getting as many penis pills emails as I once used to.
In any case, Google's GMail spam filter rocks. The email I use for fan sites is my spam email address (which I also use for communication as well), but it's not directly connected to any of my game accounts or credit card/bank/business accounts. |
miie too. minus the penis pills ads I dont miss those. LOL!
just a question... what could they do with you IGN if they cant get your email or pw? nothing right? |
|
 | |
TideSwayer
Administrator

Posts: 3382 Registered: 2009-03-17
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-25, 10:53 am | |
| | Grace wrote: | | just a question... what could they do with you IGN if they cant get your email or pw? nothing right? |
As Guru noted, some user account email addresses were accessed, but the Guru passwords are (supposedly) encrypted so they don't think the hacker(s) would be bothered to take the time to decrypt those (if they even got access to 'em). I agree with Guru in that most likely this was a random drive-by hacking for legitimate email addresses and has nothing to do with actual Guild Wars hacking/scamming/phishing attempts. I haven't noticed any funny business with either my Guru account, my in-game account (impossible to gain access via Guru regardless), or my email account linked to Guru, so it's seeming that way.
Your IGN could be used by gold-sellers to PM their website & ad to you in-game. Remember about a year and a half ago that was pretty common (and it was mad annoying too!).______________________ 
Last edited by TideSwayer on 2010-01-25, 12:50 pm; edited 1 time in total |
|
 | |
Grace
Level 6 Member

Posts: 1060 Registered: 2009-11-25
Location: a garden
 | Subject: Re: Guild Wars Guru Security Notice! 2010-01-25, 11:05 am | |
| | TideSwayer wrote: | | Your IGN could be used by gold-sellers to PM their website & ad to you in-game. Remember about a year and a half ago that was pretty common (and it was mad annoying too!). |
actually no. but I am super forgetful. I'll have to ask Killian about it when he gets off work. I know about gold seller thingys a little, but I dont understand the pm their website or what ever... you cant duplicate an IGN... so were they spamming players when they logged in? Maybe im just tired. I dont get it. |
|
 | |
| | Guild Wars Guru Security Notice! | |
|