Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Beware People Attempting to Hack Your Account

Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 08:57
Today, for the second time in a couple of weeks I got an email titled "Second Life: Password Assistance" It reads as follows:

From: someone

Click the link below to reset your password http://secondlife.com/ss/veryfiy.php?r=(long alpha numeric code)
If clicking does not work, you can copy and paste the link into your browser's address window, or retype it there. Once you have returned to secondlife.com,we will give instructions for resetting your password.

Linden Lab and the Second Life Team
http://secondlife.com


If you get one of these in your email, DO NOT CLICK THE LINK! Doing so will allow whoever caused the email to be sent to you to change your password, and then wreak havok on your account.
Just delete the email. The link will expire in a couple of hours.

Whoever keeps doing this thinking I'm stupid enough to fall for it, grow up.
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Beryl Greenacre
Big Scaredy-Baby
Join date: 24 Jun 2003
Posts: 1,312
07-01-2005 09:07
Thanks for posting about this, Chip. I think the Lindens had a MOTD a couple weeks back about it, too. It's important to mention this periodically if it's happening on a continuing basis.
_____________________
Swell Second Life: Menswear by Beryl Greenacre
Miramare 105, 82/ Aqua 192, 112/ Image Reflections Design, Freedom 121, 121
Dianne Mechanique
Back from the Dead
Join date: 28 Mar 2005
Posts: 2,648
07-01-2005 09:25
From: Beryl Greenacre
Thanks for posting about this, Chip. I think the Lindens had a MOTD a couple weeks back about it, too. It's important to mention this periodically if it's happening on a continuing basis.
Yeah, thanks Chip :)

Spoofing is scary, and easy to get caught on.

I always check for grammar bad.
It makes really good notice of they thinking of sender.

.
_____________________
.
black
art furniture & classic clothing
===================
Black in Neufreistadt
Black @ ONE
Black @ www.SLBoutique.com


.
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 09:36
I don't think it's spoofing. I think people use the "I forgot my password" thing which causes an email to be sent out with the link to reset your password. If you click the link then whoever was trying to log in to your account has a chance to get there before you and change it. That's my theory anyway.
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Aimee Weber
The one on the right
Join date: 30 Jan 2004
Posts: 4,286
07-01-2005 09:37
So is the e-mail traceable? Or is there any reliable way to track this person down? It seems to me that this behavior is more of a criminal violation than a simple TOS issue.
_____________________
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 09:41
From: Aimee Weber
So is the e-mail traceable? Or is there any reliable way to track this person down? It seems to me that this behavior is more of a criminal violation than a simple TOS issue.


I'm not sure Aimee. It could be someone who's not even an SL member. If they are I suppose LL could compare the IP that initiated the password change request to the IP's of users. If they found a match they could ban that IP.
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Chris Wilde
Custom User Title
Join date: 21 Jul 2004
Posts: 768
07-01-2005 09:41
From: Aimee Weber
So is the e-mail traceable? Or is there any reliable way to track this person down? It seems to me that this behavior is more of a criminal violation than a simple TOS issue.

The email would be generated by LL. Only LL would have the ability to find the IP of those requesting the password generation.
Aimee Weber
The one on the right
Join date: 30 Jan 2004
Posts: 4,286
07-01-2005 09:46
From: Chris Wilde
The email would be generated by LL. Only LL would have the ability to find the IP of those requesting the password generation.

From: Chip Midnight
I'm not sure Aimee. It could be someone who's not even an SL member. If they are I suppose LL could compare the IP that initiated the password change request to the IP's of users. If they found a match they could ban that IP.


Good points. I guess these kinds of perps are just generally difficult to pursue.
_____________________
Cristiano Midnight
Evil Snapshot Baron
Join date: 17 May 2003
Posts: 8,616
07-01-2005 09:48
Just out of curiousity, how do they have the account email addresses to email people anyway?
_____________________
Cristiano


ANOmations - huge selection of high quality, low priced animations all $100L or less.

~SLUniverse.com~ SL's oldest and largest community site, featuring Snapzilla image sharing, forums, and much more.

China Frost
Registered User
Join date: 4 Mar 2005
Posts: 16
07-01-2005 09:49
If you look in the headers of the e-mail you can find the IP address where the e-mail originated. You can look up the IP address on WHOIS

http://www.networksolutions.com/en_US/whois/index.jhtml

Also you can get the IP address of whatever site you are redirected to (right click the link in your e-mail, copy location, and paste it into notepad) and look it up.

Forward this information to LL, they most likely have procedures on contacting ISPs regarding the behavior.
Blayze Raine
Renegade
Join date: 29 Dec 2004
Posts: 407
07-01-2005 09:52
I can't remember, but did LL ask an additional security question when you created your account? If not, that would be the best thing to use as an added measure when someone wants their password reset.

Account security has to be a tricky thing for them to deal with considering everyone has your login name anyway. I would definitely rather go through the inconvenience of an extra step or two when accessing my account or requesting a password change than to have someone be able do this.
Jonquille Noir
Lemon Fresh
Join date: 17 Jan 2004
Posts: 4,025
07-01-2005 10:09
From: Cristiano Midnight
Just out of curiousity, how do they have the account email addresses to email people anyway?


I don't think they do, Cris. The email is actually sent from LL.

If you try to sign into an account and don't know the password, you can request they send you the password.. but the email will be sent to whatever email you have linked to your SL account, not the email of the person trying to log into the account.
_____________________
Little Rebel Designs
Gallinas
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 10:54
From: Cristiano Midnight
Just out of curiousity, how do they have the account email addresses to email people anyway?


They don't. They use the SL client software to request a password change on your account. To do that all they need to know is your user name. That causes LL to send the email I quoted. It gets sent to you, not to them. If you click the link I assume the person who initiated the password change request then has a chance to beat you to changing your password. They'd have to keep trying in the hopes that you foolishly clicked the link. It's a total crap shoot and I'm not even sure it would work for them. I've never changed my password so I don't know what happens next after you click the link in the email. It's just rather annoying and unpleasant knowing there's someone trying to gain access to my account.
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Siggy Romulus
DILLIGAF
Join date: 22 Sep 2003
Posts: 5,711
07-01-2005 10:55
OMFG Th3Y H4xX0r3D D4 G1b50N!

Siggy.

(You have no idea how long it took to type that...)
_____________________
The Second Life forums are living proof as to why it's illegal for people to have sex with farm animals.

From: Jesse Linden
I, for one, am highly un-helped by this thread
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 10:57
From: Siggy Romulus
OMFG Th3Y H4xX0r3D D4 G1b50N!

Siggy.

(You have no idea how long it took to type that...)


Bored at work again Siggy? :D
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Aimee Weber
The one on the right
Join date: 30 Jan 2004
Posts: 4,286
07-01-2005 10:58
From: Chip Midnight
They don't. They use the SL client software to request a password change on your account. To do that all they need to know is your user name. That causes LL to send the email I quoted. It gets sent to you, not to them. If you click the link I assume the person who initiated the password change request then has a chance to beat you to changing your password. They'd have to keep trying in the hopes that you foolishly clicked the link. It's a total crap shoot and I'm not even sure it would work for them. I've never changed my password so I don't know what happens next after you click the link in the email. It's just rather annoying and unpleasant knowing there's someone trying to gain access to my account.


Oh wait. I think I know how this works. They tell you to click on a link, and they have a code at the end of that URL you need to click (that only YOU have, not your hacker). I suspect what happens is, if you click on that link it will take you to a web page that asks you for a new password but ONLY if that code is in the URL you clicked. So basically the only person that can change your password is whoever sees that special link sent only to you.

Does this make sense or have I been hitting the wine early this weekend?
_____________________
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 11:01
From: Aimee Weber
Oh wait. I think I know how this works. They tell you to click on a link, and they have a code at the end of that URL you need to click (that only YOU have, not your hacker). I suspect what happens is, if you click on that link it will take you to a web page that asks you for a new password but ONLY if that code is in the URL you clicked. So basically the only person that can change your password is whoever sees that special link sent only to you.

Does this make sense or have I been hitting the wine early this weekend?


Yep, that makes sense. The code in the email verifies that the account owner is the one who requested the password change. What happens after that I don't know. Maybe a Linden can chime in with how it actually works and if getting one of these emails and clicking the link could actually give someone else the ability to change your password or not.
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Roberta Dalek
Probably trouble
Join date: 21 Oct 2004
Posts: 1,174
07-01-2005 11:03
You get asked for your security question answer. There's no way they'd guess that.

I'm confused. If you forget your password they email you a link. You click on the link and it asks you your security question. If like me you have no idea what you put in you end up having to decrypt your browser's password cache to get your password back.

If this is phishing then wouldn't it go to a fake SL page?
_____________________
See my stuff on SL Boutique!
Aimee Weber
The one on the right
Join date: 30 Jan 2004
Posts: 4,286
07-01-2005 11:04
From: Chip Midnight
Yep, that makes sense. The code in the email verifies that the account owner is the one who requested the password change. What happens after that I don't know. Maybe a Linden can chime in with how it actually works and if getting one of these emails and clicking the link could actually give someone else the ability to change your password or not.


I'm thinking it asks YOU (the one with the code) to change the password. If your hacker tries to log in before you change it, they have to guess your old password. If they try to log in after you change it, they have to guess your new password. And if they try to go to that web page without that code, the page will tell them to take a hike.

Linden chime would be good here but I am guessing this is all secure.
_____________________
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 11:06
It doesn't appear to be phishing. According to the headers the email originated from web1.lindenlab.com
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 11:08
From: Aimee Weber
Linden chime would be good here but I am guessing this is all secure.


That's my guess too, but since is the second time in as many weeks I wouldn't mind some clarification Just to be sure. It makes me want to change my password, but now I'm nervous to do it because I won't know if the email I get is from my request or someone else's. :p

Good to know about the security question. I wonder what the hell I put? hehe
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
Eggy Lippmann
Wiktator
Join date: 1 May 2003
Posts: 7,939
07-01-2005 11:14
Whoops, sorry Chip, I was trying to change MY password but accidentally misspelled "Eggy Lippmann" :D
Aimee Weber
The one on the right
Join date: 30 Jan 2004
Posts: 4,286
07-01-2005 11:46
From: Eggy Lippmann
Whoops, sorry Chip, I was trying to change MY password but accidentally misspelled "Eggy Lippmann" :D
Happens all the time. I was writing an e-mail to chip earlier today, and I accidentally misspelled

From: someone
Hey chip, how's it going?
as

From: someone
The Second Life user named Eggy Lippmann has a bomb and I believe he also has three hostages who are foreign nationals. He has boasted on numerous occasions that he fully intends use this bomb on U.S. soil against a random egg packing plant. He believes this symbolic gesture will bring the public eye upon the mistreatment of eggs and other dairy products and launch his organization, the Egg Liberation Front (ELF) into a position where it will have leverage on international affairs. I believe he intends to strike on July 4th.


And you know me...butterfingers Aimee. I misspelled Chip's e-mail address as [email]tips@fbi.gov[/email].

:D
_____________________
Katja Marlowe
Registered User
Join date: 15 Apr 2005
Posts: 421
07-01-2005 11:51
You know, I haven't checked my email in awhile, but I have noticed some weird things going on with my password. Wonder if there's actually some sort of bug? I had it clicked to save password, but for awhile it wouldn't. Then it started to. Then yesterday it had one in there but it was like 6 letters longer than mine...*wonders if she should check her email tonight*
*realizes it has over a 1000 msgs and pushes off the task to another day*
Chip Midnight
ate my baby!
Join date: 1 May 2003
Posts: 10,231
07-01-2005 11:59
From: Aimee Weber
He has boasted on numerous occasions that he fully intends use this bomb on U.S. soil against a random egg packing plant.


That reminds me... I think I'll have a fried egg sandwich for lunch today :)
_____________________

My other hobby:
www.live365.com/stations/chip_midnight
1 2