Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

My Account Was Hacked And I've Been Suffering For It.

Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 08:54
Hello....my first Second Life account was hacked a few weeks ago. My Paypal account was abused so I had to have them put Limited Access on it. My avie was completely shut down and I've just spent weeks and weeks getting things back together and getting all my friends back.
I received no email to tell me what's happening....just Linden Labs suggesting I 'phone them...which means a transatlantic call as I'm in the UK.

Now I've had my replacement account disabled...just because my Paypal is limited access.
I finally 'phoned them and they say I should have 'phoned them straightaway about this.
I've found out from Paypal how to remove Limited Access and supposedly I will get my disabled account enabled.

I'm just fed up with the way LL refuse to communicate via email....a quick one just telling me what's going on and what I can do regarding Paypal would only take a minute or two to send.
I can't understand why my new account gets disabled when I wasn't using Paypal in that account.

You can do much better than this, Linden Labs!
Briana Dawson
Attach to Mouth
Join date: 23 Sep 2003
Posts: 5,855
07-17-2008 09:05
How does an account get hacked?????

I mean really? I hear this stuff all the time: "my account was hacked" How??

My password is 9 alpha-numeric digits that don't even form a word.


Who else did you give your password to?
_____________________
WooT
------------------------------

http://www.secondcitizen.net/Forum/
Chris Norse
Loud Arrogant Redneck
Join date: 1 Oct 2006
Posts: 5,735
07-17-2008 09:08
Did you use a cybercafe or piggy back on a wireless signal?
_____________________
I'm going to pick a fight
William Wallace, Braveheart

“Rules are mostly made to be broken and are too often for the lazy to hide behind”
Douglas MacArthur

FULL
Damien1 Thorne
Registered User
Join date: 26 Aug 2007
Posts: 4,877
07-17-2008 09:08
From: Chris Norse
Did you use a cybercafe or piggy back on a wireless signal?

:D
_____________________
As we fade into the darkness...
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 09:10
I didn't give my password to anybody....I used a strong password with numbers and letters. Mine didn't form a normal word or phrase, either. Hmmmph.
I was CAREFUL. There are some clever swines out there.

If they want to they can hack into all kinds of online things. Thanks for your sympathy...not.
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 09:12
From: Chris Norse
Did you use a cybercafe or piggy back on a wireless signal?


No....I only ever accessed SL from my own home.
Chris Norse
Loud Arrogant Redneck
Join date: 1 Oct 2006
Posts: 5,735
07-17-2008 09:13
From: Bryony Constantine
No....I only ever accessed SL from my own home.

You still didn't answer the second question. Were you using a wireless signal to connect to SL?
_____________________
I'm going to pick a fight
William Wallace, Braveheart

“Rules are mostly made to be broken and are too often for the lazy to hide behind”
Douglas MacArthur

FULL
Skell Dagger
Smitten
Join date: 26 Jun 2007
Posts: 1,885
07-17-2008 09:15
Not sure that it's appropriate to post the direct link here because of the nature of some of the specific blog post's content, but onemansblog.com featured a post back in March 2007 (you can go and look for it, if you want to) about how easy it is to hack passwords. The post actually features a LOT of useful info on how to take preventative steps, but it also features links that are probably not the sort of thing that should be accessible from this forum. So yeah, you can hunt for it if you like ;)

Anyway, one of the best bits of advice he gave was this:

From: onemansblog.com
Another thing to keep in mind is that some of the passwords you think matter least actually matter most. For example, some people think that the password to their e-mail box isn’t important because “I don’t get anything sensitive there.” Well, that e-mail box is probably connected to your online banking account. If I can compromise it then I can log into the Bank’s Web site and tell it I’ve forgotten my password to have it e-mailed to me. Now, what were you saying about it not being important?
_____________________
It always ends in chickens...

Store blog - http://primflints.wordpress.com/
Inworld - http://slurl.com/secondlife/Jindalrae/21/25/442
XStreet - http://tinyurl.com/primflints
Photos - http://www.flickr.com/photos/skelldagger/
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 09:16
No...I was using broadband down a landline.
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 09:20
From: Skell Dagger
Not sure that it's appropriate to post the direct link here because of the nature of some of the specific blog post's content, but onemansblog.com featured a post back in March 2007 (you can go and look for it, if you want to) about how easy it is to hack passwords. The post actually features a LOT of useful info on how to take preventative steps, but it also features links that are probably not the sort of thing that should be accessible from this forum. So yeah, you can hunt for it if you like ;)

Anyway, one of the best bits of advice he gave was this:


Hi SKell....I was using a strong password...after the hack I got extra tips on this from my geek friend.
Hackers have hacked in the UK's Scotland Yard website and defaced it. That was a minor one.
If they're clever enough they can hack anything. I changed my passwords again and again like someone deranged after it happened.
Dante Tucker
Purple
Join date: 8 Aug 2006
Posts: 806
07-17-2008 09:25
From: Bryony Constantine
I changed my passwords again and again like someone deranged after it happened.


Thats good, and thats what everyone is supposed to do. Realy who is going to bother to change all there passwords every week, but everyone should at least change them every month or so.
Chris Norse
Loud Arrogant Redneck
Join date: 1 Oct 2006
Posts: 5,735
07-17-2008 09:25
Have you checked for keystroke loggers? Which viewer are you using?
_____________________
I'm going to pick a fight
William Wallace, Braveheart

“Rules are mostly made to be broken and are too often for the lazy to hide behind”
Douglas MacArthur

FULL
Meade Paravane
Hedgehog
Join date: 21 Nov 2006
Posts: 4,845
07-17-2008 09:27
Catching wireless signals usually requires the evil-doer to be more-or-less near the person getting hacked and them requires them to decrypt the packets.

Since I think hackers are more interested in volume, I think it's more likely she got keylogged or used some evil bot/viewer that simply sent her password off to the bad folks when she tried to log in.
_____________________
Tired of shouting clubs and lucky chairs? Vote for llParcelSay!!!
- Go here: http://jira.secondlife.com/browse/SVC-1224
- If you see "if you were logged in.." on the left, click it and log in
- Click the "Vote for it" link on the left
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 09:48
From: Meade Paravane
Catching wireless signals usually requires the evil-doer to be more-or-less near the person getting hacked and them requires them to decrypt the packets.

Since I think hackers are more interested in volume, I think it's more likely he got keylogged or used some evil bot/viewer that simply sent his password off to the bad folks when he tried to log in.



I'm a lady. Bryony is a well known female name in the UK. :) I'd prefer to be addressed in the first person...not referred to in the third person.
Oryx Tempel
Registered User
Join date: 8 Nov 2006
Posts: 7,663
07-17-2008 09:53
Well hopefully all's well that ends well. Still, you're right. LL needs a better way of communicating.

[And welcome to the forums!]
_____________________
Meade Paravane
Hedgehog
Join date: 21 Nov 2006
Posts: 4,845
07-17-2008 09:53
From: Bryony Constantine
I'm a lady. Bryony is a well known female name in the UK. :) I'd prefer to be addressed in the first person...not referred to in the third person.

Oops! Sorry, ma'am..

edit: and, since my reply was more to the other people asking questions about wireless and such, I think 3rd-person was appropriate. :P
_____________________
Tired of shouting clubs and lucky chairs? Vote for llParcelSay!!!
- Go here: http://jira.secondlife.com/browse/SVC-1224
- If you see "if you were logged in.." on the left, click it and log in
- Click the "Vote for it" link on the left
Skell Dagger
Smitten
Join date: 26 Jun 2007
Posts: 1,885
07-17-2008 09:53
From: Bryony Constantine
I'm a lady. Bryony is a well known female name in the UK. :) I'd prefer to be addressed in the first person...not referred to in the third person.
I think Meade was directly addressing those in this post that were asking you if you used a wireless connection, and suggesting that the hacker probably didn't use that method.

/me steps away from this thread now.
_____________________
It always ends in chickens...

Store blog - http://primflints.wordpress.com/
Inworld - http://slurl.com/secondlife/Jindalrae/21/25/442
XStreet - http://tinyurl.com/primflints
Photos - http://www.flickr.com/photos/skelldagger/
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 09:58
From: Meade Paravane
Oops! Sorry, ma'am..

edit: and, since my reply was more to the other people asking questions about wireless and such, I think 3rd-person was appropriate. :P



No offence taken! Just wanted to be included in the conversation. :)
Jeffrey Gomez
Cubed™
Join date: 11 Jun 2004
Posts: 3,522
07-17-2008 10:06
From: Chris Norse
Did you use a cybercafe or piggy back on a wireless signal?

Just using Windows and IE is a more likely security risk.

Or for that matter, Windows without NAT:
http://it.slashdot.org/it/08/07/15/0123245.shtml
_____________________
---
Psyra Extraordinaire
Corra Nacunda Chieftain
Join date: 24 Jul 2004
Posts: 1,533
07-17-2008 10:27
Simply due to the fact that it's as potentially possible that someone's entire computer, not just account, could be compromised (people that use the same password for everything, basically) means I'd rather have to phone them than email them. It could also form the basis of why they'd rather you phone them than play email tag with them.

Emails mean you have to wait for each reply, it's very inefficient. Phone calls are handled live. Simple 'nuff.
_____________________
E-Mail Psyra at psyralbakor_at_yahoo_dot_com, Visit my Webpage at www.psyra.ca :)

Visit me in-world at the Avaria sims, in Grendel's Children! ^^
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 10:32
From: Jeffrey Gomez
Just using Windows and IE is a more likely security risk.

Or for that matter, Windows without NAT:
http://it.slashdot.org/it/08/07/15/0123245.shtml



We've used Mozilla Firefox on this computer, simply because the new Windows keeps playing
up. Then I saw chat in NCI about how poor Windows is and that put me off it even more.
Salvador Nakamura
http://www.sl-index.com
Join date: 16 Jan 2007
Posts: 557
07-17-2008 10:49
still a good password, Regular Updated Anti Virus + Firewall, and not storing login information for automated logins is pretty good protection against the average attack

*from the good hackers out there, maybe only a few would target an unknown ip


*it also would be "nice" if SL used captcha for logins, specially since the login name is already known, its almost neglection not to have it these days ?


.
_____________________
SL-Index , providing an easy and affordable start in secondlife
Rentals, Easy Setup Scripts, Freebies & Value Boxes

www: http://sl-index.com

HQ: http://slurl.com/secondlife/Immintel/212/14/100
Bryony Constantine
Registered User
Join date: 16 Jul 2008
Posts: 32
07-17-2008 12:23
From: Salvador Nakamura
still a good password, Regular Updated Anti Virus + Firewall, and not storing login information for automated logins is pretty good protection against the average attack

*from the good hackers out there, maybe only a few would target an unknown ip


*it also would be "nice" if SL used captcha for logins, specially since the login name is already known, its almost neglection not to have it these days ?


.



Those captcha things can be problematic....I knew a site where, because the captcha wasn't working properly, you couldn't access part of it.
Meade Paravane
Hedgehog
Join date: 21 Nov 2006
Posts: 4,845
07-17-2008 12:28
From: Salvador Nakamura
*it also would be "nice" if SL used captcha for logins, specially since the login name is already known, its almost neglection not to have it these days ?

How would captcha help? I thought that was mostly a test to prove that you're not a bot.
_____________________
Tired of shouting clubs and lucky chairs? Vote for llParcelSay!!!
- Go here: http://jira.secondlife.com/browse/SVC-1224
- If you see "if you were logged in.." on the left, click it and log in
- Click the "Vote for it" link on the left
Ghosty Kips
Elora's Llama
Join date: 2 May 2008
Posts: 2,386
07-17-2008 12:30
From: Meade Paravane
How would captcha help? I thought that was mostly a test to prove that you're not a bot.


That is *exactly* how it would help. Not all bots play SL.
_____________________
--
Why aren't you doing something more useful, like playing WoW?
1 2