Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Password uncovered

Edwardo Jardberg
Registered User
Join date: 8 Feb 2009
Posts: 48
06-12-2009 04:22
I'm running a Mac with Leopard. THis morning I turned on the computer and found a file on my desktop from someone seeming to solicit email from me, and citing 3 URLs which I have not looked at yet. The name of the file is my SL password with file extension 'rtf'. I suppose the password can be gotten at for this purpose, but it scares me to see it there without any action on my part.

Should I call this to Linden Lab's attention, and if so, how? Or is it nothing to be concerned about?

Abd how do I go about changing my password?

Thank you all, folks.
Phoenixa Sol
Dance Addict
Join date: 31 Aug 2006
Posts: 315
06-12-2009 04:34
DONT go to any URL listed in there!! You shouldn't have done whatever you did to receive this, which could have been either opening a bad email, (from a sender you dont know, or potentially one you do know that had some kind of malicious attachment in it) or going to a compromised site. At this point I recommend solving your problem before taking time to alert LL.

Sorry to sound alarmist here, but it sounds like you have a keylogger you need to get RID of before you change passwords yourself, or even type in a password that LL would give you. Because if this is the case, that would grab the new one anyway. You might even have a PWS trojan too or some other malicious critter.

I highly recommend you run through this majorgeeks malware removal procedure and get rid of any creatures, and then change your password.

http://forums.majorgeeks.com/showthread.php?t=35407

Those folks are experts there, and if you have a critter in your machine that procedure doesn't zap, they can help you with removal.

Once you are sure there are no keyloggers or trojans on your machine, then you change passwords here once you've logged into the secondlife website:

https://secure-web17.secondlife.com/account/password.php?lang=en

That change password link is found when you open the website at www.secondlife.com, log in, click on "my account" and then on the left side NAV bar you will see a hyperlink to CHANGE PASSWORD.

Oh and do your friends and family a favor, dont send them any email attachments until your machine is clear of any infection. If you sent any at all recently, at least warn them when you find out whatever stung your machine.
_____________________
Dance, dance, dance, dance and film it!
"How I dance in secondlife" dance tutorial video, SLurls, handy links and text explanations:
http://wiki.secondlife.com/wiki/User:Phoenixa_Sol

Take your dance to new heights!



Free FlyDance animation just for stopping by. Buy from box vendor for $0L!

http://tinyurl.com/5paevr
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
06-12-2009 05:13
Seems possible that someone found you logged in and your screen unlocked.
_____________________
Argent Stonecutter - http://globalcausalityviolation.blogspot.com/

"And now I'm going to show you something really cool."

Skyhook Station - http://xrl.us/skyhook23
Coonspiracy Store - http://xrl.us/coonstore
Tod69 Talamasca
The Human Tripod ;)
Join date: 20 Sep 2005
Posts: 4,107
06-12-2009 05:45
Just to add to the advice:

When removing spyware/malware/viruses....... Literally DISCONNECT the internet from your computer.

Unplug the network cable or router.

Many of these annoying lil' programs like to bury some tiny bit of themselves deep in the registry, so when you find & try to remove their "main" part, it re-downloads itself.

Sneaky lil' monkeys. ;)
_____________________
really pissy & mean right now and NOT happy with Life.
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
06-12-2009 05:59
Why are you people pointing him to Windows sites and talking about the Registry? He's running Mac OS X 10.5 ("Leopard";).
_____________________
Argent Stonecutter - http://globalcausalityviolation.blogspot.com/

"And now I'm going to show you something really cool."

Skyhook Station - http://xrl.us/skyhook23
Coonspiracy Store - http://xrl.us/coonstore
Pserendipity Daniels
Assume sarcasm as default
Join date: 21 Dec 2006
Posts: 8,839
06-12-2009 06:02
/me thought the PR material said that no-one wrote malware for Macs . . .

Pep (. . . why bother for that tiny minority - the OP has probably jumped to conclusions.)
_____________________
Hypocrite lecteur, — mon semblable, — mon frère!
Phoenixa Sol
Dance Addict
Join date: 31 Aug 2006
Posts: 315
06-12-2009 06:06
From: Argent Stonecutter
Why are you people pointing him to Windows sites and talking about the Registry? He's running Mac OS X 10.5 ("Leopard";).


Those folks can help him too then:

http://forums.majorgeeks.com/forumdisplay.php?f=40
_____________________
Dance, dance, dance, dance and film it!
"How I dance in secondlife" dance tutorial video, SLurls, handy links and text explanations:
http://wiki.secondlife.com/wiki/User:Phoenixa_Sol

Take your dance to new heights!



Free FlyDance animation just for stopping by. Buy from box vendor for $0L!

http://tinyurl.com/5paevr
Brenda Connolly
Un United Avatar
Join date: 10 Jan 2007
Posts: 25,000
06-12-2009 06:08
From: Tod69 Talamasca
Just to add to the advice:

When removing spyware/malware/viruses....... Literally DISCONNECT the internet from your computer.

Unplug the network cable or router.

Many of these annoying lil' programs like to bury some tiny bit of themselves deep in the registry, so when you find & try to remove their "main" part, it re-downloads itself.

Sneaky lil' monkeys. ;)


Nice tip, thanks.
_____________________
Don't you ever try to look behind my eyes. You don't want to know what they have seen.

http://brenda-connolly.blogspot.com
Milla Janick
Empress Of The Universe
Join date: 2 Jan 2008
Posts: 3,075
06-12-2009 06:08
The fact the file is on your desktop is somewhat disturbing, as well. If you didn't put it there accidentally somehow.

Do you use the same password for anything else? Is there a chance you've copy/pasted it inadvertently?
_____________________


http://www.avatarsunited.com/avatars/milla-janick
All those moments will be lost in time... like tears in rain...
Brenda Connolly
Un United Avatar
Join date: 10 Jan 2007
Posts: 25,000
06-12-2009 06:08
From: Pserendipity Daniels
/me thought the PR material said that no-one wrote malware for Macs . . .

Pep (. . . why bother for that tiny minority - the OP has probably jumped to conclusions.)


The Leopard has paws of clay?
_____________________
Don't you ever try to look behind my eyes. You don't want to know what they have seen.

http://brenda-connolly.blogspot.com
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
06-12-2009 06:29
Nobody with any credibility has said "nobody has written malware for macs".

Thing is, there's no reason to assume that there's any malware involved here. First, this is a really unlikely thing for a virus or trojan to do. Second, there are security problems, like leaving yourself logged in and your screen unlocked, that no operating system can protect against. The least secure component in any computer system is the one between the chair and the keyboard.

I've gone in to "remove viruses" on Windows boxes, and found that all that had happened was that the user had walked away and someone had walked up and moved icons around on the desktop. There's a classic prank that people do, where they take a screenshot of the desktop and make it the desktop wallpaper, then hide all the desktop icons in a folder they move offscreen...

I've had user's passwords revealed by someone opening Notepad and clicking "paste".

I've had someone tell me they downloaded a virus because they updated Flash player and it said it was version 10 and they "knew" the current version was 9.
_____________________
Argent Stonecutter - http://globalcausalityviolation.blogspot.com/

"And now I'm going to show you something really cool."

Skyhook Station - http://xrl.us/skyhook23
Coonspiracy Store - http://xrl.us/coonstore
Bobby Baudin
Registered User
Join date: 20 Jan 2009
Posts: 8
06-12-2009 08:11
To be honest, the only sure-fire way to clear out malware, viruses etc is a complete format / reinstall from the ground up.
Pserendipity Daniels
Assume sarcasm as default
Join date: 21 Dec 2006
Posts: 8,839
06-12-2009 08:15
From: Argent Stonecutter
Nobody with any credibility has said "nobody has written malware for macs".

That doesn't conflict with what I said. ;)

Pep (How can you tell when a PR person is lying? Her lips move.)
_____________________
Hypocrite lecteur, — mon semblable, — mon frère!
Ceka Cianci
SuperPremiumExcaliburAcc#
Join date: 31 Jul 2006
Posts: 4,489
06-12-2009 08:18
From: Argent Stonecutter
Nobody with any credibility has said "nobody has written malware for macs".

Thing is, there's no reason to assume that there's any malware involved here. First, this is a really unlikely thing for a virus or trojan to do. Second, there are security problems, like leaving yourself logged in and your screen unlocked, that no operating system can protect against. The least secure component in any computer system is the one between the chair and the keyboard.

I've gone in to "remove viruses" on Windows boxes, and found that all that had happened was that the user had walked away and someone had walked up and moved icons around on the desktop. There's a classic prank that people do, where they take a screenshot of the desktop and make it the desktop wallpaper, then hide all the desktop icons in a folder they move offscreen...

I've had user's passwords revealed by someone opening Notepad and clicking "paste".

I've had someone tell me they downloaded a virus because they updated Flash player and it said it was version 10 and they "knew" the current version was 9.

that was the first thought that came to mind is .who else is in the house lol


i used to do that screen shot thing to keep my nephews off my computer..it's amazing how well it really does work with everyone lol
_____________________
Starfire Desade
Can I play with YOUR mind
Join date: 10 Jul 2006
Posts: 404
06-12-2009 10:16
From: Argent Stonecutter
Nobody with any credibility has said "nobody has written malware for macs".


Good... then I know not to trust the mac guy on those commercials.
_____________________
"Hypnotic Magic" - Second Life's Hypnosis Specialists - Home of the TranceStar (Hypno, BDSM, Mind Control) Free your mind from the ordinary!

http://slurl.com/secondlife/Stellar%20Dreams/122/67/26/
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
06-12-2009 10:26
From: Starfire Desade
Good... then I know not to trust the mac guy on those commercials.
Of course not. He's a frigging actor. Sheesh.

On the other hand, you can trust the "Linux" guy:

_____________________
Argent Stonecutter - http://globalcausalityviolation.blogspot.com/

"And now I'm going to show you something really cool."

Skyhook Station - http://xrl.us/skyhook23
Coonspiracy Store - http://xrl.us/coonstore
Darien Caldwell
Registered User
Join date: 12 Oct 2006
Posts: 3,127
06-12-2009 12:18
From: Argent Stonecutter
Of course not. He's a frigging actor. Sheesh.

On the other hand, you can trust the "Linux" guy:



if Linux guy was holding a ferret, I would be very worried.
_____________________
Amaranthim Talon
Voyager, Seeker, Curious
Join date: 14 Nov 2006
Posts: 12,032
06-12-2009 12:30
From: Edwardo Jardberg
I'm running a Mac with Leopard. THis morning I turned on the computer and found a file on my desktop from someone seeming to solicit email from me, and citing 3 URLs which I have not looked at yet. The name of the file is my SL password with file extension 'rtf'. I suppose the password can be gotten at for this purpose, but it scares me to see it there without any action on my part.

Should I call this to Linden Lab's attention, and if so, how? Or is it nothing to be concerned about?

Abd how do I go about changing my password?

Thank you all, folks.

OK- now i am the one freaking out- i just logged into sl and found a very polite im from THE OP :

THAT I HAVE NOW EDITED OUT IN CASE THE OP DOESN'T KNOW HE IS THE OP- WOULDNT WANT TO OFFEND HIM :rolleyes:


I just went thru my trasactions from may 13 to today and find no record of having given this guy anything- now i do send things to people when they request stuff either here or in-world and sometimes dont even comment- just send it cause they needed it - but i dont remember him really and if i didnt do this- i might have need to check at home but wdnt it be on my transactionrecords? If i didnt then what the heck is this about?

I am calling LL right now about this in fact-
_____________________
"Yield to temptation. It may not pass your way again. "
Robert A. Heinlein




http://talonfaire.blogspot.com/

Visit Talon Faire Main:
http://slurl.com/secondlife/Misto%20Presto/216/21/155- Main Store

XStreets: http://tinyurl.com/6r7ayn
xtina Borkotron
Registered User
Join date: 12 Oct 2008
Posts: 8
06-12-2009 12:37
talk about naming names and posting chat logs!!!
Amaranthim Talon
Voyager, Seeker, Curious
Join date: 14 Nov 2006
Posts: 12,032
06-12-2009 12:47
Well hell i can edit it but he is the one who opened the thing- its not like he is pretending not to be
_____________________
"Yield to temptation. It may not pass your way again. "
Robert A. Heinlein




http://talonfaire.blogspot.com/

Visit Talon Faire Main:
http://slurl.com/secondlife/Misto%20Presto/216/21/155- Main Store

XStreets: http://tinyurl.com/6r7ayn
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
06-12-2009 12:53
I think this is what we call, in the system admin business, a "PEBCAK" situation.
_____________________
Argent Stonecutter - http://globalcausalityviolation.blogspot.com/

"And now I'm going to show you something really cool."

Skyhook Station - http://xrl.us/skyhook23
Coonspiracy Store - http://xrl.us/coonstore
xtina Borkotron
Registered User
Join date: 12 Oct 2008
Posts: 8
oi
06-12-2009 12:54
oh i have no horse in this race.
but people sometimes get mad when their IM's are posted hey. and its against the tao and the vaunted ToS
Argent Stonecutter
Emergency Mustelid
Join date: 20 Sep 2005
Posts: 20,263
06-12-2009 12:56
From: Darien Caldwell
if Linux guy was holding a ferret, I would be very worried.
No ferret, but he recently bought a Tronguy-themed airplane:

_____________________
Argent Stonecutter - http://globalcausalityviolation.blogspot.com/

"And now I'm going to show you something really cool."

Skyhook Station - http://xrl.us/skyhook23
Coonspiracy Store - http://xrl.us/coonstore
Eli Schlegal
Registered User
Join date: 20 Nov 2007
Posts: 2,387
06-12-2009 12:57
From: Argent Stonecutter
No ferret, but he recently bought a Tronguy-themed airplane:



I don't understand why you need a plane Argent. Your flight feather doesn't work in RL?
:p
Amaranthim Talon
Voyager, Seeker, Curious
Join date: 14 Nov 2006
Posts: 12,032
06-12-2009 13:03
So- i got off live chat with LL - they recommended i file an abuse report with Governor Linden as the culprit and give them all this info so they can start looking into it- I contacted the OP in world to let him know i had no idea what was going on and i imagine i wil hear back from him plus now he can read here that LL is looking into it.
_____________________
"Yield to temptation. It may not pass your way again. "
Robert A. Heinlein




http://talonfaire.blogspot.com/

Visit Talon Faire Main:
http://slurl.com/secondlife/Misto%20Presto/216/21/155- Main Store

XStreets: http://tinyurl.com/6r7ayn
1 2 3