Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Repost: possible hacking?

Yiffy Yaffle
Purple SpiritWolf Mystic
Join date: 22 Oct 2004
Posts: 2,802
09-19-2006 05:27
To quote myself from the linden answeres thread i made

I think after the grid attack tonight someone has attempted to hack my account. Please view the JPG file by clicking here (it is quite large to post onto a forum). Someone or some object in-world spammed my gmail account with about 120 emails containing nothing but giberish. The UUID key of whoever or whatever did this is listed in the header of each email. I emailed support about this already.

As a follow up thismorning, when i logged in i found these were inventory objects passed to me by one of the attackers. IM me for persons name

The self replicator kept renaming it's self to bypass the goo fence and kept giving copies of its self to people.
_____________________
Bosozoku Kato
insurrectionist midget
Join date: 16 Jun 2003
Posts: 452
09-19-2006 05:33
First, you don't have to paste this into other threads :p

Second, how is email bombing you a hack attempt?

Anyway, they'd have to get your email, which ought to be quite difficult in SL. There's no scripted function to llGetEmailAddressOfAvatar(key id). Only way to get someone's email is if they tell you what it is.

Now, the object might be IM'n you, and if you have IM->to->Email set in your preferences (ctrl+p) you'd get emails from an IM spamming object. That'd be my hunch.

You haven't been hacked, you've been spammed. Still worthy of reporting to lindens, imho.

Edit
Oh wait, object IM's don't go to email (far as I know). Have you shared your email with strangers? Didn't daddy warn you about that?

--Bos
_____________________
float llGetAFreakingRealTimeStampSince00:00:00Jan11970();
Usagi Musashi
UM ™®
Join date: 24 Oct 2004
Posts: 6,083
09-19-2006 05:53
many people got those unknown objects..........
Angel Fluffy
Very Helpful
Join date: 3 Mar 2006
Posts: 810
09-19-2006 06:00
I thought object IMs *did* go to your email? At least, I think they did before...

With regards to the email flood, I'd suggest a few things :
1) go to sneakemail.com and get disposable email addresses there. They will greatly help you if you get spammed, because you can just terminate the email address you are being spammed on, or filter it before it gets to your inbox at all.
2) use gmail filters to identify and delete conversations that look like spam. I also have gmail filters auto-delete incoming notifications that people have left groups I own (to avoid getting spammed that way, as SL doesn't, annoyingly, have an option to turn those notices off for owners).
3) If you get a ton of messages you don't want, consider doing what I do : turning "send to email" off, (thus ensuring that nothing hits your email address automatically), and putting in your profile "to contact me, email : ________". That means that anyone who knows you or looks at your profile will be able to contact you, but random spambots won't.

I'm not sure if any of these will help in your case, but I hope they do :)

In any case, report this to LL, something fishy is definately going on here... unless of course it's a known issue caused by spammy grid-attacking objects as was suggested above, in which case I'd save the logs and wait for an announcement.
_____________________
Volunteer Portal (FAQs!) : https://wiki.secondlife.com/wiki/Volunteer_Portal

JIRA / Issue Tracker : http://jira.secondlife.com (& http://tinyurl.com/2jropp)
Zi Ree
Mrrrew!
Join date: 25 Feb 2006
Posts: 723
09-19-2006 06:00
The spammer objects are trying to deliver inventory to you. It might be that the presence bug caused you to appear offline to the object while it tires to send yu copies of itself. Those inventory offers get relayed to email when you are not online, or presence shows you as offline. I have been near one of those objects myself and got plastered with inventory offers very quickly, so that would be the cause for the huge number of mails you got.
_____________________
Zi!

(SuSE Linux 10.2, Kernel 2.6.13-15, AMD64 3200+, 2GB RAM, NVidia GeForce 7800GS 512MB (AGP), KDE 3.5.5, Second Life 1.13.1 (6) alpha soon beta thingie)

Blog: http://ziree.wordpress.com/ - QAvimator: http://qavimator.org

Second Life Linux Users Group IRC Channel: irc.freenode.org #secondlifelug
Yiffy Yaffle
Purple SpiritWolf Mystic
Join date: 22 Oct 2004
Posts: 2,802
09-20-2006 05:55
From: Zi Ree
The spammer objects are trying to deliver inventory to you. It might be that the presence bug caused you to appear offline to the object while it tires to send yu copies of itself.

Yea thats what i belive happened. Anyway i'm glad that GMail stacks all emails from the same person as 1 big email, or it would have been one heck of a page load. SL support email hasn't replied to me so it's obvous to me i can't count on them to answer anything...

It's probably better to buy a plane ticket to their business location and walk in. :/ I know now that it wasn't a hack attempt but it still was rather a anoyance that griefers shouldn't be able to do. Many LSL functions should be limited to parcel owners... I meen just giving these abilities to anyone is dangerous/anoying.
_____________________
Brent Linden
eXtreme Bug Hunter
Join date: 16 Feb 2005
Posts: 212
09-20-2006 10:16
We're really sorry you were affected by the grey goo attack in this way and want to articulate what we've done in the past and what we're doing now to reduce the threat of these sorts of attacks.

We tried limiting llGiveInventory to parcel owners back in October 05 as an emergency band-aid to stop multiple grey goo attack scenarios before we had the grey goo fence and other bad content-zapping systems in place. We were criticized for the irrational reaction and begged to reverse it. The emergency band-aid was meant to only be that: a band-aid that we'd rip off the wound once we had a dermal regenerator (grey goo fence, other content-zapping systems) in place.

Limiting LSL functions usually results in broken content created by you, our Residents, which is something we do not want to do. There are projects in the works to make the fence more reactive and intelligent about what it decides is grey goo, among other things.
_____________________
The best way to predict the future is to invent it. -Alan Kay
Yiffy Yaffle
Purple SpiritWolf Mystic
Join date: 22 Oct 2004
Posts: 2,802
09-21-2006 04:10
From: Brent Linden

We tried limiting llGiveInventory to parcel owners back in October 05 as an emergency band-aid to stop multiple grey goo attack scenarios before we had the grey goo fence and other bad content-zapping systems in place.

Limiting LSL functions usually results in broken content created by you, our Residents, which is something we do not want to do.

Yea i remember that. No matter how the situation is aproached, all residents would all be effected. I have this freebie dispencer that gives out a chain effect of folders to your inventry by using linkmessage to contact the other prims that store items. It currently needs to be rewritten because it's being stalled by the goo fence. I am glad the goo fence is in place however, So i'm not bothering to complain about it.

It isn't hard to rewrite the scripts. However if it was something i was selling, i would have to check my payment history and see how many people i sold it to and give them new ones. As of recently the goo fence has been bypassed by griefers. The way i see it, no matter how strong your barricade, someone will find a way to get through. THose kinda people have no life though IMO.
_____________________