• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Cataclysm beta...

Worked fine for me. Log into your battle.net account like normal and it will show up under your Manage Games tab.
 
Worked fine for me. Log into your battle.net account like normal and it will show up under your Manage Games tab.
Yeah worked fine now as well thanks, my interwebs was acting up I guess.
 
lol becareful their are a lot of Spam emails going around for fake beta invites
 
dont click any beta links sent to you in email. the official blizz ones dont have links anymore, they jsut notify you to login to battlenet, and then set things up from there.
even if the msg is showing a sender of "(something)@blizzard.com",
inspect the msg source & you'll see that they are 99.99999999999999999999999999% from redirected hotmail accounts from scammers trying to steal your account.
it was the same process for the starcraft 2 beta.

if you did click on one, you might be albe to change your pswd b4 they get around to stealing your account.
 
How does these scammers operate exactly? Are these just a group of people operating out of someones basment and they have code to send out and when clicked, it sends their info to ther computer?
 
How does these scammers operate exactly? Are these just a group of people operating out of someones basment and they have code to send out and when clicked, it sends their info to ther computer?

They make a fake website that looks like a Blizzard website, and send a fake mail directing you to that site with promises of beta access, free in-game pets or whatever. You go to the site and put in your info, which goes into their database, then they use that info log into your wow account, rape it and sell the proceeds to goldbuyers.

It's mostly done by organised companies with hundreds of employees on a very large scale, mostly based in asia or eastern europe, but it's pretty simple for any fairly tech savvy person to pull off.
 
I just got a bogus invite in my gmail inbox, It links to "http://www.worldofwarcraft.com/account" but the actual link takes you to some fake WoW site.
BEWARE!

Return email in the header is to "charmedforlife13@hotmail.com"
 
They make a fake website that looks like a Blizzard website, and send a fake mail directing you to that site with promises of beta access, free in-game pets or whatever. You go to the site and put in your info, which goes into their database, then they use that info log into your wow account, rape it and sell the proceeds to goldbuyers.

It's mostly done by organised companies with hundreds of employees on a very large scale, mostly based in asia or eastern europe, but it's pretty simple for any fairly tech savvy person to pull off.

And the fake that people fall for this crap at all absolutely amazes me, especially with how bad the spelling/grammer is in most of the emails. My wife is completely computer illiterate and can recognize these fake emails right away.

At least one person a month "gets hacked" in my guild, but I'm sure most of them were just dumb enough to fall for crap like this.
 
I get very little spam e-mails in my gmail, but 99% of the ones I get are WoW scams.
They look pretty legit but showing the details quickly identifies they were sent from hotmail.com.
I haven't even played since December.

I was in the WoTLK beta but didn't play much so I didn't opt in for the Cataclysm beta.
Still on the fence about this expansion... I usually play WoW long enough to max out my Character the best I can for the time I'm willing to invest (~1 hour sessions) then cancel my account.
 
i got like 500 beta invites!

proof!
43603268.jpg



ive never even had a retail account ive paid for. only a free trial. i get my WoW fix on private servers.
 
At least one person a month "gets hacked" in my guild, but I'm sure most of them were just dumb enough to fall for crap like this.

Account compromises don't just happen from these e-mail scams. I've experienced it first hand. Sometimes people take advantage of Java or Flash exploits and inject it into WoW fansite/database ads. It'll silently install a keylogger into your computer without triggering the antivirus. Even in Windows Vista/7, no UAC prompts come up or anything. I've read around about stuff like that and I believe it's the closest reason to how I got my account stolen. Nowadays I run noscript except for places I trust (like the [H] site and forums).
 
And the fake that people fall for this crap at all absolutely amazes me, especially with how bad the spelling/grammer is in most of the emails. My wife is completely computer illiterate and can recognize these fake emails right away.

At least one person a month "gets hacked" in my guild, but I'm sure most of them were just dumb enough to fall for crap like this.

I still don't understand why people don't just pay the $6.50 for authenticators. It is worth the frustration you will save alone.
 
I still don't understand why people don't just pay the $6.50 for authenticators. It is worth the frustration you will save alone.

I completely agree. The authenticators are awesome for everyone to have.
 
I completely agree. The authenticators are awesome for everyone to have.

they should ship authenticators with every copy of cataclysm, even if they have to raise the price of the expansion to do it. it would cut down on hacked accounts. also it would be much harder for gold sellers / paid levelling services to deal with.
Posted via [H] Mobile Device
 
Thought I read someplace that even the authenticators weren't 100%?
 
Thought I read someplace that even the authenticators weren't 100%?

They are close to 100% unless you fall into a man in the middle attack. In that situation, you have a keylogger on your PC that send information to hacker as soon as you type it in. You type in your name, password, and authenticator code. Then the hacker log onto your account within 30 seconds and start taking your shit.

You can defeat the man in the middle attack by not getting keylogged and having the login screen retain your username (so all the hackers get is a password and an authenticator code).
 
They work on most phones now actually.

I was using an iPhone authenticator for quite a while and switched to a token when I was getting rid of my phone. No excuse not to have one.

As for a key logger getting past all your other defenses, it was more than likely either your java, flash, or PDF were not patched or configured securly (turn off scripting in all PDF readers). Those are the primary infection methods and yah no-script is your friend but still isn't 100% since you have to trust some sites.
 
They are close to 100% unless you fall into a man in the middle attack. In that situation, you have a keylogger on your PC that send information to hacker as soon as you type it in. You type in your name, password, and authenticator code. Then the hacker log onto your account within 30 seconds and start taking your shit.

You can defeat the man in the middle attack by not getting keylogged and having the login screen retain your username (so all the hackers get is a password and an authenticator code).

Also, if you just keep trying to log in, it should boot the hacker. Do that, or change your password, and you would be fine.

I really don't think a man in the middle attack is a very high possibility. I would gladly pay $6.50 for something that makes me 99.99% safe compared to whatever % of people without authenticators getting hacked.
 
Also, if you just keep trying to log in, it should boot the hacker. Do that, or change your password, and you would be fine.

I really don't think a man in the middle attack is a very high possibility. I would gladly pay $6.50 for something that makes me 99.99% safe compared to whatever % of people without authenticators getting hacked.

The "man in the middle" attack spoofs the login screen, so your information never reaches battle.net's authentication system. Because if it did, the code you just entered will immediately become invalid once you're inside. The attack itself requires someone to install a DLL file I believe. So it's much more invasive and probably easier to catch than the standard keyloggers. Best defense in that situation is to hope you have WoW installed and updated in a clean computer to kick em off.
 
Speaking of authenticators and account security, I just got hacked a few days ago...

I don't have an authenticator. I quit before Wrath came out. I have no level 80s, not even a 71. The last time my account was active was last December, and that was on the 10-day trial of WotLK. I didn't think I'd need an authenticator. My account has been inactive for the longest time. I don't go to any fishy sites. The only WoW-related site I go to is Wowhead, and I don't even get any fishy emails from Blizzard. I didn't think anybody would hack an inactive account. BIG MISTAKE. Somehow, they got into my account and threw and authenticator on it, and whatever they did got me banned for "abusing the economy". I first heard about this via an email that I got saying that I was banned. I made sure NOT to click any links in the email, and instead opened a new tab and went to the WoW site manually. Turns out the email was legit, after all.

I can't post on the official forums obviously, but I did give Blizzard an email on Saturday. I'm hoping that they can get it back. If I don't hear from them by tomorrow, I think I'll have to give them a call.

Point of the story is, GET AN AUTHENTICATOR, even if you're not currently playing. Unless you don't give a damn about your account at all, I suggest that you get one if you don't have one already. I always considered my common sense as my security system. but like I said: I don't go to any fishy sites, I don't click any fishy links, and I never share my account or leave my info laying around, yet someone STILL got through to me. Get an authenticator.
 
They are close to 100% unless you fall into a man in the middle attack. In that situation, you have a keylogger on your PC that send information to hacker as soon as you type it in. You type in your name, password, and authenticator code. Then the hacker log onto your account within 30 seconds and start taking your shit.

You can defeat the man in the middle attack by not getting keylogged and having the login screen retain your username (so all the hackers get is a password and an authenticator code).

This.

The Authenticators should be "as well as", not "instead of" all the other stuff you should be doing, like:

Use a a strong password that you change every once in a while.

Don't use the same password for wow as for your email account.

Make sure you run Windows Update frequently to keep your OS as secure as possible.

Make sure you keep your browser and other apps (especially flash) up to date.

USE ANTIVIRUS, seriously, you need it. If you think that you don't, then you need it MORE, because you're an idiot. There are many free products available that are every bit as good as the paid ones, like AVG, even MS own Security Essentials, which has proven to be every bit as effective as NOD32 or Kaspersky in independent evaluations, and has a really light footprint.

Avoid logging in on strange PCs, you don't know where they've been.

This stuff doesn't just help protect WoW, but also everything else :p
 
Speaking of authenticators and account security, I just got hacked a few days ago...

I don't have an authenticator. I quit before Wrath came out. I have no level 80s, not even a 71. The last time my account was active was last December, and that was on the 10-day trial of WotLK. I didn't think I'd need an authenticator. My account has been inactive for the longest time. I don't go to any fishy sites. The only WoW-related site I go to is Wowhead, and I don't even get any fishy emails from Blizzard. I didn't think anybody would hack an inactive account. BIG MISTAKE. Somehow, they got into my account and threw and authenticator on it, and whatever they did got me banned for "abusing the economy". I first heard about this via an email that I got saying that I was banned. I made sure NOT to click any links in the email, and instead opened a new tab and went to the WoW site manually. Turns out the email was legit, after all.

I can't post on the official forums obviously, but I did give Blizzard an email on Saturday. I'm hoping that they can get it back. If I don't hear from them by tomorrow, I think I'll have to give them a call.

Point of the story is, GET AN AUTHENTICATOR, even if you're not currently playing. Unless you don't give a damn about your account at all, I suggest that you get one if you don't have one already. I always considered my common sense as my security system. but like I said: I don't go to any fishy sites, I don't click any fishy links, and I never share my account or leave my info laying around, yet someone STILL got through to me. Get an authenticator.

the first thing hackers do now is throw an authenticator onto accounts they gain access to. this makes it much harder for the owner to quickly try changing the information to kick out the hackers.
Posted via [H] Mobile Device
 
I tied my battle.net account to the Android market authenticator. I might have to get my phone replaced, how hard is it to replace the authenticator when I redownload a new one?
 
I tied my battle.net account to the Android market authenticator. I might have to get my phone replaced, how hard is it to replace the authenticator when I redownload a new one?

I would remove the authenticator from the account before switching phones.

I personally wouldn't use one on Android. As soon as you uninstall it, switch roms, or whatever you have to go through the whole account verification process with battle.net to remove the old serial number and assign a new one.
 
I tied my battle.net account to the Android market authenticator. I might have to get my phone replaced, how hard is it to replace the authenticator when I redownload a new one?

Remove authenticator from bnet account before getting rid of phone.

When you get new phone, d/l authenticator and re-add new serial to bnet account.

Done.
 
If the android/iphone app functions like the keyfob, removing the authenticator just requires inputting 2 consecutive codes, and that's it. If you delete or replace the app without removing it first, you've basically lost your authenticator and have to call up billing to have it removed. There's no way to copy the app to another device since the algorithm was generated uniquely for that particular device.

Point of the story is, GET AN AUTHENTICATOR, even if you're not currently playing. Unless you don't give a damn about your account at all, I suggest that you get one if you don't have one already. I always considered my common sense as my security system. but like I said: I don't go to any fishy sites, I don't click any fishy links, and I never share my account or leave my info laying around, yet someone STILL got through to me. Get an authenticator.

Pretty much exactly my story. I'm almost convinced that it has to be some infected Flash ad or Java exploit on Wowhead that got to me. I don't know if you read any of my other posts on this forum regarding account compromises, but I noticed some full-screen popup ads while browsing Wowhead bout 4-5 months ago. Soon after that, my account was stolen.
 
Cool! I've been getting so many blizzard spam mails. But I was wondering whether Android had an authenticator app yet.
 
You can back up the Android authenticator's data. The file is /data/data/com.blizzard.bma/shared_prefs/com.blizzard.bma.AUTH_STORE.xml.

Just redownload the app and install it. Then copy that file back to the phone before running the authenticator. You'll be back up and running without having to detach and reattach a new authenticator to your account. You can even have a backup authenticator if you know how to undo the mask they used to hide the secret token and serial number that's inside the XML file.
 
Back
Top