<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LiquidSilver &#187; hacking</title>
	<atom:link href="http://www.liquidsilver.org/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liquidsilver.org</link>
	<description>Technology Matters</description>
	<lastBuildDate>Mon, 06 Feb 2012 08:30:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Still no Sign of Playstation Network</title>
		<link>http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/</link>
		<comments>http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/#comments</comments>
		<pubDate>Sun, 08 May 2011 20:16:43 +0000</pubDate>
		<dc:creator>Mauldor</dc:creator>
				<category><![CDATA[Gaming]]></category>
		<category><![CDATA[creditcard]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[gift]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[letter]]></category>
		<category><![CDATA[playstation]]></category>
		<category><![CDATA[psn]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[sony]]></category>

		<guid isPermaLink="false">http://www.liquidsilver.org/?p=3028</guid>
		<description><![CDATA[Tweet It is now the 8th May 2011 and although Sony have been making noises about offering a free Month of PSN+ service, a free game of some sort and other such good things, In the UK nothing has been heard and still no news of getting the service back. I have heard of people [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080; border-radius:5px 5px 5px 5px; box-shadow:2px 2px 5px rgba(0,0,0,0.3);background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.liquidsilver.org%2F2011%2F05%2Fstill-no-sign-of-playstation-network%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/"  data-text="Still no Sign of Playstation Network" data-count="horizontal" data-via="LiquidTV">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.liquidsilver.org/wp-content/uploads/2010/11/ps3_slim.jpg"><img class="aligncenter size-full wp-image-2564" title="ps3_slim" src="http://www.liquidsilver.org/wp-content/uploads/2010/11/ps3_slim.jpg" alt="" width="640" height="360" /></a></p>
<p>It is now the 8th May 2011 and although Sony have been making noises about offering a free Month of PSN+ service, a free game of some sort and other such good things, In the UK nothing has been heard and still no news of getting the service back. I have heard of people selling there PS3 and buying an XBOX360 and saying they will never buy a Sony product ever again and if you do not, then you must be a fan boy or something. I want to set the record straight from my own viewpoint of this whole PS3 debates.</p>
<p><span id="more-3028"></span><strong>What is PSN</strong></p>
<p>This <strong>free</strong> service allows you to play on-line with others, send and receive messages (rather like email then) and voice and/or video chat with them if you have the right gear. In the world of PC&#8217;s &#8211; on-line games each have there own server and you end of with various names across the board. Sony by placing a central service means you may well have one name but once this middle man goes down &#8211; you are left high and dry.</p>
<p>The only game which I used On-line to be honest was <a href="http://mysackboy.littlebigplanet.com/">LittleBigPlanet</a> which allows others to jump in and help you complete the levels. I suck as First person Shooters on a console, so 99% of the time I am playing single player anyhow. As I have other means to chat to people instead of PSN, this feature never gets used and I have yet to speak to a single person on-line even though I have all the gear.</p>
<p><strong>Are you Selling your PS3?</strong></p>
<p>I bought the PS3 unit itself, this costs me £200 for the 160GIG unit. We then bought the Bluetooth microphone &#8211; £23, we add to this the Move Starter kit, another £40 and we have 11 games ranging from £10 to £20. This means I have easily spent Over £400 on that lot. If I were to sell this at some store, I would be lucky to get half of that &#8211; what sane person would chuck away half of there money just because the PSN part is currently off-line?<strong></strong></p>
<p>The PS3 still serves it purpose in that it plays games I enjoy playing, the games are cheap to come by and there is still a lot of life in the thing. I can browse the web (with flash) and I can play movies no problems.</p>
<p><strong>Items I wish I had never bought</strong></p>
<p>The Bluetooth headset I should only have bought once I got speaking to people, these days my online chat sessions are limited even on the PC never mind the PS3. I can use it with the PC though and it charges via a cradle so it was not 100% waste of my money and it was only £23. The other item I have not used much (due to lack of games) is the Move, I did get the camera (which I was going to buy anyhow) and it is fun but I could have lived without it. <strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.liquidsilver.org/2011/05/still-no-sign-of-playstation-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Playstation 3 and the Banning Order</title>
		<link>http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/</link>
		<comments>http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/#comments</comments>
		<pubDate>Tue, 22 Feb 2011 23:00:08 +0000</pubDate>
		<dc:creator>Mauldor</dc:creator>
				<category><![CDATA[Gaming]]></category>
		<category><![CDATA[3.56]]></category>
		<category><![CDATA[ban]]></category>
		<category><![CDATA[banning]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[geohot]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[playstation]]></category>
		<category><![CDATA[playstation3]]></category>
		<category><![CDATA[ps3]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[updated]]></category>

		<guid isPermaLink="false">http://www.liquidsilver.org/?p=2864</guid>
		<description><![CDATA[Tweet The one console that remained rock steady in the light of people hacking them to play illegal and unsigned software was the playstation 3. A person by the name of Geohot managed to work out the secret security key that all playstation software is signed with. Armed with this information, you could load a game / application [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080; border-radius:5px 5px 5px 5px; box-shadow:2px 2px 5px rgba(0,0,0,0.3);background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.liquidsilver.org%2F2011%2F02%2Fplaystation-3-and-the-banning-order%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/"  data-text="Playstation 3 and the Banning Order" data-count="horizontal" data-via="LiquidTV">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.liquidsilver.org/wp-content/uploads/2011/02/playstation_3.jpg"><img class="aligncenter size-full wp-image-2865" title="playstation_3" src="http://www.liquidsilver.org/wp-content/uploads/2011/02/playstation_3.jpg" alt="" width="620" height="365" /></a></p>
<p>The one console that remained rock steady in the light of people hacking them to play illegal and unsigned software was the playstation 3. A person by the name of Geohot managed to work out the secret security key that all playstation software is signed with. Armed with this information, you could load a game / application onto the PS3 and it thought it was an official piece of software and ran no problems. Ther was in fact three area&#8217;s that were of concern here and these were playing pirated games (Sony looses money), Install Homebrew software and finally hacking on-line games somehow. Sony recently not only updated the firmware to 3.56 to combat this but also issued an email to all people it suspected of running the firmware and saying it would ban them if they did not remove it.</p>
<p><span id="more-2864"></span><strong>The email from Sony</strong></p>
<blockquote><p>Important: Access to the PlayStation(R)Network and Access to Qriocity(TM) Services Notice</p>
<p>Unauthorized circumvention devices for PlayStation(R)3 system have been recently released by hackers for the PlayStation(R)3 system.  These devices permit the use of unauthorized or pirated software.</p>
<p>Use of such devices or software violates the terms of your “System Software License Agreement for the PlayStation(R)3 System” and the “Terms of Services and User Agreement” for the PlayStation(R)Network/Qriocity(TM) and its Community Code of Conduct provisions.  In addition, copying or playing pirated software is a violation of International Copyright Laws.</p>
<p>A circumvention device and/or unauthorized or pirated software currently resides on your PlayStation(R)3 system.</p>
<p>Immediately cease use and remove all circumvention devices and delete all unauthorized or pirated software from your PlayStation(R)3 system.  Failure to do so will result in termination of your access to PlayStation(R) Network and access to Qriocity(TM) services through your PlayStation(R)3 system.</p></blockquote>
<p><strong>The Background</strong></p>
<p>I am happy to buy games for my playstation, they range from £8 to £21 with most going for the lower £10 price tag. I have enough games to keep me going for a while and was not going to test the water by hacking my firmware. There is always the chance that you can brick the PS3 if it goes wrong. One night I got bored and I gave it a go, it went smooth and after I installed the 3.55 firmware by GeoHot, I now had the ability to &#8220;Install package Files&#8221;. I installed a few homebrew titles such as emulators and FTP Programs.</p>
<p><strong>The Update</strong></p>
<p>When 3.56 came out and I was not on-line, I had no issues with updating to the latest version, I felt at this point after removing any traces of the software I had installed, I was back to been legal. I could not install any files, I could not access any previous titles (they had been removed anyhow) and all was god in the world right?</p>
<p>I still got that email &#8211; this means Sony may have detected I ran such a thing but am I now safe? I started to doubt myself at this stage, had I removed all the file I need to? Should I have gone back to 3.55 Official before I updated to 3.56? Will I still get banned at some point? If I do get banned, is it the console or just me?</p>
<p><strong>My thoughts</strong></p>
<p>Sony first of all need to produce a way for people to make there console 100% legal, so people can sleep easy at night they have done the right thing. Sending emails with warning that you better sort it out or else we will ban you is not a good PR move.</p>
<p>I have the Sony Bluetooth Headset, I have the Sony Move and Webcam and countless bought games. I have spent a good chunk of money on this Sony made device. If they start to go wild and ban people who are now legal &#8211; they might as well forget about making the PS4. If I had installed a Chip and carried on using it after they told me it was against the rules &#8211; thats fine by me but blanket emails is not good. I am start to loose faith in Sony and the PS3 &#8211; remember people such as me will tell friends and family &#8220;You should buy a PS3 and not the XBOX360&#8243;.</p>
<p>I just did a system update again &#8211; and it updated from 3.56 to 3.56 &#8211; Very odd.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.liquidsilver.org/2011/02/playstation-3-and-the-banning-order/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PayPal Hacked maybe?</title>
		<link>http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/</link>
		<comments>http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/#comments</comments>
		<pubDate>Tue, 15 Feb 2011 23:09:49 +0000</pubDate>
		<dc:creator>Mauldor</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[lockdown]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[paypal]]></category>

		<guid isPermaLink="false">http://www.liquidsilver.org/?p=2839</guid>
		<description><![CDATA[Tweet Before I jump into the story, let me tell you a bit of background. I only have a paypal account as I sold some items on eBay many years ago and recently I used this method I think to buy something from eBay. As a general rule I do not log into my PayPal [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080; border-radius:5px 5px 5px 5px; box-shadow:2px 2px 5px rgba(0,0,0,0.3);background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.liquidsilver.org%2F2011%2F02%2Fpaypal-hacked-maybe%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/"  data-text="PayPal Hacked maybe?" data-count="horizontal" data-via="LiquidTV">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.liquidsilver.org/wp-content/uploads/2011/02/paypal_logo.jpg"><img class="aligncenter size-full wp-image-2840" title="paypal_logo" src="http://www.liquidsilver.org/wp-content/uploads/2011/02/paypal_logo.jpg" alt="" width="600" height="260" /></a>Before I jump into the story, let me tell you a bit of background. I only have a paypal account as I sold some items on eBay many years ago and recently I used this method I think to buy something from eBay. As a general rule I do not log into my PayPal account, I have no funds on there and I honestly thought it was safe. Yet more background &#8211; my passwords are so hard (Uppercase, Lowercase, Numbers &#8211; no real words, longer than 12 characters in length) that I have to write them in a book which is secure. I would like to say that maybe Chrome saves my passwords but in the case of Paypal and the fact I had not logged into it for so long, it was not stored on this computer.</p>
<p>So what is the Hack you may ask? Well let me go through a sequence of events which all took place today and I am glad I carry a phone that shows my emails as they come in.</p>
<p><span id="more-2839"></span><strong>The flood of emails</strong></p>
<p>The first email came in at 14:22, it read:</p>
<blockquote><p>Dear Thomas,</p>
<p>You have initiated a PayPal Mobile payment for $1,080.00 USD to <a href="mailto:tommy1988tommy@yahoo.com">tommy1988tommy@yahoo.com</a>. This payment will be completed once the recipient has accepted the payment.</p>
<p>It may take a few moments for this transaction to appear in the Recent Activity list on your Account Overview.</p>
<p>Currency conversion: £712.48 GBP = $1,117.02 USD</p>
<p>The exchange rate for this purchase is 1 GBP = 1.56779USD</p>
<p>Payment details</p>
<p>Amount: $1,080.00 USD<br />
Transaction Date: 15 February 2011<br />
Transaction ID: XXXXXXXXXXXXX (Not real)</p>
<p>Message:<br />
I have recieved this virtual item will not charge back . Sent using the PayPal Mobile application.</p></blockquote>
<p>As I get loads of these fake emails, I headed to my work computer to check it out, I got another email though at 14:27</p>
<blockquote><p>Dear Thomas,</p>
<p>This Apple® mobile digital device was removed from your PayPal account: Owner’s iPod.</p>
<p>The next time you log in to PayPal on this device, it will link to your account again.</p></blockquote>
<p>I do not own an iPod &#8211; this was swiflty followed at 14:43:</p>
<blockquote><p><strong>Your account has been limited until we hear from you</strong></p>
<p>Dear Thomas,</p>
<p>We need your help resolving an issue with your account. To give us time to work together on this, we&#8217;ve temporarily limited what you can do with your account until the issue is resolved.</p></blockquote>
<p>You can see the sequence of events taken place, somebody managed to somehow make a payment from my account via an iPod using the Mobile paying service and PayPal locked the doors quickly as they suspected something.</p>
<p><strong>Checking the real PayPal</strong></p>
<p>I was not sure if these emails were even real, never click on any links in an email in such a case and always just go to the site in question and log in to check it out instead &#8211; which is what I did. The first thing that annoyed me was it stated that this had gone through and would be taken from the credit card on my account. I would not be a happy bunny if $1000 left my credit card, I filed a fraud claim and I called them up. They assured me it will be dealt with and said no money will leave any account plus they will look into IP&#8217;s that logged in and so forth.</p>
<p><strong>Security</strong></p>
<p>When I did go to the page, it made me not only change all my details but also to confirm via phone various items and on top of this I have now switched on the SMS function that requires me having my mobile with me. On top of this I have removed any credit cards on there and my bank details.</p>
<p><strong>Thoughts on this</strong></p>
<p>My Password to my knowledge was secure and not easy to guess and why did PayPal lock my account down straight away after the transaction? Why do I not have access to see what IP&#8217;s address logged into my account?</p>
<p>I do know that once this is sorted, I am closing down my PayPal account. I have just checked with my credit card people and in fact they tried to take 3 x $1000, the 2nd two got denied and thus why my PayPal account got locked down I guess. The transaction is authorised but has not been collected from Paypal &#8211; this means while my account might show me as been £712 down, it has not physically entered into the other persons bank. If Paypal do not come up with the goods I shall have to go to the credit card side and get the money back this way.</p>
<p>My Advice since this happened? If you do use Paypal, make sure you remove the credit card after you have used it for the proper purpose.</p>
<p><strong>** Update 16 Feb 2011 **</strong></p>
<p>I got an email first thing this morning:-</p>
<blockquote><p>We&#8217;ve finished reviewing your unauthorised activity claim and you&#8217;ll receive a refund for the transaction amount. It may take up to five working days for the funds to appear in your account.</p>
<p>Any portion of the payment that was funded with your credit card will be refunded directly to your credit card. You will see this in your transaction log as two entries. The first is the refund to your PayPal account and the second is the credit to your credit card. Credits to a credit card generally take two to three working days to clear, and may not</p>
<p>be immediately reflected in the card&#8217;s balance.</p></blockquote>
<p>This is great news &#8211; but later tonight, I thought I better check Paypal and low and behond:</p>
<p>A Cancellation fee of $37.02 has been placed on my account &#8211; I reach for the phone. They said that a Fee for any transaction returned is paybale by the person of the account. My point here was that the account was used fraudulently (i.e. a crime had been committed) and yet PayPal felt the need to charge me for the fact? They explained that the money will be returned once it is all sorted and she could not put me though to anybody else as all the other departments were closed. There is no credit card assigned to that account now &#8211; will they try and take it off the card that was registered before?</p>
<p>I wrote another email and my plan of attack is as follows:</p>
<ul>
<li>Call the Credit Card company on Friday to verify that the money has gone back on.</li>
<li>Get them to issue a new set of cards so no more money can be taken no matter what.</li>
<li>Close the Paypal Account once this is all sorted once and for all.</li>
</ul>
<p><strong>*** Update 17 Feb 2011 ***</strong></p>
<p>This now sort of concludes, I emailed them and they replied:</p>
<blockquote><p>Thank you for contacting PayPal in relation to the unauthorized payment that was taken out from your account. I can sense the importance of this matter so please let me get to the bottom of this.</p>
<p>Mr. Hill, having reviewed your account it shows that indeed the transaction was proven to be fraudulent thus refunding you the amount that was taken from your card.</p>
<p>When a transaction was initiated PayPal will charge a corresponding fee and this will be paid by either the seller or the buyer which in this case was charged on your account. Since the transaction was cancelled, the payment fee of $37.02 USD has been cancelled as well. So therefore, PayPal did not take any charge on the said transaction and refunded you the full amount of £712.48 that was the amount originally taken from your card.</p>
<p>I hope I was able to address your concern today and should you need further assistance please don&#8217;t hesitate to contact us again.</p>
<p>I understand that you have been patient and understanding about this matter and it is very much appreciated.</p></blockquote>
<p>I did call them up to ask <strong>why</strong> was my account comprised &#8211; they searched the records and could not come up with any answers. They suggested all of the following (Shifting the blame to me):</p>
<ul>
<li>I Clicked a link in a false email from Paypal and my account was stolen.</li>
<li>There is a virus on my computer which stole the password.</li>
<li>My Password was in fact very simple to guess.</li>
<li>A Friend may have used my account (which of course I gave the password to).</li>
<li>They plain just guessed the password.</li>
</ul>
<p>Needless to say &#8211; I do not feel at all safe using paypal period and I will tell my story to all that will listen, I was lucky and got my money back quickly, you may not be so lucky.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.liquidsilver.org/2011/02/paypal-hacked-maybe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HotMail Compromised</title>
		<link>http://www.liquidsilver.org/2010/10/hotmail-compromised/</link>
		<comments>http://www.liquidsilver.org/2010/10/hotmail-compromised/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 20:22:57 +0000</pubDate>
		<dc:creator>Mauldor</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[contacts]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hotmail]]></category>
		<category><![CDATA[media]]></category>
		<category><![CDATA[msn]]></category>
		<category><![CDATA[skype]]></category>
		<category><![CDATA[social]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.liquidsilver.org/?p=2358</guid>
		<description><![CDATA[Tweet It has been some years since I have even bothered to look at Hotmail or in fact MSN Live Messenger as it is now called. As I removed most of the Social networks now which includes Twitter and Skype &#8211; I thought I would install MSN once again and see if anybody was about [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080; border-radius:5px 5px 5px 5px; box-shadow:2px 2px 5px rgba(0,0,0,0.3);background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.liquidsilver.org%2F2010%2F10%2Fhotmail-compromised%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.liquidsilver.org/2010/10/hotmail-compromised/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.liquidsilver.org/2010/10/hotmail-compromised/"  data-text="HotMail Compromised" data-count="horizontal" data-via="LiquidTV">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.liquidsilver.org/2010/10/hotmail-compromised/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.liquidsilver.org/2010/10/hotmail-compromised/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a rel="attachment wp-att-2359" href="http://www.liquidsilver.org/2010/10/hotmail-compromised/hotmail-logo/"><img class="aligncenter size-full wp-image-2359" title="hotmail-logo" src="http://www.liquidsilver.org/wp-content/uploads/2010/10/hotmail-logo.jpg" alt="" width="580" height="250" /></a></p>
<p>It has been some years since I have even bothered to look at Hotmail or in fact MSN Live Messenger as it is now called. As I removed most of the Social networks now which includes Twitter and Skype &#8211; I thought I would install MSN once again and see if anybody was about for a chat and such. It had been such a long time that I had forgot my password &#8211; I went through and reset this to something I would know though still hard to guess. Once I booted up Messenger, it informed me I was already logged in somewhere else and it would log me off that location (very odd). As I had so many email I had not read in years, I set up Outlook to also grab the mails.</p>
<p><span id="more-2358"></span><strong>Next day&#8230;.</strong></p>
<p>I logged in once again and fired up Outlook &#8211; I saw that a LOT of messages were &#8220;Undeliverable&#8221; &#8211; one to each of my contacts in fact with some link, some badly written English and 100% not from me. I know people can easy spoof emails who they are from &#8211; so I checked my sent items and sure enough there was all of the emails I had sent out. I am sure my contacts wonder why I am sending them some email with me swearing as the topic and me sending them a link &#8211; I hope none of them clicked the said link.</p>
<p><strong>It makes you wonder though..</strong></p>
<p>I had changed the password yet somehow they managed to do this very thing and the password was pretty intense with Capitals, lowercase and numbers and not even a real word. They sent them today, this means they managed to do this in the last 24 hours but unlike Google Mail which shows you who logged in and from where &#8211; I have no idea how to check this.</p>
<p><strong>Removal of all things Microsoft</strong></p>
<p>As I expected, nobody was actually on-line on my MSN List, they have either blocked me (as I thought I had left or blocked them maybe) or they were just not using MSN also. I never use my Hotmail for anything at all and 90% of the messages were in fact Spam, do MS not have a Spam filter like Google then? I de-installed the Live package (which included MSN and such) and closed down my account &#8211; or at least tried to. I have to wait 72 hours without logging in to see if it finally is all gone, I personally hope so.</p>
<p><strong>Yet less on-line interaction then?</strong></p>
<p>You might be forgiven to thinking I am trying to disappear from the net &#8211; I have since lost all 3 Twitter Account, removed my Skype, deleted all other Social Networking logins / sites and now we remove MSN. I do not even have Chat enabled on FaceBook and if you try and search for me &#8211; good luck in actually finding me, I have set the privacy so low that it just won&#8217;t come up.</p>
<p>Maybe I am happier that I can choose who to contact and how I want to contact them without every single person known the slights movement I make right? Maybe the people who seem to Live and thrive on these social networking sites have limited outside contact with real humans? Anyhow &#8211; lets hope MSN goes away soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.liquidsilver.org/2010/10/hotmail-compromised/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Bypass WoW Authenticators</title>
		<link>http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/</link>
		<comments>http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 21:27:15 +0000</pubDate>
		<dc:creator>Mauldor</dc:creator>
				<category><![CDATA[MMORPG]]></category>
		<category><![CDATA[accounts]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[locked]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[warcraft]]></category>
		<category><![CDATA[wow]]></category>

		<guid isPermaLink="false">http://www.liquidsilver.org/?p=1695</guid>
		<description><![CDATA[Tweet A new keylogger disguised as a World of Warcraft add-on is stealing account info and goods. Last week reports of a &#8220;man-in-the-middle-attack&#8221; surfaced in regards to Blizzard&#8217;s MMORPG. World of Warcraft. Apparently hackers have created a tool that grants them access to accounts protected by an authentication tool. Once they are in control of [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080; border-radius:5px 5px 5px 5px; box-shadow:2px 2px 5px rgba(0,0,0,0.3);background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.liquidsilver.org%2F2010%2F03%2Fhackers-bypass-wow-authenticators%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/"  data-text="Hackers Bypass WoW Authenticators" data-count="horizontal" data-via="LiquidTV">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.liquidsilver.org/wp-content/uploads/2010/01/wow-logo-01.jpg"><img class="aligncenter size-full wp-image-1526" title="wow-logo" src="http://www.liquidsilver.org/wp-content/uploads/2010/01/wow-logo-01.jpg" alt="" width="450" height="300" /></a><strong>A new keylogger disguised as a World of Warcraft add-on is  stealing account info and goods.</strong></p>
<p>Last week reports of a &#8220;<a rel="nofollow" href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man-in-the-middle-attack</a>&#8221; surfaced in regards to  Blizzard&#8217;s MMORPG. World of Warcraft. Apparently hackers have created a  tool that grants them access to accounts protected by an authentication  tool. Once they are in control of the account, hackers can thus steal  virtual gold and possessions until the account password is reset.  Currently there&#8217;s no indication if the hackers gain access to data such  as credit cards or other personal information.</p>
<p><span id="more-1695"></span></p>
<p>The tool in question is a keylogger, possibly a file named emcor.dll  which can be found in C:/Documents and  Settings/Users/[username]/Application Data/Temp. Once the user launches  the keylogger, the PC is infected and will in turn cause World of  Warcraft to crash. Once the players re-start the game and log back into  the account, the authenticator code is intercepted by the hacker. A  different code is sent to Blizzard&#8217;s servers, locking the player out.</p>
<p><a href="http://www.liquidsilver.org/wp-content/uploads/2010/03/matrixx.jpg"><img class="aligncenter size-full wp-image-1696" title="matrixx" src="http://www.liquidsilver.org/wp-content/uploads/2010/03/matrixx.jpg" alt="" width="499" height="233" /></a></p>
<p>So how do players get the keylogger on their PC? It all starts with a  sponsored link in Google showing up as a top result for <a rel="nofollow" href="http://www.wowmatrix.com/" target="_blank">WowMatrix</a>,  a free World of Warcraft add-on installer and updater. The problem is  that the listing isn&#8217;t a genuine, leading gamers to the malware.  &#8220;Several downloads are available and I decided to check out the  installer / updater,&#8221; reads t<a rel="nofollow" href="http://bluetack.co.uk/forums/index.php?showtopic=20218">his forum post</a>. &#8220;Results are pretty low at virustotal  for the executable. The detection of the DLL hooked into our system is  even worse, only 1 antivirus suspects some illegal activity.&#8221;</p>
<p>Because authenticator codes only last for 30 seconds, hackers have  access to the WoW account until they log out. &#8220;This is still perpetrated  by key loggers, and no method is always 100% secure,&#8221; Blizzard said in <a rel="nofollow" href="http://forums.wow-europe.com/thread.html?topicId=12730404058&amp;sid=1&amp;pageNo=1#15">this forum post</a>.</p>
<p>WoW gamers are warned to stay away from the following sites, which  are actually based on legitimate WoW related sites with a typo at the  end of each URL:</p>
<ul>
<li>wowmatrixf(dot)com</li>
<li>Cursea(dot)com</li>
<li>deadlybossmodss(dot)com</li>
<li>gamesacca(dot)com</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

