<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LiquidSilver &#187; keylogger</title>
	<atom:link href="http://www.liquidsilver.org/tag/keylogger/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liquidsilver.org</link>
	<description>Technology Matters</description>
	<lastBuildDate>Mon, 06 Feb 2012 08:30:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Hackers Bypass WoW Authenticators</title>
		<link>http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/</link>
		<comments>http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 21:27:15 +0000</pubDate>
		<dc:creator>Mauldor</dc:creator>
				<category><![CDATA[MMORPG]]></category>
		<category><![CDATA[accounts]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[locked]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[warcraft]]></category>
		<category><![CDATA[wow]]></category>

		<guid isPermaLink="false">http://www.liquidsilver.org/?p=1695</guid>
		<description><![CDATA[Tweet A new keylogger disguised as a World of Warcraft add-on is stealing account info and goods. Last week reports of a &#8220;man-in-the-middle-attack&#8221; surfaced in regards to Blizzard&#8217;s MMORPG. World of Warcraft. Apparently hackers have created a tool that grants them access to accounts protected by an authentication tool. Once they are in control of [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080; border-radius:5px 5px 5px 5px; box-shadow:2px 2px 5px rgba(0,0,0,0.3);background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.liquidsilver.org%2F2010%2F03%2Fhackers-bypass-wow-authenticators%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/"  data-text="Hackers Bypass WoW Authenticators" data-count="horizontal" data-via="LiquidTV">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://www.liquidsilver.org/wp-content/uploads/2010/01/wow-logo-01.jpg"><img class="aligncenter size-full wp-image-1526" title="wow-logo" src="http://www.liquidsilver.org/wp-content/uploads/2010/01/wow-logo-01.jpg" alt="" width="450" height="300" /></a><strong>A new keylogger disguised as a World of Warcraft add-on is  stealing account info and goods.</strong></p>
<p>Last week reports of a &#8220;<a rel="nofollow" href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man-in-the-middle-attack</a>&#8221; surfaced in regards to  Blizzard&#8217;s MMORPG. World of Warcraft. Apparently hackers have created a  tool that grants them access to accounts protected by an authentication  tool. Once they are in control of the account, hackers can thus steal  virtual gold and possessions until the account password is reset.  Currently there&#8217;s no indication if the hackers gain access to data such  as credit cards or other personal information.</p>
<p><span id="more-1695"></span></p>
<p>The tool in question is a keylogger, possibly a file named emcor.dll  which can be found in C:/Documents and  Settings/Users/[username]/Application Data/Temp. Once the user launches  the keylogger, the PC is infected and will in turn cause World of  Warcraft to crash. Once the players re-start the game and log back into  the account, the authenticator code is intercepted by the hacker. A  different code is sent to Blizzard&#8217;s servers, locking the player out.</p>
<p><a href="http://www.liquidsilver.org/wp-content/uploads/2010/03/matrixx.jpg"><img class="aligncenter size-full wp-image-1696" title="matrixx" src="http://www.liquidsilver.org/wp-content/uploads/2010/03/matrixx.jpg" alt="" width="499" height="233" /></a></p>
<p>So how do players get the keylogger on their PC? It all starts with a  sponsored link in Google showing up as a top result for <a rel="nofollow" href="http://www.wowmatrix.com/" target="_blank">WowMatrix</a>,  a free World of Warcraft add-on installer and updater. The problem is  that the listing isn&#8217;t a genuine, leading gamers to the malware.  &#8220;Several downloads are available and I decided to check out the  installer / updater,&#8221; reads t<a rel="nofollow" href="http://bluetack.co.uk/forums/index.php?showtopic=20218">his forum post</a>. &#8220;Results are pretty low at virustotal  for the executable. The detection of the DLL hooked into our system is  even worse, only 1 antivirus suspects some illegal activity.&#8221;</p>
<p>Because authenticator codes only last for 30 seconds, hackers have  access to the WoW account until they log out. &#8220;This is still perpetrated  by key loggers, and no method is always 100% secure,&#8221; Blizzard said in <a rel="nofollow" href="http://forums.wow-europe.com/thread.html?topicId=12730404058&amp;sid=1&amp;pageNo=1#15">this forum post</a>.</p>
<p>WoW gamers are warned to stay away from the following sites, which  are actually based on legitimate WoW related sites with a typo at the  end of each URL:</p>
<ul>
<li>wowmatrixf(dot)com</li>
<li>Cursea(dot)com</li>
<li>deadlybossmodss(dot)com</li>
<li>gamesacca(dot)com</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.liquidsilver.org/2010/03/hackers-bypass-wow-authenticators/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

