Author Topic: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts  (Read 13770 times)

0 Members and 1 Guest are viewing this topic.

Janus

  • *spicy* *camper*
  • Administrator
  • *
    • View Profile
    • Mount&Blade Unofficial File Repository
  • Faction: Rhodok
  • M&BWBWF&S
IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« on: October 21, 2010, 10:29:33 PM »
The forum Administration will not ask for password or serial key information via random PM.
This will never be legit:

Immediately report any such PMs to the Administration team.


First Security Message (Oct 21, 2010)

Please note that the forum will never ask for your username and password in a separate popup window. The only valid password entry forms for the forum look like this, integrated into the page as shown:



If instead you ever see a password entry request in a pop-up window like the one below, do not enter you forum account info into it. Any such password request pop-up is almost certainly an attempt to steal your account info.



You'll notice in the above image that the popup window clearly indicates in the first line the actual website domain which the request is coming from, and it's not TaleWorlds (no matter what it may indicate in the second line). The above screenshot is of a password popup generated in Firefox, but other browsers should similarly indicate the actual website domain which such requests are coming from.
If you ever unwittingly enter your account info into such a password request form, you should immediately change your password.

The reason for this announcement is due to a recent user apparently having a fake image link in his signature which would cause the above example of a password request pop-up. Again, if you saw that pop-up and actually entered your forum account info, you should immediately change the password on your forum account, along with any accounts with other sites on the internet on which you used the same password.
« Last Edit: July 12, 2012, 03:05:26 PM by Caba`drin »
Tomas asked Dolgan, "What place is this?"
The dwarf puffed on his pipe. "It is a glory hole, laddie. When my people mined this area, we fashioned many such areas."
     - Raymond E. Feist, Magician: Apprentice  (Riftwar Saga)

FrisianDude

  • Coitus non Awesome
  • Grandmaster Knight
  • *
  • Zis is Tshörman tärritorie!
    • View Profile
  • Faction: Neutral
  • MP nick: OLL_SirAndelot/Liudulf Ward
  • M&BWB
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #1 on: October 21, 2010, 10:36:42 PM »
Whoah, yeah. :? Thanks for the announcement.
Nords ruled by King Ragnar, Khergits ruled by Sanjar Khan, Rhodoks ruled by King Graveth, Swadians ruled by King Harlaus, Vaegirs ruled by King Yaroglek. All those peoples live, fight, and die in the continent of Calradia. The Nords and Rhodoks field solely infantry and archers, the Swadians and Vaegirs have infantry, archers and cavalry and the Khergit field almost exclusively cavalry. No such things as "infarty" or "calvary" exist. Play Vikingr!

Warcat92

  • Knight
  • *
  • Beneath the soft fur lies a vicious beast
    • View Profile
  • Faction: Khergit
  • MP nick: Fallen_Warcat_
  • M&BWBWF&SNW
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #2 on: October 21, 2010, 10:43:51 PM »
You find out who was doing this?

Sir Hitson Winsler

  • Tin still won't turn to gold.
  • Grandmaster Knight
  • *
    • View Profile
  • Faction: Neutral
  • M&B
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #3 on: October 21, 2010, 10:45:29 PM »
I thought it was just some recruit who thought Taleworlds and Steam were trying to hack his account.

But alas, 'tis serious.
I'm young, black, rich and famous.
I got ten dollars hanging from my anus.

If you don't feel my flow
I will steal your ho
After I steal your ho
I will kill your ho
Raise her from the dead
Count up all my bread
After I am fed
I will make that ho re-dead

McBeverage

  • Not a number, a free man!
  • Grandmaster Knight
  • *
  • On the edge - spirit begins to break.
    • View Profile
  • Faction: Neutral
  • MP nick: Botchbrood_McBeverage
  • M&BWB
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #4 on: October 21, 2010, 10:46:25 PM »
You find out who was doing this?
The particular user was this one.

Might be others around, but I'll let Janus answer that when he posts next.
can i  have friendly hand shack
A friendly hand shack?  That sounds like some shady masturbation establishment.
How about bane for the insult of user?

Warcat92

  • Knight
  • *
  • Beneath the soft fur lies a vicious beast
    • View Profile
  • Faction: Khergit
  • MP nick: Fallen_Warcat_
  • M&BWBWF&SNW
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #5 on: October 21, 2010, 10:48:13 PM »
How'd he not know what his sig was doing. And if his sig did that, what could other sigs be doing?

Janus

  • *spicy* *camper*
  • Administrator
  • *
    • View Profile
    • Mount&Blade Unofficial File Repository
  • Faction: Rhodok
  • M&BWBWF&S
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #6 on: October 21, 2010, 10:49:47 PM »
You find out who was doing this?

Yes. I've contacted the person in question on the vanishingly slim chance that it wasn't intended as a password theft attempt before outright banning him, but I don't expect much from that. Even if this particular instance wasn't malicious in nature (unlikely), other such attempts could happen in the future so I figured this announcement was needed.
The only real way we could completely prevent such a thing from happening again would be to disable images from being posted in the forum entirely, and I'm not willing to do that.

EDIT: after further investigation which proves the malicious intent, he's now banned.
« Last Edit: October 21, 2010, 10:52:17 PM by Janus »
Tomas asked Dolgan, "What place is this?"
The dwarf puffed on his pipe. "It is a glory hole, laddie. When my people mined this area, we fashioned many such areas."
     - Raymond E. Feist, Magician: Apprentice  (Riftwar Saga)

Janus

  • *spicy* *camper*
  • Administrator
  • *
    • View Profile
    • Mount&Blade Unofficial File Repository
  • Faction: Rhodok
  • M&BWBWF&S
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #7 on: October 21, 2010, 11:00:12 PM »
I should further add that I've found he is connected to the following site:
http://risker.in/

Anyone who entered their username and password to that popup message should really also change their password on any other accounts on the internet which use the same password as they have here on the forum. Otherwise, you should expect to have your other accounts accessed eventually.
Tomas asked Dolgan, "What place is this?"
The dwarf puffed on his pipe. "It is a glory hole, laddie. When my people mined this area, we fashioned many such areas."
     - Raymond E. Feist, Magician: Apprentice  (Riftwar Saga)

COGlory

  • Recruit
  • *
    • View Profile
  • Faction: Neutral
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #8 on: October 21, 2010, 11:04:04 PM »
Thanks Janus.  Always keeping the site up.  :) 

Warcat92

  • Knight
  • *
  • Beneath the soft fur lies a vicious beast
    • View Profile
  • Faction: Khergit
  • MP nick: Fallen_Warcat_
  • M&BWBWF&SNW
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #9 on: October 21, 2010, 11:08:17 PM »
Good work. Hope not many people fell victim of that scam before it was deleted. They seem to have had something againist Hobos

McBeverage

  • Not a number, a free man!
  • Grandmaster Knight
  • *
  • On the edge - spirit begins to break.
    • View Profile
  • Faction: Neutral
  • MP nick: Botchbrood_McBeverage
  • M&BWB
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #10 on: October 21, 2010, 11:10:05 PM »
Whoah, that looks worse than I originally suspected.
can i  have friendly hand shack
A friendly hand shack?  That sounds like some shady masturbation establishment.
How about bane for the insult of user?

COGlory

  • Recruit
  • *
    • View Profile
  • Faction: Neutral
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #11 on: October 21, 2010, 11:11:57 PM »
I just checked out the risker site, and...that person needs to die. 

EDIT:  And McBev is on it.  :P 

SPQR

  • Master Knight
  • *
    • View Profile
  • Faction: Neutral
  • MP nick: Balion_John_Marston
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #12 on: October 21, 2010, 11:21:52 PM »
Good looking out.. thanks.  :wink:

McBeverage

  • Not a number, a free man!
  • Grandmaster Knight
  • *
  • On the edge - spirit begins to break.
    • View Profile
  • Faction: Neutral
  • MP nick: Botchbrood_McBeverage
  • M&BWB
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #13 on: October 21, 2010, 11:24:10 PM »
EDIT:  And McBev is on it.  :P
I am?   :o
can i  have friendly hand shack
A friendly hand shack?  That sounds like some shady masturbation establishment.
How about bane for the insult of user?

Comrade Temuzu

  • Grandmaster Knight
  • *
  • Remove smelly Kolechian from premises.
    • View Profile
  • Faction: Rhodok
  • MP nick: ComradeTemuzu
  • M&BWBWF&SNW
Re: IMPORTANT SECURITY ANNOUNCEMENT: Password Theft Attempts
« Reply #14 on: October 21, 2010, 11:27:16 PM »
You are now.

Godspeed. And dont come back without his head.

Also, related? http://forums.taleworlds.com/index.php?topic=142378.new#new

EDIT. Nevermind, I checked his posts. Just trollin'.
« Last Edit: October 21, 2010, 11:29:59 PM by Comrade Temuzu »