I OBSOLUTELY CANNOT believe that perfect world allows people to change their passwords and email without verification from an original phone number, account number, or email! This is rediculous. There is a hacker out there spamming the PW database. He takes down your email address which is somehow accessable publicly in the game, then spams the servers and bang, he has your password and changes the email! Total BS! Obsultely the worst security ever. I love this game but will not play it anymore if this continues. Why in God's name don't they lock accounts or have some kind of anti-hacking device like WOW does? I mean come on....
And as far as me getting hacked, it's not a virus or keylogger, etc. I've been a freelance computer tech since 1990, the last time I was infected with a virus was 1988 before I become a tech. So it's none of my doing.
I OBSOLUTELY CANNOT believe that perfect world allows people to change their passwords and email without verification from an original phone number, account number, or email!
Good, because they don't. I'm far from a fan of PWE, but when you attempt to change the password it sends a verification to your e-mail. Might want to check the security on all your accounts.
0
perigornMember, Neverwinter Beta Users, Neverwinter Guardian UsersPosts: 6Arc User
edited May 2013
UPdate: I had a CHampions online account too. I went into the Manage Account Guard section, logged in and found this info:
email: wqwaxadd1122@hotmail.com
IP address: 209.73.153.150
Computer ID: 2012-1004-
Last Time Active: May 19, 2013, 2:28 a.m.
I deleted his butt from the approved list so now they shouldn't be able to get back in.
did further digging, apparently this guy likes to hack databases using this info:
userid: moiy285md email: jimmycdf98@gmail.com
got his ISP info too:
209.73.153.150 - Geo Information
IP Address 209.73.153.150
Host 209.73.153.150
Location US, United States
City San Jose, CA 95133
Organization Enjoy Technology
ISP EGIHosting
AS Number AS18779 EGIHosting
HUrricane Electric Internet Services
and this:
WHOIS Lookup For IP Address 209.73.153.150:
OrgName: EGIHosting
OrgId: EGNL-1
Address: 55 S. Market St.
Address: Suite 1616
City: San Jose
StateProv: CA
PostalCode: 95133
Country: US
RegDate: 2007-07-23
Updated: 2013-04-09
Comment: http://egihosting.com
Ref: http://whois.arin.net/rest/org/EGNL-1
Nice digging there, but can you please help me retrieve my account? I paid 60$ for the founder pack recently and I wasn't planning on losing it all I didn't even reach level 60 yet
0
gibby87Member, Neverwinter Beta Users, Neverwinter Guardian UsersPosts: 0Arc User
This is why you don't try and hack an IT guy, lol! I'll be making a few phone calls on Monday, lol!
Internet tough guy! Wow, you can use WHOIS on an IP! That guy is probably using a VPN, since that IP is owned by EGIHosting.
Mature, friendly, laid back international guild. Newbie friendly. Expect banter. We have TS3 and guild bank. Must want to help other guild members out and get help in return. Message me (Walgeon@notoriouspyro) for info!
When you review the ticket that i suppose you opened you can see the email address at the bottom.
But the ticket I opened is not on the account itself, its on this different account I made to see threads and reply.
0
gibby87Member, Neverwinter Beta Users, Neverwinter Guardian UsersPosts: 0Arc User
edited May 2013
Then I think you are out of luck, the only reason I know the email that was used to hack my account is because I'm still logged in on the hacked account, namely this one.
Sadly I have to rely on the oh so awesome costumer support
And there is no way to call costumer service aswell
0
professorzMember, Neverwinter Beta Users, Neverwinter Hero UsersPosts: 0Arc User
edited May 2013
i feel for everyone of you. I have already been through this process.
Glad i have my account back now.
But there is a huge security leak somewhere.
if your email has already been changed on your account as well as the password, the only thing you can do is contact customer support.
I know that is what you dont want to hear. but is was the only way i was able to get anywhere.
I dont have such goot memories with the costumer service, last time I had to wait for a week or something.
0
perigornMember, Neverwinter Beta Users, Neverwinter Guardian UsersPosts: 6Arc User
edited May 2013
Well I got lucky, I got him like 2 minutes after he attacked. I then found that my system had 6 viruses on it! So if anyone has had their accounts hacked run Avast or better yet Combofix to remove the viruses. I spent two hours going through manually editing my registry, etc. because it turned off ALL my firewall software and viruses. The only that saved me was swift action on my part, etc.
I found that info using WHOIS and also when I reported on the PW site that I could not remember my password, PW showed me the email address it was going to. Then I saw that and quickly used the tool to change the email address back to the real one. Then I went back and changed the password so the hacker couldn't get back in. Then I had remembered that I had a free CHAMPIONS account that was linked to PW so I logged into that and then under Apps I believe I added the account guard which protects (hopefully) my other PW accounts. So I'm hoping this was enough to fix this issue.
At this point with all the BS and nonsense though with this game, I'm probably not going to play it anymore which is sad because I love it. I haven't been this excited to play something since WOW, not Star Wars, Guild Wars 2, not even Rifts. It's such a fun and simple system to play and I like the whole Foundry idea, etc. But if I'm going to have my account hacked every two weeks and PW isn't going to implement better security, combined with all the exploit nonsense then it makes it hard for me to even want to play.
Cryptic and PW totally dropped the ball here. It's a MAJOR screw-up and if they don't fix these issues no one will come back to play. I'm personally going to only comeback if they can resolve these exploits and provide us with either a phone app or a physical security key for my account protection. This whole idea of sending a password to a non-secured email quite frankly blows my mind, no company on the planet has this bad of internet protection, it's ridiculous.
Comments
Good, because they don't. I'm far from a fan of PWE, but when you attempt to change the password it sends a verification to your e-mail. Might want to check the security on all your accounts.
email: wqwaxadd1122@hotmail.com
IP address: 209.73.153.150
Computer ID: 2012-1004-
Last Time Active: May 19, 2013, 2:28 a.m.
I deleted his butt from the approved list so now they shouldn't be able to get back in.
did further digging, apparently this guy likes to hack databases using this info:
userid: moiy285md email: jimmycdf98@gmail.com
got his ISP info too:
209.73.153.150 - Geo Information
IP Address 209.73.153.150
Host 209.73.153.150
Location US, United States
City San Jose, CA 95133
Organization Enjoy Technology
ISP EGIHosting
AS Number AS18779 EGIHosting
HUrricane Electric Internet Services
and this:
WHOIS Lookup For IP Address 209.73.153.150:
NetRange: 209.73.153.128 - 209.73.153.159
CIDR: 209.73.153.128/27
OriginAS: AS18779
NetName: NET-209-73-153-128
NetHandle: NET-209-73-153-128-1
Parent: NET-209-73-128-0-1
NetType: Reassigned
RegDate: 2011-05-24
Updated: 2011-05-24
Ref: http://whois.arin.net/rest/net/NET-209-73-153-128-1
CustName: Enjoy Technology
Address: Private Customer
City: San Jose
StateProv: CA
PostalCode: 95113
Country: US
RegDate: 2011-05-24
Updated: 2011-05-24
Ref: http://whois.arin.net/rest/customer/C02762640
OrgTechHandle: LIDI-ARIN
OrgTechName: Li, Di
OrgTechPhone: +1-408-228-4448
OrgTechEmail: di@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/LIDI-ARIN
OrgNOCHandle: NOC2660-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-888-808-8806
OrgNOCEmail: noc@egihosting.com
OrgNOCRef: http://whois.arin.net/rest/poc/NOC2660-ARIN
OrgAbuseHandle: ABUSE1715-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-888-808-8806
OrgAbuseEmail: abuse@egihosting.com
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE1715-ARIN
OrgTechHandle: JJG28-ARIN
OrgTechName: Green, Joseph J
OrgTechPhone: +1-888-808-8806
OrgTechEmail: jgreen@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/JJG28-ARIN
OrgTechHandle: KTBIJ-ARIN
OrgTechName: KT, Bijoy
OrgTechPhone: +1-888-808-8806
OrgTechEmail: egni@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/KTBIJ-ARIN
OrgTechHandle: CHENJ-ARIN
OrgTechName: Chen, James
OrgTechPhone: +1-408-228-4448
OrgTechEmail: james@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/CHENJ-ARIN
# end
# start
NetRange: 209.73.128.0 - 209.73.159.255
CIDR: 209.73.128.0/19
OriginAS: AS18779
NetName: EGIHOSTING-4
NetHandle: NET-209-73-128-0-1
Parent: NET-209-0-0-0-0
NetType: Direct Allocation
Comment: http://egihosting.com
RegDate: 2011-03-04
Updated: 2012-03-02
Ref: http://whois.arin.net/rest/net/NET-209-73-128-0-1
OrgName: EGIHosting
OrgId: EGNL-1
Address: 55 S. Market St.
Address: Suite 1616
City: San Jose
StateProv: CA
PostalCode: 95133
Country: US
RegDate: 2007-07-23
Updated: 2013-04-09
Comment: http://egihosting.com
Ref: http://whois.arin.net/rest/org/EGNL-1
OrgTechHandle: LIDI-ARIN
OrgTechName: Li, Di
OrgTechPhone: +1-408-228-4448
OrgTechEmail: di@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/LIDI-ARIN
OrgNOCHandle: NOC2660-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-888-808-8806
OrgNOCEmail: noc@egihosting.com
OrgNOCRef: http://whois.arin.net/rest/poc/NOC2660-ARIN
OrgAbuseHandle: ABUSE1715-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-888-808-8806
OrgAbuseEmail: abuse@egihosting.com
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE1715-ARIN
OrgTechHandle: JJG28-ARIN
OrgTechName: Green, Joseph J
OrgTechPhone: +1-888-808-8806
OrgTechEmail: jgreen@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/JJG28-ARIN
OrgTechHandle: KTBIJ-ARIN
OrgTechName: KT, Bijoy
OrgTechPhone: +1-888-808-8806
OrgTechEmail: egni@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/KTBIJ-ARIN
OrgTechHandle: CHENJ-ARIN
OrgTechName: Chen, James
OrgTechPhone: +1-408-228-4448
OrgTechEmail: james@egihosting.com
OrgTechRef: http://whois.arin.net/rest/poc/CHENJ-ARIN
# end
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
This is why you don't try and hack an IT guy, lol! I'll be making a few phone calls on Monday, lol!
Mature, friendly, laid back international guild. Newbie friendly. Expect banter. We have TS3 and guild bank. Must want to help other guild members out and get help in return. Message me (Walgeon@notoriouspyro) for info!
But the ticket I opened is not on the account itself, its on this different account I made to see threads and reply.
And there is no way to call costumer service aswell
Glad i have my account back now.
But there is a huge security leak somewhere.
if your email has already been changed on your account as well as the password, the only thing you can do is contact customer support.
I know that is what you dont want to hear. but is was the only way i was able to get anywhere.
I found that info using WHOIS and also when I reported on the PW site that I could not remember my password, PW showed me the email address it was going to. Then I saw that and quickly used the tool to change the email address back to the real one. Then I went back and changed the password so the hacker couldn't get back in. Then I had remembered that I had a free CHAMPIONS account that was linked to PW so I logged into that and then under Apps I believe I added the account guard which protects (hopefully) my other PW accounts. So I'm hoping this was enough to fix this issue.
At this point with all the BS and nonsense though with this game, I'm probably not going to play it anymore which is sad because I love it. I haven't been this excited to play something since WOW, not Star Wars, Guild Wars 2, not even Rifts. It's such a fun and simple system to play and I like the whole Foundry idea, etc. But if I'm going to have my account hacked every two weeks and PW isn't going to implement better security, combined with all the exploit nonsense then it makes it hard for me to even want to play.
Cryptic and PW totally dropped the ball here. It's a MAJOR screw-up and if they don't fix these issues no one will come back to play. I'm personally going to only comeback if they can resolve these exploits and provide us with either a phone app or a physical security key for my account protection. This whole idea of sending a password to a non-secured email quite frankly blows my mind, no company on the planet has this bad of internet protection, it's ridiculous.