Loading. Please Wait... 
 |
 |
 |
My Account was hacked and lost everything |
|
Jan 8 2018, 09:21
|
reisherry
Newcomer
 Group: Recruits
Posts: 10
Joined: 28-June 13

|
(IMG:[ i.imgur.com] https://i.imgur.com/XZCfn7k.png) This is not me ,from 2018-1-7 My Account was hacked
Is there any admin can help me get the GP ,hath and credits back? this is urgent I just change my password
and what is message #1895422 Can admin check this message go to which account and ban that guy?
Please help!!This post has been edited by reisherry: Jan 8 2018, 17:48
|
|
|
Jan 8 2018, 09:52
|
Drksrpnt
Group: Gold Star Club
Posts: 3,551
Joined: 27-December 10

|
Go into hentaiverse and check your mooglemail log, it should say who the credits were sent to.
|
|
|
Jan 8 2018, 10:00
|
reisherry
Newcomer
 Group: Recruits
Posts: 10
Joined: 28-June 13

|
QUOTE(Drksrpnt @ Jan 8 2018, 17:52)  Go into hentaiverse and check your mooglemail log, it should say who the credits were sent to.
I cant access to mooglemail ,safety lockdown since that guy send the credits out.
|
|
|
Jan 8 2018, 10:04
|
Drksrpnt
Group: Gold Star Club
Posts: 3,551
Joined: 27-December 10

|
If you're logged in on e-hentai, you should be able to access the hentaiverse too, it's just https://hentaiverse.org/
|
|
|
Jan 8 2018, 12:03
|
mozilla browser
Group: Gold Star Club
Posts: 2,131
Joined: 22-December 11

|
doesn't help you, but in order to understand how the hack happened...
Did you have a poor / easily guessable password?
Was your computer or email hacked?
What else was done? Did your email / password get changed by the hacker, or did you do it yourself after you found out about the hack?
|
|
|
Jan 8 2018, 12:17
|
EsotericSatire
Group: Catgirl Camarilla
Posts: 12,664
Joined: 31-July 10

|
Where did you get the credits from?
Did you give your details to anyone or use any apps?
Shared account?
Its not one of the olde accounts from before lottery was fixed?
|
|
|
Jan 8 2018, 13:48
|
Tenboro

|
The account lockdown was manually applied, and is not because the email or password was changed. The accounts that received the items were all terminated before the items could be fenced.
Yours was one of 16 accounts affected, and due to its nature I believe they were session hijacks rather than the actual password being compromised. In other words, you were likely compromised by using a malicious script, or using an insecure proxy/VPN/shared environment. You might be able to shed some light on which of those that could have been?
|
|
|
|
 |
|
Jan 8 2018, 13:58
|
reisherry
Newcomer
 Group: Recruits
Posts: 10
Joined: 28-June 13

|
QUOTE(mozilla browser @ Jan 8 2018, 20:03)  doesn't help you, but in order to understand how the hack happened... Did you have a poor / easily guessable password? Was your computer or email hacked? What else was done? Did your email / password get changed by the hacker, or did you do it yourself after you found out about the hack?
easily guessable password : well...yes, sometime said the easy one is harder to guess, maybe not this time (IMG:[ invalid] style_emoticons/default/anime_cry.gif) no email hacked, fortunately QUOTE(EsotericSatire @ Jan 8 2018, 20:17)  Where did you get the credits from? Did you give your details to anyone or use any apps? Shared account? Its not one of the olde accounts from before lottery was fixed?
give/share no one....only i know , tell no friend about my account
|
|
|
|
 |
|
Jan 8 2018, 14:14
|
reisherry
Newcomer
 Group: Recruits
Posts: 10
Joined: 28-June 13

|
QUOTE(Tenboro @ Jan 8 2018, 21:48)  The account lockdown was manually applied, and is not because the email or password was changed. The accounts that received the items were all terminated before the items could be fenced.
Yours was one of 16 accounts affected, and due to its nature I believe they were session hijacks rather than the actual password being compromised. In other words, you were likely compromised by using a malicious script, or using an insecure proxy/VPN/shared environment. You might be able to shed some light on which of those that could have been?
I think its a hijack...although I don't know how it works not sure about malicious script ,I'm going to find something to scan my computer and browser completely. Use no VPN ,no share network ,the LAN is personal use
|
|
|
|
 |
|
Jan 8 2018, 15:56
|
b923242
Newcomer
 Group: Members
Posts: 40
Joined: 20-August 13

|
Having the same problem. All my GP had changed to Credit by the hijacker and transmitted. (IMG:[ invalid] style_emoticons/default/cry.gif) (IMG:[ i.imgur.com] https://i.imgur.com/ytrGUzU.png) I wonder this will affect my HentaiAtHome Cilent as well. I believe the support team will do the justice for me. However I would like to know beside from changing the password, what should I look out for to prevent this from happen again?
|
|
|
|
 |
|
|
 |
|
Jan 8 2018, 17:25
|
@43883
Group: Gold Star Club
Posts: 31,486
Joined: 6-March 08

|
I see a pattern here... Don't trust Chinese scripts or sites. If you see a funny post in the Chinese thread of diminishing quality or get a PM giving you access to some cool script, immediately report it. Watered down list: a) Never use plugins or scripts you can't check yourself. If you plan to use that, check source code, run in [ en.wikipedia.org] sandbox. If you don't know code, learn. b) Check device for malicious software. If found, secure device. If device cannot be secured, nuke from orbit. c) Check browser for [ www.cvedetails.com] vulnerabilities. Not exhaustive because publicly known list, but tells you what you should never use. d) Check account for vulnerabilities. If you use home device, make sure you have [ en.wikipedia.org] interesting data somewhere, with the real thing very unlikely to be targeted. e) Check network for vulnerabilities. Have it raped on purpose and see how ISP/VPS host/VPN host/proxy fares. Always keep an eye on net logs. f) Check servers for vulnerabilities. If you suspect there is 1+, you know what to do. Don't disclose publicly, no section is restricted. Ever. Post compression algorithm courtesy of AntiVerboseJoe. Thanks Joe! This post has been edited by AgentLillian: Jan 8 2018, 17:26
|
|
|
|
 |
|
Jan 8 2018, 18:00
|
WatermelonJuice
Group: Gold Star Club
Posts: 2,220
Joined: 20-April 13

|
My account is also affected. Most of my stuffs were sent through moogle mail. I've changed my password and I didn't use any proxy or VPN. Easily guessed password... maybe not? Of length 10 and consists numbers and alphabets, and the alphabets does not form a word in dictionary. I don't think it's brute force attack.
The only thing I can come up with it the password it used in other sites. And some of the sites were hacked, with the passwords were stolen. (Maybe weakly encrypted?) So someone try the password here.
|
|
|
|
 |
|
Jan 8 2018, 18:10
|
NekoHime27
Group: Catgirl Camarilla
Posts: 10,795
Joined: 9-July 11

|
QUOTE(w45451212 @ Jan 9 2018, 00:00)  The only thing I can come up with it the password it used in other sites. And some of the sites were hacked, with the passwords were stolen. (Maybe weakly encrypted?) So someone try the password here.
Nah that'd be too much of a coincidence for that many people to be affected.
|
|
|
Jan 8 2018, 18:12
|
Tenboro

|
QUOTE(chung2795 @ Jan 8 2018, 16:19)  You guys sure it's not a security breach? (IMG:[ invalid] style_emoticons/default/laugh.gif) A breach limited to 16 Chinese accounts, with no indication of login attempts or password/email resets? Absolutely. My money is on some kind of script or plugin with a malicious payload, that either had limited distribution or that was posted in a Chinese forum.
|
|
|
|
 |
|
Jan 8 2018, 18:31
|
WatermelonJuice
Group: Gold Star Club
Posts: 2,220
Joined: 20-April 13

|
QUOTE(Tenboro @ Jan 9 2018, 00:12)  A breach limited to 16 Chinese accounts, with no indication of login attempts or password/email resets? Absolutely. My money is on some kind of script or plugin with a malicious payload, that either had limited distribution or that was posted in a Chinese forum.
May I ask that what's wrong with the lockdown? I change my password at about 16:00 p.m. Jan 7th UTC+8. The lockdown will be over at 16:00 p.m. Jan 8th UTC+8. But by the time, it showed it will be over at about 3:00 a.m. Jan 9th UTC+8. And now it shows that QUOTE Account is in safety lockdown due to an email or password change - lockdown is lifted in 19 hours and 38 minutes
Why the lockdown time can increase? (IMG:[ invalid] style_emoticons/default/blink.gif)  Edit: Oh, I see the mail now... This post has been edited by w45451212: Jan 8 2018, 18:48
|
|
|
|
 |
|
Jan 8 2018, 18:34
|
@43883
Group: Gold Star Club
Posts: 31,486
Joined: 6-March 08

|
The lockdown limited to all 16 Chinese accounts was manual as stated above.
Don't visit dodgy Chinese forums and stop playing the HentaiVerse. The minigame is bad for your health if you can't manage.
|
|
|
Jan 8 2018, 18:36
|
beatmario
Newcomer
 Group: Gold Star Club
Posts: 48
Joined: 27-January 14

|
Many of us didn’t know each other. The BIG BROTHER is watching us?
|
|
|
|
 |
|
Jan 8 2018, 18:37
|
WatermelonJuice
Group: Gold Star Club
Posts: 2,220
Joined: 20-April 13

|
QUOTE(AgentLillian @ Jan 8 2018, 23:25)  I see a pattern here... Don't trust Chinese scripts or sites. If you see a funny post in the Chinese thread of diminishing quality or get a PM giving you access to some cool script, immediately report it. Watered down list: a) Never use plugins or scripts you can't check yourself. If you plan to use that, check source code, run in [ en.wikipedia.org] sandbox. If you don't know code, learn. (IMG:[ invalid] style_emoticons/default/cool.gif) Check device for malicious software. If found, secure device. If device cannot be secured, nuke from orbit. c) Check browser for [ www.cvedetails.com] vulnerabilities. Not exhaustive because publicly known list, but tells you what you should never use. d) Check account for vulnerabilities. If you use home device, make sure you have [ en.wikipedia.org] interesting data somewhere, with the real thing very unlikely to be targeted. e) Check network for vulnerabilities. Have it raped on purpose and see how ISP/VPS host/VPN host/proxy fares. Always keep an eye on net logs. f) Check servers for vulnerabilities. If you suspect there is 1+, you know what to do. Don't disclose publicly, no section is restricted. Ever. Post compression algorithm courtesy of AntiVerboseJoe. Thanks Joe! I believe that some Chinese sites are hacked. Otherwise, those vulnerabilities may also apply to others from different region. I've keep the browser up to date. If there's a 0day vul, the bad guy can do other things more meaningful, rather than steal credits and stuffs from HV. My equipments were taken off. Why did someone try to make me nude? (IMG:[ invalid] style_emoticons/default/mad.gif)
|
|
|
|
 |
|
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:
|
 |
 |
 |
|
|
|