Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 13 posts ] 
Author Message
 Post subject: Runescape Fan Sites Hacked
PostPosted: October 12th, 2011, 11:18 am 
Rsbandb Donor
Offline

Joined: November 4th, 2010, 4:23 am
Posts: 167
Location: Ohio, U.S. us
RS Name: TheLion
RS Status: P2P
At least two Runescape fan sites have been hacked in the past week. RuneHQ was hacked a week ago and now Tipit was hacked yesterday Oct 11. If you have any accounts with those or other fansite's you should reset your passwords ASAP (especially if you’re crazy enough to use the same password for your main runescape account!)

It may just be coincidence, but it's odd how the tip-it hack happened the same day the tip-it site was mentioned in Jagex's news update titled "Update on our ongoing battle against bots"

http://services.runescape.com/m=news/up ... -battle-against-bots .


Top
 Profile  
 
 Post subject: Register and login to get these in-post ads to disappear
PostPosted: October 12th, 2011, 11:18 am 
Rsbandb Donor

Joined: September 9th, 2004, 1:47am
Posts: 9047
Location: In your web browserz


Top
  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 12th, 2011, 12:10 pm 
Rsbandb Donor
Offline

Joined: October 13th, 2005, 9:18 pm
Posts: 3366
Location: USA us
RS Name: Duke Juker
RS Status: P2P
Clan Name: Clan Quest
Nope. Just an RSBandB person. I don't think I ever made an account on the others. I used to use some of their databases, but since I rarely play Runescape anymore, I have no use for them. The calculators here are about the only things I really need if I ever play. It is odd they got hacked. Not sure it had anything to do with the update on botting.

_________________
Image
RSBANDBInformer! Gaming Writer: 08/31/2011-09/30/15
RSBandB Donor since 07/01/2010
82nd Dragon Member since 05/12/2010
RSBandB Member #517
Current Activities: Ports, Dailies/Monthlies, DXP
Skill Masteries: Firemaking, Cooking, Woodcutting, Fletching, Mining, Agility, Prayer, Smithing, Fishing, Summoning, Construction, Herblore, Hunter, Thieving, Crafting, Divination, Dungeoneering, Farming, Runecrafting, Slayer, Magic, Ranged, Defence, Constitution, Attack, Strength, Invention & 1st Max (3/9/19), Archaeology & 2nd Max (4/16/21), 200m Firemaking, Necromancy


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 12th, 2011, 12:29 pm 
Site Owner
User avatar
Offline

Joined: September 9th, 2004, 7:39 pm
Posts: 3498 ca
RS Name: mike12088
RS Status: P2P
Clan Name: Bits and Bytes
Runehead and Draynor were hit a little while ago too I believe.

It's always a good idea to use different passwords on every site. Most sites should be storing their passwords in an irrecoverable hash, but if your password is weak, that wont protect you in the case of a sites database being stolen.


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 12th, 2011, 1:28 pm 
Mithril Member
Offline

Joined: May 14th, 2011, 1:38 pm
Posts: 127
Location: Indiana us
RS Name: Ablazin Scar
RS Status: P2P
Clan Name: Ablazin cc
Not sure if I had accounts, I know I've been to both sites. Changed pass.

_________________
Image

Image[/center]


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 12th, 2011, 4:07 pm 
Iron Member
Offline

Joined: July 10th, 2009, 8:23 am
Posts: 24 us
RS Name: Grquartzds
RS Status: F2P
Clan Name: Party Pete's People
Glad I use different passwords on all my accounts anywhere. But this would explain why the amount of phishing emails I get has doubled again. It doubled once when RuneHQ got hacked, then it suddenly doubled again. I was hoping Tip.It wasn't hacked, but now I find out it is :(

I just hope Tip.It doesn't wipe all their forum archives and delete all users, like RuneHQ did. It's bad enough to lose one forum I frequent :?

I'm kinda getting worried that they'll hit all the forums I use (this forum is one of five, and it seems two have been taken down already :cry:). Forums are practically the only thing keeping me tied to RS at this point; once all big RS forums are down I won't have anything to motivate me to play anymore.

What sucks is if they attack Zybez, they'll also end up taking Minecraft's forums down in the process (shared server - Zybez was shut down the last time Minecraft got attacked too). Then where the hell am I gonna go? #-o

_________________
Image


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 12th, 2011, 6:35 pm 
Community Ambassador
Offline

Joined: June 28th, 2011, 1:01 am
Posts: 319 us
RS Name: Lord Rickles
RS Status: P2P
Runehead was hacked twice maybe three weeks ago. It was so severe that most of the clan memberlists were altered, having the name of their clan and website listed changed to a site with a key logger. It was extremely troublesome, because Runehead has a wait time to change your clan name, so we all had to put up with the fake names for a week. -.-


Top
 Profile  
 
 Post subject: Register and login to get these in-post ads to disappear
PostPosted: October 12th, 2011, 6:35 pm 
Community Ambassador

Joined: September 9th, 2004, 1:47am
Posts: 9047
Location: In your web browserz


Top
  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 13th, 2011, 12:22 am 
Site Owner
User avatar
Offline

Joined: September 9th, 2004, 7:39 pm
Posts: 3498 ca
RS Name: mike12088
RS Status: P2P
Clan Name: Bits and Bytes
WolfieMario wrote:
I just hope Tip.It doesn't wipe all their forum archives and delete all users, like RuneHQ did. It's bad enough to lose one forum I frequent :?

I'm kinda getting worried that they'll hit all the forums I use (this forum is one of five, and it seems two have been taken down already :cry:). Forums are practically the only thing keeping me tied to RS at this point; once all big RS forums are down I won't have anything to motivate me to play anymore.


That's kind of strange they'd call all the posts by their users junk and wipe the forums making everyone re-register.

If it's any consolation, RSBandB isn't going anywhere. We're a small community but Shane and I have spent a lot of time on security and if we do manage to somehow get hacked, we have regular backups.


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 13th, 2011, 1:12 am 
Rsbandb Donor
Offline

Joined: November 4th, 2010, 4:23 am
Posts: 167
Location: Ohio, U.S. us
RS Name: TheLion
RS Status: P2P
Mike wrote:
If it's any consolation, RSBandB isn't going anywhere. We're a small community but Shane and I have spent a lot of time on security and if we do manage to somehow get hacked, we have regular backups.


I'm not the least bit worried about RSBandB's site. I have the utmost confidence in you guy's ability to run a secure site.

Anyone have any theories as to who is behind these hacks? Could it be people attempting to steal users info, for the purpose of wiping out their runescape bank, or perhaps maybe hackers backed by the botting community attempting to "punish" sites who support legit runescape players.

I don't generally visit too many other forums on non-runescape websites, so I don't know how common it is for them to get hacked, but it does seem like somone or some group out there has an agenda.


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 13th, 2011, 1:37 am 
Runite Member
Offline

Joined: September 25th, 2010, 5:08 pm
Posts: 323 us
RS Name: Jamandy52
RS Status: P2P
Clan Name: 1elitesc / Jamandy52
Thanks for the info. Lucky for me I keep my rs account secure and use different passes everywhere. :)

_________________
Image Image
http://www.youtube.com/user/Jamandy52?feature=watch ~The Youtube of the Jamandy52


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 13th, 2011, 10:40 am 
Cleverly Disguised Spammer
User avatar
Offline

Joined: December 17th, 2004, 12:03 pm
Posts: 10901
Location: Anglia europeanunion
RS Name: Piratesock
RS Status: P2P
Clan Name: The Mushroom Pirate Federation
Doesn't surprise me about RuneHQ. They've never had any respect for there users and always flown off the handle at the smallest little thing. :]

Our site was down earlier. Any relation to this or was it something else? It was only down briefly.

_________________


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 13th, 2011, 9:03 pm 
Iron Member
Offline

Joined: July 10th, 2009, 8:23 am
Posts: 24 us
RS Name: Grquartzds
RS Status: F2P
Clan Name: Party Pete's People
thelion777 wrote:
Anyone have any theories as to who is behind these hacks? Could it be people attempting to steal users info, for the purpose of wiping out their runescape bank, or perhaps maybe hackers backed by the botting community attempting to "punish" sites who support legit runescape players.

I don't generally visit too many other forums on non-runescape websites, so I don't know how common it is for them to get hacked, but it does seem like somone or some group out there has an agenda.

I don't think botters or bot sites would put the effort into taking down sites that are anti-bot.

First, players who bot to play the game aren't really as effected by Jagex's methods as the gold-farming bots are. The gold-farming bots tend to be the most obvious, and simultaneously the least important to those who run them, and I can't quite see a major gold-farming group going through the effort of taking down anti-bot fansites. Even if that effort did somehow help bot farmers, it would end up helping all bot farmers, and the time and effort needed for the hacking would have likely been better spent on them improving their own bots and watching their competition fail.

Second, I don't think players that bot honestly hate or give a **** about anti-bot players. I've made a video which directly complains about bots, and it's been shared on several bot sites (YouTube tells me where my vids get views from). The people there actually enjoyed it and couldn't care less for my anti-bot attitude. Hell, some of them even came to my video and commented or subscribed, when I make it pretty clear I'm sick of what bots have done to the game.
So if it was indeed botters who had RuneHQ and Tip.It taken down, it was most likely for the lulz, not for any hatred or "punishment".

I'm betting this actually has little to do with bots, and more to do with scammers, hackers, and phishers. As a result of these two hackings, the amount of RS-related phishing spam I get in my email has quadrupled. I'm pretty sure passwords and recovery hints are exactly what they're after, and I don't think the timing of the newspost on botting has much to do with Tip.It's hacking (I imagine, depending on how they attacked Tip.It, that planning and preparing the attack would have taken more than just a single day... This obviously wasn't just a simple DDoS, or Tip.It would have come back by now.)

_________________
Image


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 14th, 2011, 3:46 am 
Dragon Member
User avatar
Offline

Joined: December 27th, 2004, 2:17 am
Posts: 2883
RS Name: Southrend
RS Status: Classic
Lord Rickles wrote:
Runehead was hacked twice maybe three weeks ago. It was so severe that most of the clan memberlists were altered, having the name of their clan and website listed changed to a site with a key logger. It was extremely troublesome, because Runehead has a wait time to change your clan name, so we all had to put up with the fake names for a week. -.-


Well that could explain how others site could be "hacked". Most hacks happen because people use the same password for multiple websites. So if you're able to redirect people to a keylogged website and you catch their password you can cause a lot of trouble. Especially if you find a password of someone important, let's say a different site owner.

_________________
Image
Proud RSB&B Member #570 since 12/27/04
Proud RSB&B Mod since 7/24/05


Top
 Profile  
 
 Post subject: Re: Runescape Fan Sites Hacked
PostPosted: October 14th, 2011, 2:32 pm 
Iron Member
Offline

Joined: July 10th, 2009, 8:23 am
Posts: 24 us
RS Name: Grquartzds
RS Status: F2P
Clan Name: Party Pete's People
Southrend wrote:
Lord Rickles wrote:
Runehead was hacked twice maybe three weeks ago. It was so severe that most of the clan memberlists were altered, having the name of their clan and website listed changed to a site with a key logger. It was extremely troublesome, because Runehead has a wait time to change your clan name, so we all had to put up with the fake names for a week. -.-


Well that could explain how others site could be "hacked". Most hacks happen because people use the same password for multiple websites. So if you're able to redirect people to a keylogged website and you catch their password you can cause a lot of trouble. Especially if you find a password of someone important, let's say a different site owner.

RuneHQ said their hacking was due to an exploit of some old, outdated code in their system, not someone cracking the admin's password.

_________________
Image


Top
 Profile  
 
Display posts from previous:  Sort by  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Jump to: