EQ Servers Hacked

According to the Seattle Times, last October someone hacked into at least one EQ server, as well as Brad McQuaid's home computer, and obtained a superuser account and other account information. The article states that "'Access to these accounts gives the superuser an individual's name, date of birth, work and home telephone numbers, Internet protocol address and other information,' including home addresses, according to an affidavit filed with the warrant. Moreover, superuser status also 'enables the user to have complete administrative controls over the game, including the suspension, banning and unbanning of accounts.'" Furthermore, it states "In McQuaid's computer, the hacker copied a voluminous file containing the blueprint for the release of the game's next version, 'EverQuest2,' scheduled for release next year. Other personal and proprietary information was also accessed." Interesting news, considering that the existance of any Everquest 2 has never been officially confirmed by Sony. The only official statement I have seen from Sony is in the Developer's Corner where John Smedley posted this: "We have seen the article in the Seattle Times regarding an incident almost a year ago in which someone apparently got a hold of one or more superuser accounts for a short period of time. We want to assure our customers that at no time was any consumer billing information compromised. No one should be worried that their credit card information got out… IT DID NOT. In addition, some time ago we added additional layers of security in an effort to prevent this from happening again. Beyond this, it is inappropriate for us to comment in light of the ongoing investigation." I am not a computer expert, so I can't even begin to speculate on this. There are far more qualified people than me to do that, so I'll let it to you to debate the consequences, or whether you should at least change your password. You can read the entire article at this link.

Comments

« Previous 1 2
Post Comment
eq2
# Apr 16 2002 at 6:30 AM Rating: Default
LOL All I have to ssay is Hell yes about an EQ 2.. gimme gimme!
Billing Hacks
# Nov 30 2003 at 10:19 AM Rating: Default
Hey ppl, i have a question. is there any hack/cheat/code that kan ***** the system so that u dont have 2 pay $9.99 pre month?
Magic?
# Apr 15 2002 at 8:11 PM Rating: Default
Any one here play magic LOL!!! (MTG)
Changing the subject? why not
my acct was stolen please help me
# Apr 09 2002 at 5:18 PM Rating: Default
if u can help me get my account back i9ll give u alot of stuff the accounts on diablo that were stolen are poopooma and moaningsouls plz help there are great rewards hacks wanted for help on getting my accounts back
RE: my acct was stolen please help me
# Apr 09 2002 at 5:23 PM Rating: Default
my accounts on diablo 2 expansoin were stolen there are great rewards if u get my accounts back the accounts are poopooma and moaningsouls hackers wanted for help please i really want my accounts back before the next 2 mounths are over or else theyll disappear if u find out the passwords for either of the accounts email me on diablo 2 expansoin at hellboy9 4:30-8:00 during the week and early morning like 11 - 9 o clock in the afternoon thanks alot and see ya
I am so happy I surfed by and saw this...
# Dec 26 2001 at 11:02 PM Rating: Default
I quit playing EQ because the morons at Sony deleted 2 friends accounts because they said they were "compromised". Since they no longer had their original CD from 2 years ago, they were told to take a hike as it was their problem for allowing someone to hack their PC. Sony, in all of their infinite wisdom, decided that any account that had been hijacked(password altered so paying customer could not access it any longer), was a result of that customer sharing his/her password with another player. What a joke, now that I read this. Verant and Sony should be ashamed, they were obviously aware of the timing of this theft, and allowed these people to suffer great personal loss due to their cavalier attitude.

I stopped playing because I was issued a verbal account key when I loaded the original game as the one on my CD was invalid. Sony would not provide me with that information, and if my account was similarly kijacked, it would be deleted. Let them deny as I am certain they will, but I spent 2 hours on the phone with these folks, Frank Burns would be proud of them...
End All
# Oct 23 2001 at 10:32 AM Rating: Default
Reguardless...
The US liability laws, you are only Liable for $50... If you have reported your card stolen... This includes Internet fraud or theft of the slips from the knuckle busters they run credit cards on from the pre-magnetic strip era.
So when they try to sell you insurance on your Credit cards and Debit cards... they are full of crap and trying to milk you. (My x-father in law was a district manager for Hells Fargo, greedy bastards)

Firewalls...
All routers and most firewalls have a special passwords that allows access by the companys that produced them. An accociate of mine had a router that wasn't working properly and the Tech at the manufaturers accessed it remotly and tried some settings. Without us giving him the access information or passwords. It was a last resort move for them but they have the service access there. (They still had to ship a new router...)

I have heard rumors the Brad has left for greener pastures. Some say personal reasons, some said it was a falling out about the direction the game was going? (I would have loved to have been a fly on the wall for that one.)

If you don't know who he is... He's one of the people who started this whole EQ ball rolling and was part of the origional creation of the game. For him to leave has ramifications that are yet to be seen (If the rumor is true)
RE: End All
# Sep 18 2003 at 11:24 AM Rating: Default
OMG so you could get a credit card with $5 stolen, you get a free $45? bonus! i am moving to the USA now!
End All
# Oct 23 2001 at 10:32 AM Rating: Default
Reguardless...
The US liability laws, you are only Liable for $50... If you have reported your card stolen... This includes Internet fraud or theft of the slips from the knuckle busters they run credit cards on from the pre-magnetic strip era.
So when they try to sell you insurance on your Credit cards and Debit cards... they are full of crap and trying to milk you. (My x-father in law was a district manager for Hells Fargo, greedy bastards)

Firewalls...
All routers and most firewalls have a special passwords that allows access by the companys that produced them. An accociate of mine had a router that wasn't working properly and the Tech at the manufaturers accessed it remotly and tried some settings. Without us giving him the access information or passwords. It was a last resort move for them but they have the service access there. (They still had to ship a new router...)

I have heard rumors the Brad has left for greener pastures. Some say personal reasons, some said it was a falling out about the direction the game was going? (I would have loved to have been a fly on the wall for that one.)

If you don't know who he is... He's one of the people who started this whole EQ ball rolling and was part of the origional creation of the game. For him to leave has ramifications that are yet to be seen (If the rumor is true)
A Bit of Verant's Lies Coming Back to Haunt 'em
# Sep 10 2001 at 2:50 AM Rating: Default
Verant would swear up and down for the last few year that any account hacking was OUR fault. As we can see this just isn't the ONLY reason for us getting hacked.
Invisible Bob
# Sep 04 2001 at 10:38 PM Rating: Default
Who what when where why are we asking why asking who asking where asking when asking what its all one big mess. Just remember if its not something thats hurt you then dont let it bother you. Stress makes you old, chill and be groovy.
LOL
# Sep 04 2001 at 4:03 PM Rating: Good
It happened a year (or more) ago. The fun is over. No need to worry about that particular instance at this point, so more on to other things!

And as far as obtaining information (ie. Credit Card, etc.) Go shopping at local stores. If you use a credit card, it's being swiped. Some smaller ones may even just manually run it through a machine. Copies are still kept with complete numbers and exp. dates. I worked for a HUGE retail chain that printed out complete card numbers and exp dates on ever receipt! Talk about easy access to information! "Yes, I'd like to order that $3000 television, and deliver it to the Fed Ex. place... I'll pick it up from there"

This can and does happen.

I wouldn't worry so much about Verants handling of our information, but moreso the local places and smaller internet shops that really can't afford big buck security systems. And ALWAYS review your bills. You WILL find problems with them at some point or another.

Be safe.
EQ2
# Sep 04 2001 at 11:06 AM Rating: Default
There will be a EQ2 for those of you who do not know SoL's new look is just a testing group for the new engine to make sure all bugs are worked out there been many statements from the dev. team to this fact...
Everquest 2
# Sep 04 2001 at 10:22 AM Rating: Default
WHY would you guys think they would get rid of Everquest.. look at shadows of Luclin. they are giving the game a new look. adding new zones, new class and race, and new items.. this is called a "NEW GAME" in most worlds. yes some of the zones might be the same but in actuallity it will be a whole new game if you think about it. So I doubt they will officially make a new everquest. they might make another game, but NOT LIKE EVERQUEST, they might make Star wars Galaxies, but that is not the same as a EVERQUEST, so everyone stop complaining enjoy the game and if I am wrong, oops.
#Anonymous, Posted: Sep 04 2001 at 9:53 AM, Rating: Sub-Default, (Expand Post) What is up my homies!!! EQ ROCKS!!! LET EQ NEVER DIE!!! NO SPLIT GAME BETWEEN EQ1 and EQ2!!! EXPANSIONS ONLY ROCKS!!!
#Anonymous, Posted: Sep 04 2001 at 9:17 AM, Rating: Sub-Default, (Expand Post) This is a simple question...Who is your DADDY!!!!!!!!!!!??????
This Was HOW LONG AGO???
# Sep 04 2001 at 1:35 AM Rating: Default
I have a couple of simple questions??
1=How long ago was this Hack in supposed to have happened? A year or more now!
2=How many ppl have had there accounts messed up over this? I haven't heard of any so do me a favor and quit whinning over it!

Thanks and have a nice life =)
RE: This Was HOW LONG AGO???
# Dec 04 2001 at 4:27 PM Rating: Default
Actually, you pry haven't heard of any accounts being harmed because you don't have any inside info...how do you know that they didn't happen to grab a few accounts while they were hacked in. If you were on Brad's computer and had access to everything (And you were in evil person that would do this type of thing)...would you just find out that there is eq 2...no...you'd try to get as much stuff as possible (Including accounts)
And it may have happened a year ago, but that does not mean it's safe now. I'm not gonna sit in a corner worried about being hacked (has already happened to me)...I'm just pointing out that things aren't as safe as you may think *sept 11 just proves what I mean* Course when my account was hacked, "You must have given it out to another person, therefor, I must ban you for a minimum of 1 week." So it couldn't have been a hacker. Anyway...as far as eq 2, who cares, it'll pry just be a newer version that they want us to continue to buy, kinda like SoL, SoV, Kunark, etc...and if they don't expand it from the current version (including char's), they will pry lose a lot of players, no matter how damn good it is.

Well, thanks for reading my HUGE oppinion...later
whos brad anyway
# Sep 03 2001 at 10:26 PM Rating: Default
whats the big deal and who the heck is brad and who cares?
#Anonymous, Posted: Sep 03 2001 at 9:33 PM, Rating: Sub-Default, (Expand Post)
#Anonymous, Posted: Sep 03 2001 at 9:33 PM, Rating: Sub-Default, (Expand Post)
Hacker Motives
# Sep 03 2001 at 3:27 AM Rating: Default
Why would a hacker specifically target you. TO cause Major havoc and make a nightmare for Verant and EQ. if alot of player accounts are deleted or mess with.
Truth?? NOT
# Sep 02 2001 at 2:20 PM Rating: Decent

This is utterly unfeasable as a news article, anybody who plays the game of everquest will know, or at least seriously doubt the validity of this article. My statement originates from one simple fact.

"Everquest 2" we are obviously dealing with a newsreporter who has never played this game to understand that at the time of this articles writing, everquest could already be referred to as the 4th or even 5th edition of the game with the patchwork and advancements and enhancements done in game by Verant.

When the reporter makes the statement of "everquest 2", he is making a presumption that this game is like Ultima Online, or Diable, etc. Where the manufacturers of the game, to make more money, issue "updated" retail versions of the game, which completely changes the style and playing of the game itself. This reporter obviously never did his research as to how uniquely different this game of Everquest is compared to other products in the market of video games. Especially at the time of the article, consider, Ashron's Call was the first "copycat" style of this type of gaming.

To me, with the sensationalism that the "press" has a fondness of emphasizing to get a reader's/viewer's/listener's attention to pay attention to their form of reporting of information. We have a reporter who wrote an article based on presumptions on the video game market for PC's and not facts directly related to the game of Everquest.

Because of that reporter's interest in getting an article printed to get paid, he took a very uproveable rumor of somebody "hacking" into one person's computer and embelished it with, to the non initiated of this game, with industry standard tidbits of information of the pc gaming market, to make it sound feasable to an editor.

The whole article to me, should seriously be considered a large part fabrication of poorly informed reporter who acted on a very small and unsubstantiated tidbit of information.

Dreamchase
40th level wizard on Xegony
#Anonymous, Posted: Sep 02 2001 at 5:44 PM, Rating: Sub-Default, (Expand Post) Bah you say verant isnt out for money but i find that extremely hard to believe when they start to pull crap like the Loot Rules in the warrens and the Stonebrunt mountians so that only low lvl ppl can do anything there this is just an example. even though EverQuest is a well made and Good Game they are out for money.
RE: Truth?? NOT
# Sep 07 2001 at 8:56 AM Rating: Decent
Lol! ***** loot rules...

$50 for a naked character transfer that takes about 3 command lines to process? That's some major cash-grabbing there.
RE: Truth?? NOT
# Sep 02 2001 at 4:22 PM Rating: Decent
*
69 posts
Did it ever occur to you, or to anyone else who has questions about "EverQuest2" that SoL had to be called something before it was called SoL? This did happen over a year ago...
RE: Truth?? NOT
# Sep 02 2001 at 9:09 PM Rating: Decent
Actually, SoL was nicknamed EQ 1.5 by designers up until it was SoL. I think I read that somewhere, maybe here. This makes me think. Are they planning that far ahead?! Wow! Everquest 2 is probobly another expansion, and not a seperate EQ though.
RE: Truth?? NOT
# Sep 07 2001 at 1:19 PM Rating: Decent
I would have to guess another expansion, myself. Possibly one involving the aviaks? Perhaps another continent of mostly rough, mountainous terrain, with a few plateaus for cities?

/shrug

Just a guess...
RE: Truth?? NOT
# Sep 02 2001 at 10:53 PM Rating: Decent
Well I have talken to the Verant team personaly before the release of Kunark, And there statements to the Future of Eq2 was that EQ2 is more a vision of What EQ will be like years down the road. I would think that maby EQ2 is the nickname for the 6th continent and last one on the world of Norath (it does exist and will allow circumnavigation check out the globes on skyshrine for a preview look at this continent) EQ2 if it is a new game all together and not a patch or expansion i feel would be a bad idea. Looking at it from a money making standard it would be a waste to create a whole new game and then abadon one that has been around for 3years. The player base will have trouble moving to a new game which would have to be purchased seperatly and then go about exploring and starting over from scratch. I doubt many players who have spent so much time on EQ would gladdly give it up for something new and fresh. Now if they do do this what would happen to EQ. I do not think running 2 EQ games would work and what are they going to do about continuing EQ's dyanmic world (completly give it up and stop updating it?) I pray that this EQ2 is just a nickname for a new expansion. besides looking at the new graphics of SOl i Would think that maby they plan on redoing all of eq to look that clean at least i hope they do.
everquest 2
# Sep 02 2001 at 7:52 AM Rating: Default
It would be incredibly stupid to put out an everquest 2 unless it was somehow attached to the first everquest. You dont want to break up the users into to different games here. Just come out with lots of expansions to make the EQ world big with an even more enjoyable game!!
FREE FIREWALL
# Sep 01 2001 at 11:04 PM Rating: Default
ZONEALARM peoples,a great FREE firewall. zonealarm.com, it is a must.
Long live Seattle!
# Sep 01 2001 at 5:13 PM Rating: Default
here in this peaceful little, I mean big, town, i mean city, live many Computer companys. Webvan (dead), Microsoft (almost dead hahaha) and etc. It is only expected that soon we will destroy you all! *twitch* Sorry bout that, need my pills!
Internet Safety & Our Privacy
# Sep 01 2001 at 4:52 PM Rating: Decent

First let me start by saying internet fraud is my professional specialty. Preventing it and putting offenders behind bars, that is. I enjoy my job, yet sometimes get dismayed when something like this happens and gets exposed.

Let's assume Brad's computer was "hacked" (I hate that word, but it's still in vogue) by this teen in Snoqualmie and the suspect in Alabama. These people then used superuser access to look at the company private message board as well as fiddle with their own accounts (and possibly others.) How could this have happened at what are the chances our private credit card information could have been compromised?

For the how part, my own personal experience has been that over 90% of all break ins that pass firewalls are due to a lapse on the part of the victim regarding emails and files, 9% or so involve "inside jobs" where people who work with the company help the breakin attempt and about 1% involve true "cracking" of a system. I'd rule out inside job as the suspects are in different states, and concentrate on the 90% chance of a personal lapse.

Brad's a nice guy, loves his work, and has a legion of fans in the gaming community (and detractors as well, but let's think of fans.) I'd venture to guess with his love for EQ he spends as much of his "off work" time playing with the game and working on new stuff as his "work time." This would require a nice broadband access system for his home computer, probably VDSL or a cable modem. I'll give him the benefit of the doubt and say he has at the very least a fairly modern firewall on his home network. So, how did the creep get access? Possibly because Brad is a nice guy.

Imagine you get 100s of emails a day, some hatemail, some fanmail, some suggestions on new spells and such. After awhile, you get to know the addresses of the folks with ideas fairly well; so you make sure to always read their mails. Sometimes, they come with attachments, pictures, screenshots, code, excel spreadsheets, whathaveyou. Hidden in one of those screenshots from a fan who is trying to get on as a graphic artist is a visual basic program. This program is what we in the trade call a "Trojan Horse" program. It takes down Brads username and password, looks for a way to send off a message to the crook (preferably by sending out a email message using a free service like yahoo or hotmail to another such account,) and sends the crook the username and password. Since the victim's computer is probably always on, he or she has no idea that any info has been sent out; for the program is set up to wait until a certain amount of time has gone through before activating itself. It's also possible for the program to replicate itself into other attachments that the victim sends out, gaining access to other accounts within the target company. Since the crook now has the username and password of the victim, who is allowed to work from home, the crook can now access from anywhere as well. With access to a superuser account, the crook can look at an awful lot of information, but not credit card numbers.

Why am I so sure about the credit card numbers being safe from such an attempt? Simple. I used to work for an online game company, and I know the precautions *we* took with credit cards. All the card numbers were stored on a separate system, which did not have external access. No "work at homes" could see the credit card data, which meant when such an issue came up, we'd always defer our customers to on site Game Masters who could see that data. Knowing that at least one major figure from our company now works for Verant, I'd assume he made sure the same precautions were taken there.

So what could a person do to you if they had superuser access and knew your account name as well? Well, they could ban you or remove a ban, they could give or take away experience, skill points, items and cash or they could delete a character all together. For identity verification purposes, they could probably see your billing address and phone number, and most definately your name.

So, was confidential data avaialable to the crooks? Most likely. Was it anything that could ruin you financially? I'd bet money on no here. Was Brad guilty of Verant's own policy of not allowing other people access to your account no matter the reason? Yes. Being "hacked" is not a defense in Verant's eyes, lest everyone who was ever banned could claim someone hacked them and did the crime. Will Brad be banned? Heck no. They need him too much to fire him over something like this. Will this experience cause Verant to look closer at their security? I hope so. If they need an expert, I'm available at good rates...

RE: Internet Safety & Our Privacy
# Sep 02 2001 at 10:19 PM Rating: Default
Hmm, for a security expert you seem to be missing a lot of basic knowledge about computer programs...
"Hidden in one of those screenshots from a fan who is trying to get on as a graphic artist is a visual basic program"
Yes, it is possible to hide a program in a screenshot (a screenshot is just numbers, and so is a program or anything else you store on your computer), but in order for this program to perform the rest of the tricks you list, it would have to be executed. Now a lot of people seem happy to blame Brad for this break-in, but I really can't believe he'd be daft enough to run an executable (eg. a visual basic program) from a fan, after all that is how almost all viruses spread so the most elementary security procedures make it unlikely. If the program is saved with a .jpg (or .bmp or .gif etc) extension it can't be run without renaming it to .exe or .vba or some other file subscript that windows recognises as a program format.
To speculate about how the break-in was accomplished doesn't really help anything anyway, in fact this whole thing seems a bit of a non-issue given it happened so long ago. EQ2 is probably the working name for SoL, the security hole has been patched (hopefully better than the average EQ patch :), credit card information is not going to be available to employees except the accounting department, and of course the press are going to have a field day making another mountain out of a molehill.
RE: Internet Safety & Our Privacy
# Sep 03 2001 at 6:28 PM Rating: Default
Perhaps you don't read bugtrak, PDF's can excecute code what makes you think that Outlook is any smarter..
RE: Internet Safety & Our Privacy
# Sep 03 2001 at 8:52 PM Rating: Decent
pdfs can contain macros, like word docs... they are the same as executeables - you don't open them unless you're very confident it's safe.
RE: Internet Safety & Our Privacy
# Sep 01 2001 at 5:21 PM Rating: Good
I play EQ alot and I run a firewall too. Every single day and alot more on the weekends, that firewall has stopped numerous Trojan Horse programs from accessing my information. This is a DAILY thing people, meaning that since they cant penetrate my firewall, their heading to another account that can be accessed easier than mine. When I look at the trojan horse attempt, it traces back through EQ's servers. That means that when you enter the game, a hacker can get a ping to you, and try to send a trojan horse program.
SOLUTION: Get at least a good Firewall program like Norton. You will be AMAZED at what you find is going on while your camping Gynok Moltar in Befallen :)
RE: Internet Safety & Our Privacy
# Sep 04 2001 at 7:46 PM Rating: Excellent
A good firewall is a must have, especially if you are using your 'puter for multiple tasks.. like personal finance, work at home, etc. However, if you're particularly worried about somebody busting your f-wall and sleazing your docs or your password or financial info, you do what I do. You use your main comp with all the fancy security crap on it for work and personal business, which I prefer to actually use a dialup modem on so haqers don't have 24/7 access to it. Then when you need a break from the daily grind and would really like to join that guild raid on ToV, you switch over to the comp with the good graphics card, high speed processor, uber-ram, and most importantly cable or DSL hookup. Only thing I have on this computer is EQ, Diablo 2, Myth, and Baldur's Gate 2. HACK AWAY!!! Nothing they can access given all the time they want will benefit them in the slightest. Yes, if they got into my other computer they could potentially, with the right know how, scoot off with a few million (not mine, unfortunately) and I'd be well and truly skrood. Thankfully the IT guys at work are good at their jobs, and my connection times to the net are incredibly minimal. I don't get email with attatchments from anyone who knows my email address, so any that come in are logged, reported, and deleted unopened. So yeah, I bet I get hit with a few hacks here and there while beating up treants or camping Dyllin Starshine for 8+ hours, but those who get through take a look at my barren wasteland of nothing but gamefiles and realize their time was wasted. If they should get petty and decide to delete my EQ characters, oh skippy well, I can build them back up again. Slightly annoyed, but not destitute.
EQ2
# Sep 01 2001 at 3:40 PM Rating: Decent
Heh, the sad thing is, what really caught my attention about this article was the mention of "Everquest 2". Is that wrong? *starts looking in the phonebook for a psychiatrist*
re
# Sep 01 2001 at 2:46 PM Rating: Default
I think the greater concern would be over any sensitive company information the hacker obtained, not individual account info.
« Previous 1 2
Post Comment

Free account required to post

You must log in or create an account to post messages.