It has been reported on numerous websites that several character’s accounts have been compromised. The intruders will change the password and/or credit card information so that the actual owners cannot log in and make it difficult to get their password reset through SquareEnix’s tech support. I will try to deliver you facts that I know in this post. I have been given lots of information from visitors and team members of FFXIAH. Communities have been reporting this incident as early as Dec 4th. I can’t be sure of the exact date. How the attackers gained access isn’t clear either mainly due to vast speculation from self-proclaimed information security experts.
Somepage.com
It has been reported and confirmed that ‘somepage‘ HAD a hidden iframe on their front page. I don’t know how long it was there nor if it was the prime source of all incidents. If you aren’t familiar with an iframe, it can load an external page that can contain malicious code that is hard to detect. There was indeed what appeared to be harmful obfuscated Javascript code that was identified as a RealPlayer exploit. This may only have affected users with a combination of vulnerable versions of RealPlayer installed and Internet Explorer. The iframe has been removed from the front page but the webpage’s admin might need some time to make sure their site is fully secure.
FFXIAH Advertising
FFXIAH has recently become a member of a new ad network. The ads would contain non-RMT companies, as opposed to Google’s Adsense. Some users of our site experienced intrusive advertisements that aggressively attempted to get the user to install anti-spyware software. I could not recreate this behavior myself so I couldn’t tell what the original advertisement was. I need to know this so I can report it to the ad network. We theorize that one of the flash based advertisements in the rotation contained code to forward the page. We do not believe this has anything to do with the recent FFXI account hijackings, just a mere coincidence in timing. We have researched and found that this is a general problem facing advertisers, publishers, and ad networks. Either way, the possibility that these ads being exposed to our users is unacceptable to us and we have suspended the new advertisements at the time being. The incident is more of a blanket attack on publishers and advertisers and not necessarily targeting FFXI accounts specifically:
http://www.dynamoo.com/diary/malware-scan-newbieadguide-com-hijack.htm
http://forums.coldfront.net/coldfront/1762-invasive-banner-ad-kolwiki-redirects-fakes-error-message.html?highlight=avsystemcare
http://forum.dvdtalk.com/archive/index.php/t-514848.html
http://www.wired.com/techbiz/media/news/2007/11/doubleclick
http://www.youtube.com/watch?v=8lBUQqufZWc
ChineseRMT
Lately we experienced anonymously posted links on the blog and forum that were quickly removed. At first they just appeared to be spam but they linked to sites with hidden code. This pattern has been reported on other sites and Wikis within the JP community. The ChineseRMT are very resourceful and motivated to steal virtual goods without fear of consequence. It is a very unfortunate but we can only play defense. All Internet Explorer users, please use Firefox (getfirefox.com). It is the single most easiest thing to do to protect yourself. If you don’t have Anti-Virus, I can recommend AVG free edition (http://free.grisoft.com/).
Forum
You may have noticed we have taken down our forum. Our logs show evidence of IPs originating in China blatantly attempting to exploit vulnerabilities in PHPBBv3 and earlier versions. It has been taken down as a precaution and may be down for the rest of the month of December. Possible alternatives are being discussed, including possibly just a simple in-house model.
Let me know if anyone can supply me with additional information. I especially want to hear from people that had problems with advertisements on FFXIAH.com. Send me an email at ffxiah@gmail.com. Thanks in advance.