Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Sunday, April 1, 2018

Breaking News: Hacker Renames Hundreds of Accounts Trump and Clinton


*Update - April Fool's*

In a shocking move, a hacker was somehow able to gain access to Linden Lab's computers and rename several hundred accounts. It is believed he or she was about to seize control of the renaming process and used it to change the names of the residents. There were a number of males in motorcross clubs given names such as "Kissyfur" and "Cuddlebaby." And there were several professors in science groups given insulting names such as "Dunderhead" and "Flatearther." But the majority of the affected residents were accounts that were created after 2010, given the surnames "Trump" and "Clinton." This includes a few dozen in political groups, given the name of the political figure in the party opposite theirs.

Numerous residents have already spoken out in various forums, demanding Linden Lab fix their accounts. Several have already stated they will not return until their accounts are fixed. Linden Lab in response has stated they are considering activating the ability for residents to change their names early, though has not spoken on whether or not the residents affected by the hacking will have their account names restored for free.

For the official statement by Linden Lab, Click Here.

Tuesday, February 27, 2018

Second Life Hit By Large Scale DDOS Attack



Second Life has been under attack by trolls many times. But this time, hackers are the ones causing the trouble.

For the second day in a row, residents have had trouble getting inworld. People couldn't log in, or if they were already in, they'd be logged out. People had trouble bringing up the Second Life webpage as well as Marketplace. Yours truly couldn't get on until after 7PM SL time. Curiously, Firestorm was also described as being down. There was naturally speculation about the cause. One person wondered if one of the twelve employees Linden Lab recently let go had something to do with it. Others suspected a DDOS, or Distributed Denial of Service, attack.

Finally just after 11AM SL time, April Linden finally announced the cause, an unusually large DDOS, one that the Lab stated were "at a level that we rarely see."

As I’m sure most of y’all have noticed, Second Life has had a rough 24 hours. We’re experiencing outages unlike any in recent history, and I wanted to take a moment and explain what’s going on.
The grid is currently undergoing a large DDoS (Distributed Denial of Service) attack. Second Life being hit with a DDoS attack is pretty routine. It happens quite a bit, and we’re good at handling it without a large number of Residents noticing. However, the current DDoS attacks are at a level that we rarely see, and are impacting the entire grid at once. 

My team (the Second Life Operations Team) is working as hard as we can to mitigate these attacks. We’ve had people working round-the-clock since they started, and will continue to do so until they settle down. (I had a very late night, myself!) 

Second Life is not the only Internet service that’s been targeted today. My sister and brother opsen at other companies across the country are fighting the same battle we are. It’s been a rough few days on much of the Internet. 

We’re really sorry that access to Second Life has been so sporadic over the last day. Trying to combat these attacks has the full attention of my team, and we’re working as hard as we can on it. We’ll keep posting on the Second Life Status Blog as we have new updates.

As I am writing this, I've been hearing that various online retailers have also been hit with DDOS attacks. Although the Grid Status Report suggests there are still problems, some are telling me they can get on again. Hopefully the issue will be resolved quickly.

Image Credit: Spooked Dreamscape

Bixyl Shuftan

Saturday, March 1, 2014

Word on the Street: Hack Attacks


Lately, we've been hearing of a number of groups passing out warnings of people getting hacked after checking a link posted by a friend, which ends up leading to disaster. They usually go something like the following.

*WARNING* Multiple hacking going on in SL today and it involves Market Place. your "friend" will send you a link to market place, you log in giving your name and password and your are hacked. They immediately change your password and then send the same invite to all your friend's....DO NOT follow any links to Market Place today whether the offer came from a friend or not. LL is aware of it and have shut many accounts down today.

These warnings aren't just idle threats.  Some months ago, one of the residents of the Sunweavers was the victim of a similar hacking attack. So be careful about what links  you click on.

Monday, September 23, 2013

Hacked

Earlier this month, a warning was sounded in the Angels and Sunweaver groups. Brandi Streusel, one of the more popular members, noted for her "Brandi's Panties" line of outfits, had been hacked. An amount of Lindens were swiped from her account, a number of items on her were compromised, and the most visible example of what happened, Castle Mousehold was wrecked. The possessed avatar deleted about half the place.

As soon as she realized what was happening, Nydia sounded the alarm in the Sunweaver and Angel groups, in addition to several other groups, urging the account be barred from their places until it was confirmed she was back. And above all, not to click on links she was sending out.

As you all probably know by now, Brandi's account has been hacked, I have banned her where I could, but not before the castle was destroyed, right now...our home is gone. I have asked Rita for a roll back that should fix that, as for when we get Brandi back ….I don't know.


Unfortunately, someone else did click on a link sent by the hacker before word got around, Dusk Griswold. So word went out about the second hacked account, warning that if they clicked on anything sent by them, "you need to change all your passwords NOW, and anything your account is linked to."

If  you are ever sent a website link that tries to be something from Second Life.  Make sure that it is actually from secondlife.com

This   http://markettplacefree.altervista.org/index.html   IS NOT from Second life.  Never click on a link, or log into a page that isn't an Actual Second Life web page.  If you're not sure,, be safe and just don't. 


Eventually, Brandi and Dusk were back. Linden Lab didn't give Brandi the Lindens she lost back, and she had to go through her inventory to examine what might have been compromised. But the sim rollback was carried out and the castle restored. Dusk reported the hackers tried to rob her, but the Lab took care of the details.

Just wanted to let everyone know LL has restored my account after the hacking incident. The person first tried taking all my Lindens, then buying Lindens. They did succeed in making a few small transactions on Paypal, but they have been notified, and I should get credit for those. The Lindens they took from me here have been restored, and all my passwords have been changed.  

And so the hackers were stopped. Thanks to the community spreading the word, no more found themselves locked out of their accounts. But this was a warning to all about "illicit links and the problems they cause."

" …. people will understand the peril they put themselves in if they don't take 5 seconds to simply check links. They can lose everything and not even be here for it, everything including their own financial holdings. A hacker if they can get your account and log in, they can get access to your personal money line account numbers, and that leads to things far far worse than this world. I know... it's happened to me. I fought tooth and nail to get everything back … "

Words of warning to listen to. And of course, a reminder if one suspects anything funny, don't hesitate to change your password.

Press Pass Media also wrote an article recently on the subject of phising scams (click here). 

Bixyl Shuftan

Monday, April 15, 2013

Virtual Cash Makes Real-Life News with Bitcoin Crash


By Bixyl Shuftan


Last month, the US Department of the Treasury issued "guidelines" aimed at virtual currencies. While the Linden dollar will be affected by the Government's interest, another virtual currency with a larger distribution and volume was also targeted: the bitcoin.

Wikipedia defines the Bitcoin, abbreviated to BTC sometimes, as "an online commodity that is based on an open-source, peer-to-peer encryption protocol … creation and transfer is accomplished on an Internet-based network and is not managed by any central authority." Bitcoins are created through "miners" that automatically add new amounts by "adding codes to a decentralized log, which is updated and archived periodically." They're transferred electronically, either via computer, or through handheld devices like smartphones.

Computer geeks are sometimes drawn to it due to it's online nature. But as banks are not necessary in the exchange, and it is not created by governments, some people are attracted to it due to the lack of involvement by larger institutions. It's also gotten some skeptics because of the lack of involvement by larger institutions, and concerns that drug traffickers and other criminals use it as an easy way to sell illegal goods.

Bitcoin went through what some are calling a "bubble" recently when it's value jumped from about $90 in late March to a high of $260 on the morning of Wednesday April 10th. Then the value crashed, plummeting to around $130 in six hours. It regained some of it's lost value the following day, rising to $160. As of the writing of this article, bitcoincharts.com listed the value as $99.00.


The crash was linked to an unknown bitcoin owner who up and gave away $13,000 in bitcoins via the Reddit social website. But there have been other problems. There have been attempts by hackers to break into computers and make it mine bitcoins for the hijacker. News of this did cause a drop in the value of Bitcoins on April 4, but the price surge continued again. There was also an account hacking in which $12,800 worth of Bitcoin was stolen.


The crash has caused some to feel Bitcoins, or any other unregulated currency, is just too risky. But others are still trading them. Even as all this was going on, people in the US Treasury Department had already taken notice. In March, the Department of Treasury's FinCEN issued it's guidelines, defining Bitcoin as a "de-centralized virtual currency" with "no central repository and no single administrator, and … persons may obtain by their own computing or manufacturing effort." Like Linden Labs, Bitcoin miners in the United States will have to file anti-money laundering reports with the Treasury Department, in addition to registering with them. There is a "blurred definition" however between users of Bitcoin and "administrators." Could a miner be considered just a user as long as the Bitcoins created weren't traded for US dollars or other real-life money?

Already having caught the interest of the US Government, with the news of hacking attacks and the market volatility, bitcoin is highly likely to face additional scrutiny from both American and European authorities. It's laissez-faire days of being free from big business and government may soon be coming to a close.

For information on what a bitcion cost, check this April 14th article at techcrunch.com.

Second image from salon.com

Sources: Wikipeda, BBC News, CNN, verge.com, Modern Payment Systems

Bixyl Shuftan

Friday, July 6, 2012

DNSChanger Malware Could Knock Thousands of Computers Offline July 9

Thousands of computers are at risk of being unable to use the Internet because of malware from online criminals in a scam last year. Despite an effort to get the word out, as many as 277,000 computers worldwide still cary the hostile software known as DNSChanger.

DNSChanger was discovered in 2007, and may have infected millions of computers over time. The malware worked by detecting what websites its victims browsed, then redirected them to sites under the control of a cybercrime enterprise working from the small Eastern European country of Estonia, where ads were pushed onto the viewers. The criminals were netting millions before the FBI worked with Estonian police to break up the crime ring and confiscated the servers. Six were arrested with a seventh in Russia still at large.

To avoid disrupting those with infected computers, the servers were kept online as word was spread about the malware infections. In January, it was estimated a half million computers had the malware. But on Midnight July 8, the servers will be turned off, and those computers still infected will be unable to get online, at least without taking certain steps. In January, it was estimated a half million computers had the malware. As many as 277,000 computers across the world may still be infected, including as many as 4500 in the United States. Messages, such as the one Google has been showing to users of computers it detected the malware on (shown below), have helped to get the word out.

For those computers still infected, there are a number of places one can go. Among them is a website that a group of security groups and experts set up: www.dcwg.org. Others include:

Hitman Pro (32bit and 64bit versions)

Kaspersky Labs TDSSKiller

McAfee Stinger

Microsoft Windows Defender Offline

Microsoft Safety Scanner

Norton Power Eraser

Trend Micro Housecall

MacScan

Avira


For computers knocked offline, they can still get to Google by typing "173.194.34.72" into their address bar, or to Microsoft with "64.4.11.37".

Internet security company Internet Identity reported at least 60 companies on the Fortune 500 still have infected computers. At the beginning of the year, they believed the number was 250. or 50 percent. For US Government agency computers, the amount infected went down from an estimated 49 percent to 4.

Sources: http://www.dcwg.org/, Forbes, Reuters, Internet News , Google


Bixyl Shuftan

Tuesday, November 2, 2010

Phoenix Reports Counterfeit Viewers

This message was going around Second Life group chats yesterday:

We've just received from a credible source that there are viewers being circulated that look just like official third party viewers, (including the Phoenix Viewer) but that have key loggers and password stealer's in the code. Please do not download any viewers from url's outside the viewers associated website! If someone offers you a viewer that is not hosted on their official site, please abuse report that person and include the link they were sending you too. More info about this on our website blog.

The source of the message was the Phoenix Viewer Team. It was not stated whom was sending these counterfeits.