free

News

collapse

User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

* Recent Posts

NOTICE OF PARKING ENFORCEMENT CHANGES by Huntsman
[June 19, 2025, 05:22:50 pm]


Re: Stopping by by Sinister
[June 08, 2025, 01:58:04 pm]


Re: Stopping by by Ehks
[June 04, 2025, 12:25:17 am]


Re: Rest in peace by Stefanrsb
[June 02, 2025, 03:38:02 am]


Re: [SA:MP]House of Sforza | The Elite Power | Estd. 2006 | LS - LV by Stefanrsb
[June 02, 2025, 03:09:22 am]


Re: The Soprano Family | Royal Loyalty by Stefanrsb
[June 02, 2025, 03:00:31 am]


Re: The Gvardia Family || San Fierro's Main Power || Best criminal group of 09/10/11 by Stefanrsb
[June 02, 2025, 02:47:01 am]


Re: BALLAS | In memory of INFERNO 9 and NBA by Stefanrsb
[June 02, 2025, 02:31:29 am]


Re: Count to 1,000,000. by Stefanrsb
[June 02, 2025, 02:15:04 am]


Re: Stopping by by Traser
[June 01, 2025, 10:23:13 pm]


Re: Stopping by by Old Catzu
[May 18, 2025, 07:27:06 pm]


Re: Stopping by by TheRock
[May 18, 2025, 06:44:49 am]

* Who's Online

  • Dot Guests: 412
  • Dot Hidden: 0
  • Dot Users: 0

There aren't any users online.

* Birthday Calender

July 2025
Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5
6 7 8 9 [10] 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31

Fraudulent / Malicious Email Alert

Teddy · 16733

0 Members and 1 Guest are viewing this topic.

Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
on: August 22, 2016, 01:56:32 am
Hello,

We've become aware of an email being received by some that appears to originate from Argonath RPG using third party mail services like Yahoo and Gmail. These emails ARE NOT Argonaths, all of our official emails originate from *.argonathrpg.com, argonathrpg.com, and argonathrpg.eu. We do NOT use any other third party service.

Do NOT click any links from these emails. Do NOT reply to them. Delete them immediately.

Kindly,
Web Team



Offline Khm

  • Webmaster
  • *****
    • Posts: 5456
    With us since: 29/09/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: Marshall Kings
  • V:MP: Khm
Reply #1 on: August 22, 2016, 02:02:15 am
who's it this time.. Thanks for the heads up.



Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #2 on: August 22, 2016, 02:24:23 am
I've already managed to reverse the intent of the link. It appears to try and hijack your forum session if you are already logged in. Good news is Google Chrome and Firefox have built-in protection against this, as does our forum to a degree. IE users may be vulnerable but that's nothing new since it's an insecure piece of shit anyways.

Just to be safe, avoid clicking the link anyways.

who's it this time.. Thanks for the heads up.

I kinda hoped they were dumb enough to use their real name or Argonath name when signing up for either but doesn't appear so. Not entirely sure, best we can do now is make sure people are aware.



Offline Khm

  • Webmaster
  • *****
    • Posts: 5456
    With us since: 29/09/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: Marshall Kings
  • V:MP: Khm
Reply #3 on: August 22, 2016, 02:31:58 am
I kinda hoped they were dumb enough to use their real name or Argonath name when signing up for either but doesn't appear so. Not entirely sure, best we can do now is make sure people are aware.
Once someone falls for it, we will find out who's behind it anyways. :lol:
Desperately waiting for their e-mail tbh.



Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #4 on: August 22, 2016, 03:07:46 am
Will be keeping an eye out.



Offline Rei

  • Hero
  • ****
    • Posts: 2276
  • Baba Yaga
  • With us since: 25/09/2013
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #5 on: August 22, 2016, 03:14:40 am
Do those email appear only in our spam box in gmail, or they can be among these emails we get for example when someone send us a message in forum?


Offline [NP]Monte Montague

  • The
  • Hero
  • ****
    • Posts: 3895
    • monte_montague
  • With us since: 18/05/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
    • Parallel Universe Co-Operative Gaming Community
  • SA:MP: [NP]Monte.Montague
Reply #6 on: August 22, 2016, 08:00:07 pm
Do those email appear only in our spam box in gmail, or they can be among these emails we get for example when someone send us a message in forum?

Spoof emails, phishing emails, emails that contain malware and so on and so forth can be made to look like actual emails so YOU NEED TO BE CAUTIOUS.



Do NOT use the same email you use for everything else with ArgonathRPG.
Don't use the same passwords or details if it can be helped.

Make sure you have appropriate anti virus, anti malware software. Don't rely on the free stuff.

Use a mainstream email client or one that you know is secure.

Don't use outlook / desktop email clients / applications or the like as THEY ARE vulnerable. Especially important for windows users who don't know what they are doing or who can not be bothered to protect their devices or those who just simply are ignorant.

Make sure you know what sort of addons you put on your chrome, firefox.



Since the forum or web database or w.e was hacked... People really should think twice, especially if they were around when that happened or were victims of that previous old attack that happened. 

ParUni.NET - The Co-Operative Gaming Community


Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #7 on: August 22, 2016, 08:01:01 pm
Do those email appear only in our spam box in gmail, or they can be among these emails we get for example when someone send us a message in forum?

Most appear in the normal inbox, depending on your choice of email service. Most who've received it reported it was in their inbox and not in spam.



Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #8 on: August 22, 2016, 10:32:15 pm
Do NOT use the same email you use for everything else with ArgonathRPG.

Make sure you have appropriate anti virus, anti malware software. Don't rely on the free stuff.
Both of these suggestions are actually highly-misleading. Your choice of email service has nothing to do with this situation, and having a separate one wouldn't make you any less vulnerable to phishing attempts from anyone online. Also, not all free anti-malware programs are bad. Some of them are even better than their paid competition.



Offline Ben.

  • Veteran
  • ***
    • Posts: 2958
  • Benjamin J. Blake
  • With us since: 21/07/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: =AV=Ben_Blake
Reply #9 on: August 23, 2016, 01:00:10 am
Yeah, doesnt make sense when you take it out of context but when combined with the password  comment below it, suddenly it does.
Your email address is one which great for hackers if they want your account...suddenly the use of a salt value originating from your ID becomes pointless.


Salt and hate won't take us anywhere.
And we do not try to be real life, as why would you ever play real life if you have one ? We play the GTA universe, and our players should try to live in the GTA world, not the real one.


Offline SugarD

  • Hero
  • ****
    • Posts: 11515
    With us since: 21/03/2008
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #10 on: August 24, 2016, 04:02:57 pm
Yeah, doesnt make sense when you take it out of context but when combined with the password  comment below it, suddenly it does.
Your email address is one which great for hackers if they want your account...suddenly the use of a salt value originating from your ID becomes pointless.
Not using the same password everywhere is just a general rule. That has absolutely nothing to do with the email address you have chosen. Getting an ID from your forum account isn't going to enable them to get into your email address. The only way they could attack both would be by getting a hold of your forum password, and then, (assuming the password is the same in both places), logging into your email address with said password.



Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #11 on: August 24, 2016, 06:51:07 pm
The password is irrelevant in this case. In order to know who you are the forum stores a cookie with an ID on your computer, this is ID links to a session stored on the server which is all of your data in regards to the forum. This specific attack aims to try and steal that cookie's data and interpret the ID, then mimicking it to try and trick the forums into thinking they're you and to give access to your session thus impersonating you. Unfortunately for them this doesn't work so easily anymore due to security advancements.



Offline TiMoN

  • an
  • Hero
  • ****
    • Posts: 4066
  • Self-Elected Best Overall Player 2015
  • With us since: 07/10/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: TiMoN
  • Minecraft: TiMoN
Reply #12 on: August 24, 2016, 07:01:09 pm
The password is irrelevant in this case. In order to know who you are the forum stores a cookie with an ID on your computer, this is ID links to a session stored on the server which is all of your data in regards to the forum. This specific attack aims to try and steal that cookie's data and interpret the ID, then mimicking it to try and trick the forums into thinking they're you and to give access to your session thus impersonating you. Unfortunately for them this doesn't work so easily anymore due to security advancements.
Is this method also used to catch ban evaders or am I just over thinking?



Offline Julio.

  • Hero
  • ****
    • Posts: 6010
    With us since: 21/07/2009
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • SA:MP: [Rstar]Julio
  • IV:MP: [R*]Julio
  • VC:MP: [R*]Julio
  • V:MP: [R*]Julio
Reply #13 on: August 24, 2016, 07:07:22 pm
Is this method also used to catch ban evaders or am I just over thinking?

Hm, not really. This is specifically linked to the browser and your session (length determined by your "stay logged in for" time).



Offline TeddyTopic starter

  • Orc
  • *****
    • Posts: 9161
  • "I'm on top of the world because of you."
  • With us since: 05/02/2011
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Reply #14 on: August 25, 2016, 01:15:23 am
Is this method also used to catch ban evaders or am I just over thinking?

No, if you are banned that is stored in the session, so if you were using the same session token then you'd be presented with the ban message and thus wouldn't be ban evading very well.



 


free
SimplePortal 2.3.7 © 2008-2025, SimplePortal