blonde poker forum

Community Forums => The Lounge => Topic started by: booder on January 15, 2013, 09:21:33 PM



Title: Sighballs
Post by: booder on January 15, 2013, 09:21:33 PM
Had my hotmail , googlemail , pokerstars and full tilt accounts hacked.

apologies in advance if you get any spam mail.


Title: Re: Sighballs
Post by: kinboshi on January 15, 2013, 09:24:20 PM
:(

Hope they didn't get much.  You got control of the accounts back again?


Title: Re: Sighballs
Post by: booder on January 15, 2013, 09:30:36 PM
:(

Hope they didn't get much.  You got control of the accounts back again?

Can't access either of mail accounts so can't access any contact info or previous information contained in emails.

they have tried to change my passwords on my pokersites but i cannot access the correspondence from support now.

luckily my pokerstars account has  secendary protection so at least my 95c are safe


Title: Re: Sighballs
Post by: tikay on January 15, 2013, 09:52:40 PM
That sucks so bad.

This hacking stuff is getting out of hand.


Title: Re: Sighballs
Post by: kinboshi on January 15, 2013, 09:53:26 PM
You can contract Google about your Gmail account. You will have given them a secondary email account (hopefully not your Hotmail one) and they can send a reset password link to that. If you've given them a mobile number, they can even text you the link (or a code that you can enter to reset the password ).

If you do get back in,set up the two-step verification to help secure your account going forward.


Title: Re: Sighballs
Post by: booder on January 15, 2013, 10:00:39 PM
You can contract Google about your Gmail account. You will have given them a secondary email account (hopefully not your Hotmail one  SIGH) and they can send a reset password link to that. If you've given them a mobile number  SIGH,HACKERS CHANGED IT, they can even text you the link (or a code that you can enter to reset the password ).

If you do get back in,set up the two-step verification to help secure your account going forward.


Title: Re: Sighballs
Post by: EvilPie on January 15, 2013, 10:05:48 PM
:(

Hope they didn't get much.  You got control of the accounts back again?

Can't access either of mail accounts so can't access any contact info or previous information contained in emails.

they have tried to change my passwords on my pokersites but i cannot access the correspondence from support now.

luckily my pokerstars account has  secendary protection so at least my 95c are safe

Who's 95c ;)


Title: Re: Sighballs
Post by: booder on January 15, 2013, 10:06:52 PM
:(

Hope they didn't get much.  You got control of the accounts back again?

Can't access either of mail accounts so can't access any contact info or previous information contained in emails.

they have tried to change my passwords on my pokersites but i cannot access the correspondence from support now.

luckily my pokerstars account has  secendary protection so at least my 95c are safe

Who's 95c ;)


FML


Title: Re: Sighballs
Post by: booder on January 15, 2013, 10:50:10 PM
Hello David,

Thank you for contacting us.

We have confirmed that your PokerStars account has been hacked by a keylogger from a location in France; fortunately, no funds were lost and our security systems detected this access promptly.

In order to help you gain access back to your account, we will need you to format your computer, reinstall Windows and change your email password; please contact once you have done so and bear in mind that we cannot continue communication until you have proceeded as request.

We appreciate your collaboration with this matter.

For any further questions we will be more than happy to assist you.

Regards,

Miguel A
PokerStars Security Team





Marvellous


Title: Re: Sighballs
Post by: Graham C on January 15, 2013, 10:56:47 PM
Ouch, what a pain in the arse, hope you get it sorted soon.


Title: Re: Sighballs
Post by: EvilPie on January 16, 2013, 12:12:01 AM
Just checked my emails and somebody's had a username retrieval sent to my email address. Certainly wasn't me so hopefully I'm not being done as well.

Currently changing all passwords just in case.

Marvelous.


Title: Re: Sighballs
Post by: Free_Rollin on January 16, 2013, 12:28:23 AM
Hopefully it gets sorted all out for you Booder!

Are these hacks generally when people have sat there and tried to guess your password? Or is there other way they are doing it? Anybody know?


Title: Re: Sighballs
Post by: kinboshi on January 16, 2013, 09:10:33 AM
It's often done using keys loggers, programs that are installed on your machine and record your key strokes (and report them back). Usually install themselves at the same time as you install some dodgy software, or they're installed as part of a virus / Trojan infection.

There are also vulnerabilities in certain programs that can be exploited (such as programs that store or send passwords in plain text).



Title: Re: Sighballs
Post by: kinboshi on January 16, 2013, 09:14:23 AM
You can contract Google about your Gmail account. You will have given them a secondary email account (hopefully not your Hotmail one  SIGH) and they can send a reset password link to that. If you've given them a mobile number  SIGH,HACKERS CHANGED IT, they can even text you the link (or a code that you can enter to reset the password ).

If you do get back in,set up the two-step verification to help secure your account going forward.

Bugger. Might be worthwhile contacting them and explaining what's happened. They will be able to see the IPs that have been used to access your account and if they have all been UK and then suddenly change to a foreign IP they'll see it wasn't you who changed all the info.

Worth a shot.


Title: Re: Sighballs
Post by: booder on January 16, 2013, 11:25:59 AM
Got my old googlemail account recovered, eventually.

Got fulltilt back with added security measures, just need to jump through pokerstars hoops now.

what a palava.


Title: Re: Sighballs
Post by: kinboshi on January 16, 2013, 11:37:58 AM
Good news about the gmail account.

Have you set up the 2-step verification for it? 

My gmail account was hacked (about a year ago now) via an app that had been compromised on my android phone.  Scared the shit out of me as I use that account for a lot of stuff and have emails in there going back well over 5 years. Fortunately, I was alerted to the hack and managed to get in, change the password and lock the hackers out within 5 minutes.  They'd already spammed loads of people in my contacts and had moved 12 months of emails into the Bin (but fortunately, hadn't deleted them permanently).

Anyway, have a look at the Google two-step verification as that makes your gmail account a LOT more secure to this sort of attack.

http://support.google.com/accounts/bin/answer.py?hl=en&answer=180744

and this is worth a read:

http://www.theatlantic.com/technology/archive/2012/08/turn-on-gmails-2-step-verification-now/260822/


Title: Re: Sighballs
Post by: kinboshi on January 16, 2013, 11:40:10 AM
With PokerStars (don't know about any others), you can add a second-level of security using either a security dongle (which there's a one-off payment for), or with a simple 6-digit pin that you can add to the login process so you need to add that as well as your password.  The 6-digit pin is entered via your mouse on a randomised keyboard to stop keyloggers from being able to 'grab' the PIN.

Worth doing that as well if you haven't already.  Will keep your 95c safe.


Title: Re: Sighballs
Post by: booder on January 16, 2013, 11:41:26 AM
With PokerStars (don't know about any others), you can add a second-level of security using either a security dongle (which there's a one-off payment for), or with a simple 6-digit pin that you can add to the login process so you need to add that as well as your password.  The 6-digit pin is entered via your mouse on a randomised keyboard to stop keyloggers from being able to 'grab' the PIN.

Worth doing that as well if you haven't already.  Will keep your 95c safe.

yeah got one of those thanks.


Title: Re: Sighballs
Post by: booder on January 16, 2013, 11:47:35 AM
Good news about the gmail account.

Have you set up the 2-step verification for it? 

My gmail account was hacked (about a year ago now) via an app that had been compromised on my android phone.  Scared the shit out of me as I use that account for a lot of stuff and have emails in there going back well over 5 years. Fortunately, I was alerted to the hack and managed to get in, change the password and lock the hackers out within 5 minutes.  They'd already spammed loads of people in my contacts and had moved 12 months of emails into the Bin (but fortunately, hadn't deleted them permanently).

Anyway, have a look at the Google two-step verification as that makes your gmail account a LOT more secure to this sort of attack.

http://support.google.com/accounts/bin/answer.py?hl=en&answer=180744

and this is worth a read:

http://www.theatlantic.com/technology/archive/2012/08/turn-on-gmails-2-step-verification-now/260822/

Done.Thanks.


Title: Re: Sighballs
Post by: Free_Rollin on January 16, 2013, 01:07:08 PM
It's often done using keys loggers, programs that are installed on your machine and record your key strokes (and report them back). Usually install themselves at the same time as you install some dodgy software, or they're installed as part of a virus / Trojan infection.

There are also vulnerabilities in certain programs that can be exploited (such as programs that store or send passwords in plain text).



Ah ok, thanks Dan. :)


Title: Re: Sighballs
Post by: kinboshi on January 16, 2013, 01:10:18 PM
It's often done using keys loggers, programs that are installed on your machine and record your key strokes (and report them back). Usually install themselves at the same time as you install some dodgy software, or they're installed as part of a virus / Trojan infection.

There are also vulnerabilities in certain programs that can be exploited (such as programs that store or send passwords in plain text).



Ah ok, thanks Dan. :)

After I wrote that, I realised I missed another way they get your password: http://blondepoker.com/forum/index.php?topic=60068.msg1701013#msg1701013

Which is why the 2-step verification is even more important for those who access their Google account via their mobile, especially on android where your google account is 'built-in' to virtually everything you do on the phone.


Title: Re: Sighballs
Post by: kinboshi on January 31, 2013, 01:59:38 PM
Another reason why gmail is probably a better bet than Yahoo for your email:

http://arstechnica.com/security/2013/01/how-yahoo-allowed-hackers-to-hijack-my-neighbors-e-mail-account/


Title: Re: Sighballs
Post by: booder on February 04, 2013, 08:17:29 PM
Got my stars account up and running eventually. Had to send front and back scans of picture ID , photo of myself holding said ID and then had to wait for phone call from stars security department to verify some account related questions.

Looking forward to playing again this weekend.