View Single Post
Old 01/28/08, 4:28 AM   #48 (permalink)
Bunni
Von Kaiser
 
Bunni's Avatar
 
Troll Shaman
 
Deathwing (EU)
Originally Posted by NateDawg1021 View Post
Still the exploit of people joining your guild with Permissions set up from their old guild. And voila, stolen goods. Last week we had 3 people (same person we assume) Ask everyone anytime someone knew log on saying they were a friend of our guild member. Finally like 5 or 6 people reported him. I told him to back off before he got suspended/banned.

(For those of you that don't know this is a problem and still hasn't been addressed, whenever you invite a new person to your guild immediately change their rank so it resets their bank permissions).
When the banks went live and we saw something about this I did quite a bit of testing back and forth between our main guild and alt guild. The only issue I found was that literally the number of withdrawals I had made that day was never reset, I never saw any problem with access to tabs or the total I was allowed to withdraw. So say as an officer in GuildX I had taken out 5 things, I /gquit or am kicked (tried both) and then join GuildY which has a daily limit of 3 for the default rank. I wasn't able to withdraw at all in the new guild because I was already over my limit for that day even though I hadn't taken anything from Y's bank. No amount of promoting or demoting changed this.

About the only situation I didn't test (for lack of motivation and willing helpers during the day) was forming my own guild and disbanding as guild master. It's possible that the special unlimited access rank is different and the source of the real problem. If that is the case though it does rather limit the problem to people specifically out to scam and willing to put time and effort into it, not just random opportunists.

As for password security, with keyloggers being the name of the game these days no amount of complicated string manipulation or regular changes is going to save you. I wouldn't recommend giving up totally and using your last name for everything (I personally use the tiered approach others have mentioned) but I think switching to Firefox with NoScript, keeping your scanners up to date and avoiding sketchy links is going to do more than anything else. Unless you stand out for some reason it's unlikely that anyone is going to target you specifically for hacking and much more likely that you just click before you think some night at 3am after a crappy pug.
 
User is offline.
Reply With Quote