Network: WoW Gold | WoW Accounts | MPS Games | FPSowned
MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides
Homepage »      Register »      Hall of Fame »      Ranks And Awards »      Advertise »      Marketplace »
 
Sign up



Do you like this excellent information? Then Donate HERE to remove ads and support the MMOwned community.


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > World of Warcraft > WoW Scams

WoW Scams World of Warcraft Whitehat Scamming Methods ONLY.
[NO QUESTIONS HERE]
We do not condone scamming, this section is meant for people to read about scamming so they can prevent being scammed themselves.

Reply
 
LinkBack Thread Tools
  #1  
Old 02-19-2009
Wastrel is offline.
Sergeant
  
 
Join Date: Aug 2008
Posts: 54
Reputation: 78
Points: 428, Level: 1
Points: 428, Level: 1 Points: 428, Level: 1 Points: 428, Level: 1
Level up: 6%, 472 Points needed
Level up: 6% Level up: 6% Level up: 6%
Activity: 0.9%
Activity: 0.9% Activity: 0.9% Activity: 0.9%
Wastrel's "perfect" account Phishing scam

I'm bored, and when I get bored I do things just to see if they can be done.

I'm no scammer, I dislike the idea of someone taking my account and don't want to inflict that on someone else. Recently, though, I thought "Could do it? Could I scam an account if I wanted to?"

Naturally this lead to thoughts of "the perfect scam", how to reliably get the information I needed without arousing suspicion, that way the recently bunko'd wouldn't immediately change his info and slam me out again.

I can say these are my conclusions.
Of 58 emails sent out, I received 36 unique returns. of those 36, 28 were viable account information, the other 8 were bogus info. Most of the unique 36 were repeated as the user attempted to log in again from my source email.

I personally logged into each of the 28 accounts (this took forever) and looked at their toon select screens. I did NOT log in their toons or take anything from the accounts, this was a mental exercise, nothing more.

Enough of the preface, this is the detail.

- - - - - - - - - - - -

What this is: A medium complexity phishing scam.

Why this is unique: This scam uses social engineering to interest the account holder without direct threats or "too good to be true" offers.

What this won't do: It will not give you account-based info like secret question/answer, CD key, or names/addresses.

What this guide won't do: I will not provide templates or HTML. I did this as a mental exercise, if you want to do this you must put in the work as well.

The What: This scam has two parts, the bait and the hook.

The Bait.
Fabricate an HTML email similar to the "blizzard insider" or other promotional Blizzard emails. This will require HTML skills or an editor, some Photoshop work, and a good understanding of what the email should look like in the end.
The email should be an announcement, played out as most real emails are, the biggest headline being "Sign up for the Blizzard Account and receive "Flapper" the in-game non-combat pet."(I used a model-pic of a proto-drake whelp recolored bright green with Photoshop).

This email should contain a well written paragraph or two on the Blizzard Account system, saying how the Blizzard Account will be used just like your WoW account is now, and how you can sign up multiple accounts to one Blizzard account. Throw in some stuff about how your blizzard account will also be used for Diablo III and Starcraft II, and how Blizzard account holders will be eligible for special deals and pricing that will be announced later. Hit up the real Blizzard account pages for real information on this.

Make sure to include a masked URL to a PHP-enabled site you control, as well as various links to other real blizzard services and opt-out links.

Email this to your email-list (I used a list compiled from guild websites) using a spoofed header ([Only registered and activated users can see links. ])
If you do this right the user will click the email link and head to your Hook.

The Hook

This is a PHP/SQL enabled webpage you design to look EXACTLY like the standard account admin sign-in page.
There are templates available for the lazy*, but I made my own. The page contains all the legit links for Blizzard sites, so if your mark chooses to click them they work as suspected.


* This thread ([Only registered and activated users can see links. ]) contains a nice phisher page setup, though I'm not sure what changes would need be made to allow the next step to proceed as planned, if any.

For multiple Phishing resources see this link: [Only registered and activated users can see links. ]


The Login box serves must do two things. One, it writes the user-name and Password into your database for easy retrieval (or sends an email, of you didn't write your own), the second, and this is the important bit, it links to the REAL account admin login page.

That's right, they enter their user-name and pass, then get linked to the regular login, where they will be prompted again to log in.
The second time works normally and they log in thinking "well, second time's the charm"

Once they're on the real WoW pages they can sign up for a blizzard account as normal, never the wiser.

The kicker here is, the system is already live and in place, but most WoW users don't have Blizzard accounts yet. By offering an in-game reward you entice the user to go sign up for the free service and lose his account info on the way.



Why it Works

If done correctly you have a legit-looking HTML email extolling the virtues of a real service that you then really link to. The mark often knows about this service, but many haven't bothered signing up because it's a bit of a hassle outside of what they already have.

The bait is plausible and reliable based on what Blizzard has done in the past. they often give out non-tactical game items in promotions.

The Hook is also plausible, as they authorize and pass through your page to land exactly where they suspected they would. They need to log in again, but who hasn't had site problems that required the same? Once logged in there's the service they were looking for, right there where it needs to be.

The Phishing page isn't overly complex, and it's not on the user's browser long enough for most to notice the address isn't quite right. Often Phishing pages linger too long, looking for too much information. This gives too much time for the mark to notice they aren't where they think they are.

Done correctly this should give long-term access to the account, I can still log into the ones I have, and I've had them for weeks.



There you go, MMOwned, Wastrel's perfect Phishing scam. This is 100% written by me, as are all Wastrel's guides.
Repost as you wish, but leave all links and text intact and always give credit to your original author.
__________________
Wastrel's drinking game: Take a drink every time I say the word "Toon"
Reply With Quote


Donate to remove ads, get your "DONATOR title, and get access to the MMOwned community's elite Shoutbawx.

  #2  
Old 02-19-2009
rubindd is offline.
Banned
  
 
Join Date: Dec 2008
Posts: 53
Reputation: 1
Mmm, i like it.

Think you should straighten it out a little cause its hard to skip through it and find what i need to find. Not exactly unique though.
Reply With Quote
  #3  
Old 02-19-2009
EddyEvil's Avatar
EddyEvil is offline.
Sergeant
  
 
Join Date: Jul 2007
Location: Seattle, WA
Posts: 34
Reputation: 16
Points: 747, Level: 1
Points: 747, Level: 1 Points: 747, Level: 1 Points: 747, Level: 1
Level up: 70%, 153 Points needed
Level up: 70% Level up: 70% Level up: 70%
Activity: 0.4%
Activity: 0.4% Activity: 0.4% Activity: 0.4%

I like this.
__________________
I have become... evil.
Reply With Quote
  #4  
Old 02-20-2009
dhlord64 is offline.
New User
  
 
Join Date: Feb 2009
Posts: 15
Reputation: 1
Thats nice!
Reply With Quote
  #5  
Old 02-20-2009
lama362 is offline.
Corporal
  
 
Join Date: Jun 2008
Posts: 25
Reputation: 6
Gj mate, nice guide
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -4. The time now is 07:38 AM.




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.1

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493