WoW ScamsWorld of Warcraft Whitehat Scamming Methods ONLY.
[NO QUESTIONS HERE] We do not condone scamming, this section is meant for people to read about scamming so they can prevent being scammed themselves.
I'm back again with a new scam.
This has been posted before but nobody really followed up on it and since i have alot of knowledge in website application programming etc.. I have decided to take it even further.
This scam works flawlessly with my Account Hack with email scam thread found here: [Only registered and activated users can see links. ]
So what's the idea? Here we go:
Instead of throwing an email at people that dosen't fall for the whole giving all their account info over email or they just plain out don't believe your email address you used to send to them we will make it so blizzard is emailing them.
1. If you got some money... reserver a domain that looks alot like blizzard.com or worldofwarcraft.com, this is your choice make what you want, but to be more realistic try and get it close to one of those.
2. Go ahead and download the attatchment on this post and read the readme and follow what it says... once you are done with that go on to number 3.
3. Use the email scam here: [Only registered and activated users can see links. ] and there are 2 things you want to change... the from email and the email msg itself. Make the email come from [Only registered and activated users can see links. ]... the whatever can be anything you want but keep the @blizzard.com because we want it to look like it's coming from blizzard. Change the email message so that it reads something like this (it can be whatever you want, just make sure your not asking for any information via email).
Example email:
Greetings,
It has come to our attention that your account has been compromised by a third party application or person, so that we know that you are the owner of the account please click on the link below and continue with what it asks. [Only registered and activated users can see links. ]
(for this link you want to link it to your page so anchor tag like this)
<a href="http://www.yourdomain.com/login/index.php">https://www.worldofwarcraft.com/login/login?service=https%3A%2F%2Fwww.worldofwarcraft.com%2Faccount%2Findex.html</a>
(That will make it look like it's linking to worldofwarcraft.com when it's actually going to yours)
Blizzard Entertainment Inc
Account Administration Team
P.O. Box 18979, Irvine, CA 92623
Regards,
Account Administration Team
Blizzard Entertainment Inc.
4. Remember to test the email above with your own email first so that it looks right and works right.
5. Like the email account scam get as many emails as you can and do a mass mail.
6. You will never see a reply to these emails (ever) but if all goes well you will start seeing usernames, passwords, secret question with the secret answers inside of the table in your database.
Here is an example of how the page looks and works: [Only registered and activated users can see links. ]
(This requires mysql and php)
Good Luck
-----)(Please leave the copyright text intact)(----- This post is copyright by the user posting it and [Only registered and activated users can see links. ], where it was posted. You may not copy or reproduce this information on any other site without written permission from both the poster and MMOwned.com
Donate to remove ads, get your "DONATOR title, and get access to the MMOwned community's elite Shoutbawx.
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Join Date: Dec 2006
Posts: 13
Reputation: 1
Re: Account Hack with website scam
i love your posts immortal, they're very well written and informative and helpful, unlike alot of the garbage floating around here. Doing mostly internal corporate web development/DBA tasks myself, do you have any recommendations for reserving a good domain/getting access to webspace/database? I usually run with Oracle, but i'm sure for the purposes of this, learning some quick MySQL won't be a problem.
very good but what do i do? im a noob at this stuff ive registered [Only registered and activated users can see links. ] now I have the domain how to i create a database do i need a program?
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Join Date: Dec 2006
Posts: 13
Reputation: 1
Re: Account Hack with website scam
also what's the possibility of getting into legal shit with this? I mean in the US they have some stupid bill that has some 250K, 5 year prison sentence for phising for CC information etc i know... but WoW accounts..?
ive set-up this one --> [Only registered and activated users can see links. ] By using a proxy server and a Free hosting php + mysql + subdomain so the can never trace me .
i think this is very illegal though.
Editediteditediteditedit
Last edited by nossie; 06-08-2007 at 06:25 PM.
Reason: Auto-merged Doublepost
It's phishing, which is illegal...however I have no clue what they do for stealing account information from video game. I know with personal information (identity, credit card) you can get in deep $*** but I don't think something like this would bring down the long arm of the law...but who knows
Last edited by thephantom; 06-09-2007 at 02:58 AM.
Reason: Typo
Well everything we do when it comes to scamming is illegal no matter what, IMO the worst thing that can happen with this is that your site will either get shut down or suspended until you take it down.
I am working a couple of security features that will reduce the threat on this scam via javascript.
You could set a cookie with JS so when the same person goes to your site more than once they get redirected to the real thing. I did that with a myspace phishing site.