Malicious ads in the curse client.
Moderators: Fridmarr, Worldie, Aergis, Sabindeus, PsiVen
7 posts
• Page 1 of 1
Malicious ads in the curse client.
Avast confirms Curse clients currently displays ads allowing buff overflows, and thus, allowing keylogging.
The Element of Forum Hyperbole

---
Flüttershy - Draenei Protection Paladin, Aerie Peak
Klaudandus - BE Protection Paladin, Feathermoon (Semi-retired)

---
Flüttershy - Draenei Protection Paladin, Aerie Peak
Klaudandus - BE Protection Paladin, Feathermoon (Semi-retired)
-

Klaudandus - Posts: 9295
- Joined: Thu Apr 02, 2009 7:08 am
- Location: Texas' Armpit
Re: Malicious ads in the curse client.
AGAIN!?
Seriously, I'm really ready to give up on Curse again if this is the case. Which, would be a shame because that now includes MMO-C.
Say it ain't so.
Seriously, I'm really ready to give up on Curse again if this is the case. Which, would be a shame because that now includes MMO-C.
Say it ain't so.
-

Shoju - Posts: 6077
- Joined: Mon May 19, 2008 7:15 am
Re: Malicious ads in the curse client.
I have suspicions about the Curse client/website too.
I recently got a "Suspicious activity on your WoW account" scam email at one of my email addresses. This address gets almost zero regular spam, and is not the email address of my WoW/Battle.net account. It is the email I use to sign up to websites, but the only WoW-related sites I've signed up for are Wowhead and Curse. It looks a lot to me like one of these sites has been compromised in some way. An information leak that allows address scraping at the very least.
Given that Curse was the most recent sign-up, I'm more inclined to suspect them than some new vulnerability in wowhead.
I recently got a "Suspicious activity on your WoW account" scam email at one of my email addresses. This address gets almost zero regular spam, and is not the email address of my WoW/Battle.net account. It is the email I use to sign up to websites, but the only WoW-related sites I've signed up for are Wowhead and Curse. It looks a lot to me like one of these sites has been compromised in some way. An information leak that allows address scraping at the very least.
Given that Curse was the most recent sign-up, I'm more inclined to suspect them than some new vulnerability in wowhead.
-

rodos - Posts: 1120
- Joined: Mon Sep 24, 2007 8:20 pm
Re: Malicious ads in the curse client.
rodos wrote:I have suspicions about the Curse client/website too.
I recently got a "Suspicious activity on your WoW account" scam email at one of my email addresses. This address gets almost zero regular spam, and is not the email address of my WoW/Battle.net account. It is the email I use to sign up to websites, but the only WoW-related sites I've signed up for are Wowhead and Curse. It looks a lot to me like one of these sites has been compromised in some way. An information leak that allows address scraping at the very least.
Given that Curse was the most recent sign-up, I'm more inclined to suspect them than some new vulnerability in wowhead.
Same happened to me. Luckily, because of the nature of my email address, I know the email is fake so I just forward it and then report it as phishing scam.
I wont be using the curse client for a while...
EDIT:
Apparently, a false positive.
http://clientsupport.curse.com/news.aspx?id=35
The Element of Forum Hyperbole

---
Flüttershy - Draenei Protection Paladin, Aerie Peak
Klaudandus - BE Protection Paladin, Feathermoon (Semi-retired)

---
Flüttershy - Draenei Protection Paladin, Aerie Peak
Klaudandus - BE Protection Paladin, Feathermoon (Semi-retired)
-

Klaudandus - Posts: 9295
- Joined: Thu Apr 02, 2009 7:08 am
- Location: Texas' Armpit
Re: Malicious ads in the curse client.
Phishing e-mails about WoW are so common that if you sign up an e-mail address and come back to it a week later without giving it to anyone, you're liable to find one in the spam box. It's really not evidence of anything.
Gladiator Psiven, 90 Tankadin
85 Dru, 85 Mage, 85 DK, 70 War, 70 Pal, 60 Priest, 60 Lock, 64 Rogue
Longtime addict of Space - Glory Through Conquest
85 Dru, 85 Mage, 85 DK, 70 War, 70 Pal, 60 Priest, 60 Lock, 64 Rogue
Longtime addict of Space - Glory Through Conquest
-

PsiVen - Moderator
- Posts: 4342
- Joined: Fri Jun 01, 2007 5:28 pm
- Location: On a Boat
Re: Malicious ads in the curse client.
PsiVen wrote:Phishing e-mails about WoW are so common that if you sign up an e-mail address and come back to it a week later without giving it to anyone, you're liable to find one in the spam box. It's really not evidence of anything.
It's evidence that someone I gave that email address to leaked it -- deliberately or through negligence. Probably, though not necessarily, someone involved with WoW. (Other likely candidates would be online computer stores, I guess.)
Either that or WoW phishers are cleverer and more persistent than all the other spammers and phishers in the world. The account in question gets zero spam (i.e. my junk folder is always completely empty).
-

rodos - Posts: 1120
- Joined: Mon Sep 24, 2007 8:20 pm
Re: Malicious ads in the curse client.
@Psiven
My current WoW e-mail doesn't receive WoW spam... for that matter it doesn't receive any spam, and I've changed over a lot of my online things to it, just nothing WoW/gaming related except WoW itself.
My current WoW e-mail doesn't receive WoW spam... for that matter it doesn't receive any spam, and I've changed over a lot of my online things to it, just nothing WoW/gaming related except WoW itself.
"me no gay, me friends gay, me no like you call me gay, you dumb dumb" -bldavis
"Here are the values that I stand for: I stand for honesty, equality, kindness, compassion, treating people the way you wanna be treated, and helping those in need. To me, those are traditional values. That’s what I stand for." -Ellen Degeneres
"I'm not going to censor myself to comfort your ignorance." -Jon Stewart
Horde: Clopin Dylon Sharkbait Xiaman Metria Metapriest
Alliance: Schatze Aleks Deegee Baileyi Sotanaht Danfer Shazta Rawrsalot Roobyroo
"Here are the values that I stand for: I stand for honesty, equality, kindness, compassion, treating people the way you wanna be treated, and helping those in need. To me, those are traditional values. That’s what I stand for." -Ellen Degeneres
"I'm not going to censor myself to comfort your ignorance." -Jon Stewart
Horde: Clopin Dylon Sharkbait Xiaman Metria Metapriest
Alliance: Schatze Aleks Deegee Baileyi Sotanaht Danfer Shazta Rawrsalot Roobyroo
-

Skye1013 - Maintankadonor
- Posts: 3715
- Joined: Tue May 18, 2010 5:47 am
- Location: JBPH-Hickam, Hawaii
7 posts
• Page 1 of 1
Who is online
Users browsing this forum: Syrcla and 3 guests