Password scam email warning!

Belorfyn

Fledgling Freddie
Joined
Dec 26, 2003
Messages
319
Well, there's first time for everything. I've never seen password scam email for online game yet on my mailbox, but have now.
Also haven't heard of any attemps on especially EU DAoC.

Yet I got mail like this on both my addresses listed on my homepage (www.duskwave.com/daoc), they're not the email addresses I have used for my subcription though (Haha losers!).

Code:
From - Tue Jan 18 01:13:11 2005
X-Account-Key: account1
X-UIDL: 1067713126.844
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-Path: <***>
Received: from localhost.localdomain (CPE-24-27-132-93.neb.rr.com [24.27.132.93])
	by mailserver2.nebula.fi (8.12.10/8.12.10) with ESMTP id j0HM0PKF031631
	for <belorfyn@duskwave.com>; Tue, 18 Jan 2005 00:00:28 +0200
Received: from localhost.localdomain (localhost.localdomain [127.0.0.1])
	by localhost.localdomain (8.12.8/8.12.8) with ESMTP id j0HM0P8k005921
	for <belorfyn@duskwave.com>; Mon, 17 Jan 2005 16:00:25 -0600
Received: (from jeremy@localhost)
	by localhost.localdomain (8.12.8/8.12.8/Submit) id j0HM0Kv4005918;
	Mon, 17 Jan 2005 16:00:20 -0600
Date: Mon, 17 Jan 2005 16:00:20 -0600
Message-Id: <200501172200.j0HM0Kv4005918@localhost.localdomain>
From: "Dark Age of Camelot Europe" <noreply@goa.com>
Reply-to: noreply@goa.com
Subject: Password Change Request
To: belorfyn@duskwave.com
Content-type: text/html
Status: O
X-UID: 844
Content-Length: 682
X-Keywords:                                                                                                    

<html>
Dear user ,
<p>You have submited a password change request . <a href="***">Click here</a> and you will be forwarded to a password change form.<br>
</p>
<p>If you aren`t the person who submited the request , submit a complaint <a href="***">here</a> and we will investigate this fraud attempt.<br>
</p>

<p>&nbsp;</p>
<p>Warning : NEVER communicate your passwords.You will be asked fot them by members of the Dark Age of Camelot - Europe team only in actions against fraud <br>
  Dark Age of Camelot - Europe team <br>
  <a href="http://www.camelot-europe.com/">http://www.camelot-europe.com/ </a><br>
</p>
</html>

Unfortunately it looks kinda real at first, I assumed first someone had tried to change my password or something. The "report fraud attempt" link is pretty clever I gotta say.

Anyway, since I got this on my public email addresses, many others might get same perhaps through known EU DAoC forums or for example their guild address at chronicles, so be careful.
 

Lookdaddy

One of Freddy's beloved
Joined
Feb 12, 2004
Messages
957
Little fuckers.. i have just recieved the same email..... good job i aint replyed to it yet... i also assumed someone had requested a password change, i was like wtf is this :wanker: :wanker:

Wot you do, just delete and forget about the email??
 

Belorfyn

Fledgling Freddie
Joined
Dec 26, 2003
Messages
319
Lookdaddy said:
Wot you do, just delete and forget about the email??

Yes.

Oh and one warning I just thought of:
If you visit the page mentioned in mail, be sure to use patched browser.. I don't know but it wouldn't surprise me if it tried to use some exploits to insert stuff to your PC.

And if anyone went for it and submitted anything to the pages then go log in to subscriptions quick, check your email address is still correct and change your game password AND report to right now about it right away, you need new subs password too.
Was it so that one can't change their subscription password at the account setings ? If it is so, then all they can do is change the email address and request new game password but they can't change subscription password.

It's not too unlikely someone would think it's real, I almost fell for it but first thing that alerted me was that I received two of the mails (to my both public addresses), I didn't even notice the address the link opened to at first!
 

Belorfyn

Fledgling Freddie
Joined
Dec 26, 2003
Messages
319
I doubt many see this here before checking their mail, best way to protect people would probably be to get that page off the net actually.
It's probably hosted on some poor bugger's hacked home PC or something simlar.. Perhaps GOA will try this. I suppose it usually takes time though, and that host seems to be in Taiwan based on the hostname anyway.
 

Jeriraa

Fledgling Freddie
Joined
Feb 17, 2004
Messages
948
This is serious scam. The site will even ask for your CC details!

The server is based in Taiwan...

If any GM spots this thread I suggest posting a warning on the official site IMMIDETLY!
 

Krakatau

Fledgling Freddie
Joined
Dec 23, 2003
Messages
523
Err...

A ping to the IP shows:
roy1231.lm.fju.edu.tw [140.136.12.31]


Looks like some Taiwanese wanna get into european servers :eek2:

I pity them tbh ;)
 

Jeriraa

Fledgling Freddie
Joined
Feb 17, 2004
Messages
948
They dont want to get into the servers. They dont want your DAoC account. They want your cc details!
 

Edaemos

Fledgling Freddie
Joined
Jul 1, 2004
Messages
908
I just got that email also, funnily enough my email for my accounts is totally different :)
 

Belorfyn

Fledgling Freddie
Joined
Dec 26, 2003
Messages
319
Jeriraa said:
They dont want to get into the servers. They dont want your DAoC account. They want your cc details!

Oh, I never checked what's ahead. I suppose that will alert almost everyone then, but still will have got the subs password if anyone goes that far and they might find some use for the passwords too...
 

Krakatau

Fledgling Freddie
Joined
Dec 23, 2003
Messages
523
Jeriraa said:
They dont want to get into the servers. They dont want your DAoC account. They want your cc details!

Hehe, then I guessed someone was fooled enough to click on some links :touch: :flame:
 

Jeriraa

Fledgling Freddie
Joined
Feb 17, 2004
Messages
948
Krakatau said:
Hehe, then I guessed someone was fooled enough to click on some links :touch: :flame:

No, actually I connected by an ftp browser and had a look at the sourcecode of the files. :p
 

Krakatau

Fledgling Freddie
Joined
Dec 23, 2003
Messages
523
cHodAX said:
No great suprise there, GOA don't exactly excel when it comes to communicating with it's customers.

OMG, Mythic actually must care about this game after all..They do warn us on an official webpage (be it US one) and GOA is clueless as usual ?! :kissit:

Sorry all, I'm loosing it it seems...Ohh, wait... That was GOA's part :flame: :flame:
 

Aussie

Banned
Joined
Dec 26, 2003
Messages
2,439
if they got the email list of the customers.. i wonder what else they got :eek:
 

Aussie

Banned
Joined
Dec 26, 2003
Messages
2,439
the taiwan ip is prolly a proxy, doubt he's that stupid if he starts with somthing like this.

to those who got mail, any way other than goa they could have recieved your email address? personally i didn't get one (yet) nor my brother or my 2 irl friends
 

Mercykiller

Fledgling Freddie
Joined
Jan 10, 2005
Messages
4
NO GOOD FRENCH "##%¤#%¤&%!"/ wake up theres a SCAM going on..
Ahh fuck it lets just all close our accounts for a month and see how they react to that shall we :puke:
 

Sinnica

Fledgling Freddie
Joined
Apr 15, 2004
Messages
731
If you aren`t the person who submited the request , submit a complaint here and we will investigate this fraud attempt.

hahahaha :D

how to pwn yourself :cheers:

EDIT: btw, time to copy that e-mail and register at various random spam sites? *whistles*

<snip>
 

LordjOX

Part of the furniture
Joined
Dec 22, 2003
Messages
3,886
Aya, got the same shit, u'd be well stupid to fall for it tbh
 

Khale

Fledgling Freddie
Joined
Apr 4, 2004
Messages
344
I just received one too. It was quite easy to notice that it wasn't a true GOA email. Hope they can catch the one who is doing these fakes.
 

boppas

Fledgling Freddie
Joined
Feb 12, 2004
Messages
322
lol..

"You will be asked fot them by members of the Dark Age of Camelot "

Would help if he/she spelt "For" right & also the so called "members" of DAoC NEVER ask for your password ;)

Always a f00kin muppet..
 

Xalin

[GOA] English Servers GM
Joined
Nov 2, 2004
Messages
241
We're going to make an announcement about this on our site later today.

In the meanwhile this is a good moment to check if your antivirus and firewall are still up to date.
 

Nerve

Loyal Freddie
Joined
Dec 23, 2003
Messages
320
Xalin said:
We're going to make an announcement about this on our site later today.

In the meanwhile this is a good moment to check if your antivirus and firewall are still up to date.

Yes cause my antivirus and firewall will surely protect me from handing over my CC details and my account password...

:twak:
 

Xalin

[GOA] English Servers GM
Joined
Nov 2, 2004
Messages
241
Nerve said:
Yes cause my antivirus and firewall will surely protect me from handing over my CC details and my account password...

:twak:

No but they will protect against sites that try to get them by using flaws in webbrowsers etc.
 

Daedalus

Can't get enough of FH
Joined
Feb 1, 2004
Messages
1,166
Hmm. That machine is running a very old version of OpenSSH.. does anyone have the tools to.. have some fun? Like.. a few machines to tunnel through?
 

Laroma

Fledgling Freddie
Joined
Dec 22, 2003
Messages
19
Haha, I almost can't stop laughing..

While Sanya over at Camelotherald makes fun of the grammar and typos in the scam email, GOA writes up an announcement that is so infested with grammar bloopers that it almost makes the scam email seem legit..

I'm shocked.. and amused.
 

Belorfyn

Fledgling Freddie
Joined
Dec 26, 2003
Messages
319
Daedalus said:
Hmm. That machine is running a very old version of OpenSSH.. does anyone have the tools to.. have some fun? Like.. a few machines to tunnel through?

Worth noting before someone starts to "have some fun" that the box running that http server is probably hacked and the actual owner is innocent to any of this.
And it's crime to break into it anyway whether it's running new or old software and whether it belongs to someone innocent or the guy who did the scam.
 

Users who are viewing this thread

Top Bottom