- WoW Account
- Blizzard Store Account
- Blizzcon'07 Beta Key
Monday, July 21, 2008
Still Hoping For a Key..
Have three horses in the race:
Friday, July 18, 2008
It's not hard to be a competent hunter.
Your competency is not represented by your guild's progression.
Your competency is not represented by your epic collection.
Your competency is not represented by your arena rating.
Your competency is not represented by your pet.
Your competency is not represented by your DPS meter.
DPS meters and raid logging programs are only of use by two kinds of people, raid leaders and ePeen strokers. A DPS meter can help a hunter find problems in their playstyle and gearing but so can websites like be.imba.hu and mods like Ratings Buster. At that point is a meter really needed? As long as the trash is dying, the bosses are dying, and there are few (if any) wipes then the group is doing FINE.
Your competency is directly, DIRECTLY represented by two things. Your skill in playing the class, and your ability to consistently not be a stupid hunter. Why so many people are unable to be a competent hunter is beyond me. I'll even cut a break for the people that can't master the jumpshot:
Your competency is not represented by your epic collection.
Your competency is not represented by your arena rating.
Your competency is not represented by your pet.
Your competency is not represented by your DPS meter.
DPS meters and raid logging programs are only of use by two kinds of people, raid leaders and ePeen strokers. A DPS meter can help a hunter find problems in their playstyle and gearing but so can websites like be.imba.hu and mods like Ratings Buster. At that point is a meter really needed? As long as the trash is dying, the bosses are dying, and there are few (if any) wipes then the group is doing FINE.
Your competency is directly, DIRECTLY represented by two things. Your skill in playing the class, and your ability to consistently not be a stupid hunter. Why so many people are unable to be a competent hunter is beyond me. I'll even cut a break for the people that can't master the jumpshot:
- Unless your pet is tanking, offtanking, or the main tank requests you do so; DO NOT enable growl in an instance or with a party.
- Unless you have absolutely no choice, DO NOT melee. An instance is no place to be leveling your staff skill, do that on your own time.
- Unless you are trapping behind the party, DO NOT run away from a mob that's aggroing on you. Use "feign death", freezing trap, your pet's intimidate (if talented for it), or just drag the mob back to the main tank.
- Learn to jumpshot. If for whatever reason you can't, learn to use maximum range, traps, distracting and concussive shot to kite as much as you can.
- DO NOT forget to bring at least one stack of food for your pet at all times.
- DO NOT forget to bring at least one stack of health potions, mana potions, and your own drinks.
- For the love of pete, DO NOT FORGET TO BRING ENOUGH AMMO FOR THE ENTIRE RUN.
- +SPI and +STR is not a hunter's friend. I understand that while leveling you will end up being dressed like a clown but please stay away from Spirit and Strength. If you need mana regen that bad look into buying wizard oils to apply to your weapons.
WotLK Beta Up, Invites Going Out Soon.
I've got three horses in this race:
- Blizzcon Beta Key
- WoW Account Opt In
- Blizzard Store Account Opt In
Tuesday, July 15, 2008
Activating the Authenticator
On the 14th I finally got my token and as I sat down to do a nice big writeup with pictures, I nosed over to WoW Insider and found one of my friends there had already done such a post. Well heck there's really no sense in me doing what's already been done, so here are a few paragraphs from Amanda Dean's post "Activating The Authenticator" and a link you can follow to the full post:
The Blizzard Authenticator is currently sold out on the Blizzard Store. I'm sure there will be plenty more to come, when they're ready. I bought one as soon as I heard they were available. Although my experience with the Blizzard Store was not great, it was certainly better than some others. After my order was placed, every time I checked on in, I what appeared to be a rag doll murloc who informed me that an error occurred on the page.
My authenticator has arrived. Thanks to the free shipping from the Blizzard online store, I saved $0.59 in United States Postal Service postage. To be honest, I'm just glad to have my security token. The token come with a single piece of documentation, which directs the user to the security token FAQ page.
I expected the authenticator to be slightly larger. It's approximately the same size as the clicker for my Mustang. I have not yet devised a tether for it, but the device will soon be leashed to my computer.
Continue reading Activating the Authenticator
The Blizzard Authenticator is currently sold out on the Blizzard Store. I'm sure there will be plenty more to come, when they're ready. I bought one as soon as I heard they were available. Although my experience with the Blizzard Store was not great, it was certainly better than some others. After my order was placed, every time I checked on in, I what appeared to be a rag doll murloc who informed me that an error occurred on the page.
My authenticator has arrived. Thanks to the free shipping from the Blizzard online store, I saved $0.59 in United States Postal Service postage. To be honest, I'm just glad to have my security token. The token come with a single piece of documentation, which directs the user to the security token FAQ page.
I expected the authenticator to be slightly larger. It's approximately the same size as the clicker for my Mustang. I have not yet devised a tether for it, but the device will soon be leashed to my computer.
Continue reading Activating the Authenticator
Thursday, July 10, 2008
Blizzard Authenticator Unboxing
For giggles I broke down and ordered an authenticator when they were first released, and it should be arriving in the next day or two. I'll have pictures and usage writeups as soon as I can.
Monday, July 7, 2008
Final View On Token Compromise Attack
Now that we have our theories on how the attack will work and where it will occur, now we have to figure out what the attackers will do once they've got the compromised account. For the most part, attackers would do a few different things. They would shard and sell everything a 'toon has then transfer the gold to another character. They may also just flat out transfer the character off the server. Either way, the password would often be changed from the original so the player could not log in.
With an authenticator, the attacker will only get one shot at an account at a time, so they will have to make a decision as to what method to take. Based on my last entry, a website-based keylogger will still allow an attacker one-time entry into the legitimate "Account Management" page for a compromised account, allowing the attacker to change the password and transfer characters off the server. The problem with that method of attack is even if the character is moved entirely off server the attacker will not be able to gain access to it, a loss of $25 to the attacker. Ergo this method of attack still seems only to be really viable for players that do not use the authenticators.
A program front-end keylogger will allow the attacker to log into the game as that player's toons, but they won't be able to wheel around and get into the "Account Management" website. So this leaves the attacker one option, to shard & sell as many items as they can and then mail the gold to a gold mule. The mule itself will then be transferred off the server, where the gold can be picked up and used for sale on the market.
Now as I had said on my last entry, the open window for a successful attack will be a short period indeed, maybe a maximum of 60 seconds. As of this writing we still don't know anything regarding Blizzard's configuration of the authentication window. Either way with such a small amount of time this means someone will need to be at the machine all the time to take advantage of a compromised account and harvest gold. It's possible such a requirement could force smaller operations out of business due to the increased complications to keep their coffers full of plundered gold. This will probably not affect larger operations quite so much as they will be able to afford a workforce to keep running 24/7.
Of course a bot program to automatically log into compromised accounts and then sell items at the nearest vendor *might* be feasible, but that's beyond the scope of this document.
With an authenticator, the attacker will only get one shot at an account at a time, so they will have to make a decision as to what method to take. Based on my last entry, a website-based keylogger will still allow an attacker one-time entry into the legitimate "Account Management" page for a compromised account, allowing the attacker to change the password and transfer characters off the server. The problem with that method of attack is even if the character is moved entirely off server the attacker will not be able to gain access to it, a loss of $25 to the attacker. Ergo this method of attack still seems only to be really viable for players that do not use the authenticators.
A program front-end keylogger will allow the attacker to log into the game as that player's toons, but they won't be able to wheel around and get into the "Account Management" website. So this leaves the attacker one option, to shard & sell as many items as they can and then mail the gold to a gold mule. The mule itself will then be transferred off the server, where the gold can be picked up and used for sale on the market.
Now as I had said on my last entry, the open window for a successful attack will be a short period indeed, maybe a maximum of 60 seconds. As of this writing we still don't know anything regarding Blizzard's configuration of the authentication window. Either way with such a small amount of time this means someone will need to be at the machine all the time to take advantage of a compromised account and harvest gold. It's possible such a requirement could force smaller operations out of business due to the increased complications to keep their coffers full of plundered gold. This will probably not affect larger operations quite so much as they will be able to afford a workforce to keep running 24/7.
Of course a bot program to automatically log into compromised accounts and then sell items at the nearest vendor *might* be feasible, but that's beyond the scope of this document.
Monday, June 30, 2008
Compromising The Blizzard Authenticator: Man-In-The-Middle
I need to get this out of the way: BLIZZARD I AM NOT CONDONING THIS IN ANY WAY SHAPE OR FORM I LOVE YOU GUYS. I am not a security expert, nor do I claim to be one. My theories of what you are about to read below may have some, most or all of it incorrect; and have been culled from what I've come to understand about how these systems work and what sort of attacks have occurred on them.
As with keyloggers, Blizzard will not be able to prevent these attacks as they are occuring against the player's PC directly. Getting this out in the open will help raise player awareness that the authenticator is not the end of account compromising security risks, and that players still need to diligently maintain their computers, scan for unwanted programs, and change their passwords regularly.
Now then. Compromising the Blizzard authenticator. It will be hard, but it can be done.
First off, some background on the authenticator. Blizzard appears to have contracted the company Vasco and it's line of security tokens called "Digipass Go6". The Go6 has a non-replaceable battery with an expected lifetime of seven years. Go6 is tamper-resistant and supports the DES, 3DES and AES cryptography algorithms. It can also withstand a 1 meter (~3 foot) drop intact. Blizzard's version will look like this:

It uses a secure key between the authenticator (AKA a"keyfob" or "token"), and the Blizzard login servers. On the image above it is six digits, the Vasco brochure states it can display up to eight. It remains to be seen how many digits will be used but I'm sure we'll find out shortly. Every certain number of seconds, both the token and the server will generate a new one-time code. If the code is not entered within the correct timeframe a new one-time code will be generated and the displayed code will be rendered useless. The details of how all this works is far too complicated for this document, and there are plenty of great websites and books out there that cover it in detail if you really would like to learn more.
So to get into World of Warcraft and in theory Starcraft 2 and Diablo 3 if they code for it, the login will go as thus (click to enlarge):

Ok, easy enough, you can see where the pathing goes. Now, how does someone compromise a token-based login?
Technically speaking what I am about to describe is more of a phishing attack than a true MITM, but I feel the terminology still works. These attacks can occur one of two ways. The first way is a simple tried and true spoofed webpage. Old, reliable, works without fail. Create a false website that pretends to be Blizzard's account management site. Have the proper fields to fill out for account name, password and code. Upon clicking submit the user is redirected somewhere else, while their information is forwarded to the attacker.
How does this work if the attacker wants to go to the source, IE the game itself? This method will prove more time consuming and costly as they will have to code up an entire program that mimics the launcher and/or portal login screen. I figure the flowchart for such a program will look like one of these three ideas (click to enlarge):
My new ideas came to me after I had originally posted this on 6/30 and I felt I should show how each one will break down. I believe all of these can be considered "Man-In-The-Middle" style attacks.
The complicated version is a bit of a mess, and will require the attacker's program to pass authentication data to the Blizzard login servers. I have been informed the complicated idea would not work as after the token code is passed to Blizzard it is rendered useless to be used a second time. I should have realized this. --7/01/08
The simple version is very straightforward. The attacker's program never passes any data to Blizzard, just collecting it until the code is entered. I feel this is the most likely angle of attack, but it assumes the target uses the authenticator. If they are not using one then the program is rendered useless.
The token/non-token version may be the best compromise between the two previous versions. The attacker's program will make one single call to the Blizzard login servers and depending on the reply will either ask for the one-time code or go directly to the notification and termination portion of the program. This version allows the attacker access to player accounts that have not purchased the authenticator, effectively operating as a sophisticated keylogger.
Once everything has been entered the attacker can be notified one of many ways. There are 4-5 ways listed here but I'm sure there could be more options. Once the notification has been sent, the program will generate an error, crash, or both. Either way the user will believe that either there is a problem with Blizzard's servers, their installation of WoW, or possibly even their computer.
It's not known how short the key generation window is, or how long the window will stay open once a user has verified their login and password. RSA SecurID keys have a 60 second key generation and use window, meaning every minute a new key is generated and must be used within that minute or else it is no longer valid. If Blizzard keeps to a 60 second key window and if on average it takes about five seconds for a user to input their key, in this scenario the attacker would have about 50 seconds to log in using your pilfered data.
As it stands no one knows the details of the new login system except for Blizzard and Vasco. We may come to learn a few little things about it in the future, but by and large it the inner workings of the token security system will be unknown.
In summation, token authentication is very secure, however a properly executed attack will still be able to circumvent the latest layer of security. Like I said in the beginning of this post these attacks are not things that Blizzard can control. Please be responsible and as I said in the beginning of this post, diligently maintain your computers. Regularly scan for viruses, trojans, malware, and please change your passwords regularly.
As with keyloggers, Blizzard will not be able to prevent these attacks as they are occuring against the player's PC directly. Getting this out in the open will help raise player awareness that the authenticator is not the end of account compromising security risks, and that players still need to diligently maintain their computers, scan for unwanted programs, and change their passwords regularly.
Now then. Compromising the Blizzard authenticator. It will be hard, but it can be done.
First off, some background on the authenticator. Blizzard appears to have contracted the company Vasco and it's line of security tokens called "Digipass Go6". The Go6 has a non-replaceable battery with an expected lifetime of seven years. Go6 is tamper-resistant and supports the DES, 3DES and AES cryptography algorithms. It can also withstand a 1 meter (~3 foot) drop intact. Blizzard's version will look like this:
It uses a secure key between the authenticator (AKA a"keyfob" or "token"), and the Blizzard login servers. On the image above it is six digits, the Vasco brochure states it can display up to eight. It remains to be seen how many digits will be used but I'm sure we'll find out shortly. Every certain number of seconds, both the token and the server will generate a new one-time code. If the code is not entered within the correct timeframe a new one-time code will be generated and the displayed code will be rendered useless. The details of how all this works is far too complicated for this document, and there are plenty of great websites and books out there that cover it in detail if you really would like to learn more.
So to get into World of Warcraft and in theory Starcraft 2 and Diablo 3 if they code for it, the login will go as thus (click to enlarge):
Ok, easy enough, you can see where the pathing goes. Now, how does someone compromise a token-based login?
Man-In-The-Middle (wiki link)
Technically speaking what I am about to describe is more of a phishing attack than a true MITM, but I feel the terminology still works. These attacks can occur one of two ways. The first way is a simple tried and true spoofed webpage. Old, reliable, works without fail. Create a false website that pretends to be Blizzard's account management site. Have the proper fields to fill out for account name, password and code. Upon clicking submit the user is redirected somewhere else, while their information is forwarded to the attacker.
How does this work if the attacker wants to go to the source, IE the game itself? This method will prove more time consuming and costly as they will have to code up an entire program that mimics the launcher and/or portal login screen. I figure the flowchart for such a program will look like one of these three ideas (click to enlarge):
| Complicated Token: | Simplistic Token: |
| Token/Non-Token Version: | |
My new ideas came to me after I had originally posted this on 6/30 and I felt I should show how each one will break down. I believe all of these can be considered "Man-In-The-Middle" style attacks.
The simple version is very straightforward. The attacker's program never passes any data to Blizzard, just collecting it until the code is entered. I feel this is the most likely angle of attack, but it assumes the target uses the authenticator. If they are not using one then the program is rendered useless.
The token/non-token version may be the best compromise between the two previous versions. The attacker's program will make one single call to the Blizzard login servers and depending on the reply will either ask for the one-time code or go directly to the notification and termination portion of the program. This version allows the attacker access to player accounts that have not purchased the authenticator, effectively operating as a sophisticated keylogger.
Once everything has been entered the attacker can be notified one of many ways. There are 4-5 ways listed here but I'm sure there could be more options. Once the notification has been sent, the program will generate an error, crash, or both. Either way the user will believe that either there is a problem with Blizzard's servers, their installation of WoW, or possibly even their computer.
It's not known how short the key generation window is, or how long the window will stay open once a user has verified their login and password. RSA SecurID keys have a 60 second key generation and use window, meaning every minute a new key is generated and must be used within that minute or else it is no longer valid. If Blizzard keeps to a 60 second key window and if on average it takes about five seconds for a user to input their key, in this scenario the attacker would have about 50 seconds to log in using your pilfered data.
As it stands no one knows the details of the new login system except for Blizzard and Vasco. We may come to learn a few little things about it in the future, but by and large it the inner workings of the token security system will be unknown.
In summation, token authentication is very secure, however a properly executed attack will still be able to circumvent the latest layer of security. Like I said in the beginning of this post these attacks are not things that Blizzard can control. Please be responsible and as I said in the beginning of this post, diligently maintain your computers. Regularly scan for viruses, trojans, malware, and please change your passwords regularly.
Subscribe to:
Posts (Atom)