Index
Would you like to react to this message? Create an account in a few clicks or log in to continue.

The complete guide to not getting hacked!

+3
NT1
Green Comet
Evilrat
7 posters

Go down

The complete guide to not getting hacked! Empty The complete guide to not getting hacked!

Post by Evilrat 5/8/2012, 11:22 pm

As i've seen a large jump in people getting hacked, including my self, i've decided to write a guide on how to prevent this from happening. It mostly takes "common sense" but there's a few extras in it. Now firstly, lets start with the basics.


~~~~~BASICS OF PREVENTION~~~~~



~Basic safety



Now, whenever you're going to some Runescape related site, you will want to use a different username and password than is used for your Runescape account. This is because occasionally there's a "legit" fan site that when it achieves a large fan base, the creators can take you'r info, IP's, etc. and steal your accounts.

Occasionally you'll get a pm from randoms asking for help to hold some gold or account or something. Generally, the gold one isn't true. They'll offer you gold and eventually most likely link you to the "forums" asking for a vouch or post or for you to look at it or something of the sort. This is most likely something called a "Phishing scam". This is where someone takes, for example, the Runescape login pages html code, modifies it where it sends the details to a form. To see how to really spot the "Phish sites" you'll have to look below. Now, to the account. When someone ask's you to hold an account, it's usually an attempt for you to logon to it so they can obtain your IP. DO NOT DO THIS! For full details on what they can do if they obtain your IP, please look below.



~How to spot phishing sites and why you need to protect your IP



Now, you'll generally spot phishing sites through someone, for example, offering a moderator application. It will ALWAYS have a fake address. An example in the spoiler.

Spoiler:

As you can see the above picture is not marked by the https:// protocol, does not have the "Jagex Limited [GB]" bar (as shown below) and does not have a "Safety lock".

Only trust RS login pages that have this in the Address bar. It will always have the protocol, https:// instead of http:// This is simply a more secure version. It will also most likely have a green lock picture as shown below. Along with the green bar that say, "Jagex Limited [GB]"
Spoiler:


Of course there's occasionally a complex URL. You can still simply spot that it's a "Phishing site" because it doesnt have the https:// , the Jagex bar, or even the "Safety lock" .

Now, on to why you need to protect your IP! If someone acquires your IP, it can be used to further "Dox" or acquire personal information. This can be used to get enough info to Recover your account. A little thing called a "RAT" ("Remote Administration Terminal") can attack your IP and obtain access to your computer. Please read the Wiki page for further details on it. If someone obtains your IP, it can also be used to "DDoS" ("Denial of service attack") which simply stops your internet. It can allow people to stop your internet, get onto your account, and steal all your items. So simply, protect your IP.


~Protecting your name


You'll generally want to keep your Runescape name confidential. It is of major importance but it's to protect you account from being targeted. Especially when dealing with, lets say selling accounts, all ways use a separate "Gold Mule" account. You make your transactions through this account and later on transfer the money to your main account if you so wish to. Note: This can be dangerous if transferring large amounts of GP to your "Main" on a single computer. It's greatly preferred that you do this on separate computers. If you so wish to transfer the gold on a single computer, please read this Guide by Rich Beetch.


~Common sense


Lets say you're doing services or looking to get some services done. You'll not only want to be wary of who you're having do your services but also who you're doing services for. When you're having services done for your account, you should know that YOU ARE GIVING YOUR ACCOUNT TO SOMEONE WHOM YOU DO NOT KNOW. So basically, only have services done by trusted people! This does not mean they have to have a Trusted/Highly Trusted badge. Now, when you're doing services for someone, you'r essentially giving them you IP address. As you've seen above, this is not smart. So, choose carefully who you do services for and of course, use that extra account and don't give them your account name to!

Also, everytime you login, you'll want to check the IP as is show on the info page. Example below. If it's different from your's someones most likely been on your account.

Spoiler:



~Java Drive-By


This is probably the most annoying and hard to prevent thing. It's as simple as this, NEVER click yes when something asks to run a Java applet. The only time you will is if it's on the client and/or on the official site! Only click it if you truly 100% trust that thing all though even then, it might've been hacked and a JDB set up as has happened to SwiftKit.



This is all for now, i'll add more stuff as I become more experienced and i'm looking for all feedback! I hope this helps everyone here! This took me quite awhile to compose. Very Happy

All this was done in Google Chrome


Last edited by Evilrat on 8/8/2012, 3:06 pm; edited 2 times in total
Evilrat
Evilrat
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


http://truivia.forumotions.net

Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Green Comet 8/8/2012, 11:36 am

Great guide, mainly common sense but surely helpful to someone.
Never heard about Swiftkit being hacked, been using it forever.
When'd it happen?

Green Comet
Tier 2 (100 posts)
Tier 2 (100 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Evilrat 8/8/2012, 2:07 pm

A month ago I think? Someone got into it and made it request to run a JDB when people logged on.
Evilrat
Evilrat
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


http://truivia.forumotions.net

Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by NT1 8/8/2012, 2:48 pm

Nice guide, but I have a few questions. Smile

You say keep your RSN hidden, but if someone sees you in ge looking rich could they just hack you by seeing you in ge?

I know the admins get our ip when we go on forums, and I trust them with this, but could just normal forum members find out our ip address?

I basically go on minecraft, rs, youtube, and twitch (to watch rs/mc livestreams) I only watch famous youtubers and for livestreams I watch popular ones such as Mx799, sm hosts, and my friend. Could they get my ip, also could youtube people get my ip?

Thanks Smile
NT1
NT1
Forum Master (1500 posts)
Forum Master (1500 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Green Comet 8/8/2012, 2:54 pm

NT1 wrote:Nice guide, but I have a few questions. Smile

You say keep your RSN hidden, but if someone sees you in ge looking rich could they just hack you by seeing you in ge?

I know the admins get our ip when we go on forums, and I trust them with this, but could just normal forum members find out our ip address?

I basically go on minecraft, rs, youtube, and twitch (to watch rs/mc livestreams) I only watch famous youtubers and for livestreams I watch popular ones such as Mx799, sm hosts, and my friend. Could they get my ip, also could youtube people get my ip?

Thanks Smile
Minecraft, twitch yes. RS and youtube are safe however.
Just avoid suspicious links.
I think my RSN hidden he meant your login name, if it differs that is.

Green Comet
Tier 2 (100 posts)
Tier 2 (100 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Evilrat 8/8/2012, 2:55 pm

If they find your RSN and decide that you're a target, they can't just see you and you're hacked. They Dox you and use that information to recover your account. They pretty much will never hack an active account as it complicates things and makes it where you can get their IP.

Only way a normal forum member could get your IP from the forums there selves is if they somehow got into the forums Database.

Neither people could get your IP from Twitch or Youtube unless they somehow got access to the Databases. Which is just nigh of impossible as both are extremely popular and secure.

And I mean RSN because they can use something such as Pipl to search your name and find things related to it. Such as emails, facebook (where they get the most information usually), etc.
Evilrat
Evilrat
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


http://truivia.forumotions.net

Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Green Comet 8/8/2012, 3:41 pm

Evilrat wrote:If they find your RSN and decide that you're a target, they can't just see you and you're hacked. They Dox you and use that information to recover your account. They pretty much will never hack an active account as it complicates things and makes it where you can get their IP.

Only way a normal forum member could get your IP from the forums there selves is if they somehow got into the forums Database.

Neither people could get your IP from Twitch or Youtube unless they somehow got access to the Databases. Which is just nigh of impossible as both are extremely popular and secure.

And I mean RSN because they can use something such as Pipl to search your name and find things related to it. Such as emails, facebook (where they get the most information usually), etc.
Actually Twitch isn't exactly safe, been proven on me via Diablo 3 way too many times this month <.<
Lost two hardcore characters Sad

Green Comet
Tier 2 (100 posts)
Tier 2 (100 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Evilrat 8/8/2012, 3:44 pm

Just watching streams on Twitch doesn't make it bad, flaunting around and making yourself a target and/or streaming itself can be bad.
Evilrat
Evilrat
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


http://truivia.forumotions.net

Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Green Comet 8/8/2012, 4:27 pm

I'm not saying it's bad.
I've never streamed, all I did was chat on a popular stream.
Had an argument with someone and got ddosed 5 minutes later.

Green Comet
Tier 2 (100 posts)
Tier 2 (100 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Evilrat 8/8/2012, 4:37 pm

Extremely hard to believe. Also, this guy must've gotten you IP someway else or a possible coincidence. Mehhh, you never know. Neutral
Evilrat
Evilrat
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


http://truivia.forumotions.net

Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Green Comet 8/8/2012, 4:53 pm

I doubt every other skid is capable of getting it via Twitch unless you're streaming but it's definitely possible.

Green Comet
Tier 2 (100 posts)
Tier 2 (100 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Seanofdead 13/8/2012, 8:47 pm

Good guide but could be misleading to someone who isn't completely knowledgeable in this topic. Mainly because you stated that "Only trust RS login pages that have this in the Address bar. It will always have the protocol, https:// instead of http:// This is simply a more secure version." Which in theory you are right but like I said to someone who has no clue about this and they get for example an email that is truly a phishing website it looks almost real. I have taken a few pictures of the ones I have in my email right now. I normally get 2-3 of these every two days.
I would recommend you include something about fake emails from "Jagex Ltd" and "Runescape" that are sent around alot saying some bs about your account is in the danger zone or has gotten an infraction like the picture below are 2 examples.


Example of Fake Emails that look 100% Real.
Spoiler:

Inside of the first one that is identically to what Jagex really sends to you if you have an infraction. But the highlighted parts are the important things to look at
Yellow= The exact same link you would get from Jagex yet again if this was a real infraction on your account
Red= The part where you can tell the difference between a fake and a real infraction ahhh a sigh of relief the moment you've been waiting for. If you look closely at the box in red it is not the same address as the box in yellow and that's bad. it should be the same. The way to tell if you didnt know was hover your mouse over the link but dont click it. try it on www.google.com if you did it right on the bottom left corner you should see the exact same address as what it says.
Facepalm Hackers do everything they can to fool you but this is one thing they have yet to figure out how to change (they cant) and the only way to tell if this email is real or not is by what I just explained to you.
Spoiler:


Here is the second Email that I received the highlights are the exact same as the above in case you wanted to see another example.
Spoiler:


But overall good guide Evil if you would like you could copy and paste this in your guide if you feel it guide worthy Razz otherwise you can take what you want out of it. Smile Just trying to help people avoid being unnecessarily hacked.


+rep if it helped.
Seanofdead
Seanofdead
Tier 4 (500 posts)
Tier 4 (500 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by SyrianXSnake 24/8/2012, 4:32 pm

Add to that getting a good INTERNET SECURITY, yes because it helps to protecting your online safety, like it warns you if there is an expectation or something.

SyrianXSnake
Tier 1 (Registered)
Tier 1 (Registered)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by herpiederp69 3/9/2012, 12:02 am

Or we can all just be insane security freaks and close all cookie sources set to be accepted from my browser, except for SM and RS.

Really, hacking can't be completely prevented, no matter how much you educate children: a lot of knowledge requires maturity.

Another great topic you should include in this discussion is actually quite primary.

The use of the RS forums as a tip off on how to help computer security, and white-hatting in general.

herpiederp69
Tier 1 (Registered)
Tier 1 (Registered)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Evilrat 3/9/2012, 12:03 am

And at that, expect a large update to this thread soon. Very Happy
Evilrat
Evilrat
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


http://truivia.forumotions.net

Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Inomonu 3/9/2012, 12:19 am

How about going into DDoS a bit more - I'm sure a lot of people don't know about the various ways one can access an IP, e.g. Skype.
Inomonu
Inomonu
Forum Fanatic (1000 posts)
Forum Fanatic (1000 posts)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by herpiederp69 3/9/2012, 6:40 am

Inomonu wrote:How about going into DDoS a bit more - I'm sure a lot of people don't know about the various ways one can access an IP, e.g. Skype.

^ This, and how plenty of information is publicly available via Dox, with less than 30$ a year; you can essentially access an unlimited number of people's personal information, from full name - to legal records, like criminal history and birth certificates.

herpiederp69
Tier 1 (Registered)
Tier 1 (Registered)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by herpiederp69 3/9/2012, 6:41 am

Evilrat wrote:And at that, expect a large update to this thread soon. Very Happy

Thanks for the updates, even though most of it is common sense, it's great to see someone willing to help the community.

I +repped this post, even though my reputation is at +1, haha. cheers

herpiederp69
Tier 1 (Registered)
Tier 1 (Registered)


Back to top Go down

The complete guide to not getting hacked! Empty Re: The complete guide to not getting hacked!

Post by Sponsored content


Sponsored content


Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum