<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>PlayNoEvil - Game Security, IT Security, and Secure Game Design Services - Contact Us at ceo@secureplay.com - Payment Processing and Financial Fraud</title>
    <link>http://playnoevil.com/serendipity/</link>
    <description>Cheating, Piracy, Griefing, Protecting Kids, and Making Money</description>
    <dc:language>en</dc:language>
    <admin:errorReportsTo rdf:resource="mailto:" />
    <generator>Serendipity 1.1.3 - http://www.s9y.org/</generator>
    <pubDate>Thu, 15 Apr 2010 01:41:26 GMT</pubDate>

    <image>
        <url>http://playnoevil.com/serendipity/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: PlayNoEvil - Game Security, IT Security, and Secure Game Design Services - Contact Us at ceo@secureplay.com - Payment Processing and Financial Fraud - Cheating, Piracy, Griefing, Protecting Kids, and Making Money</title>
        <link>http://playnoevil.com/serendipity/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>NCsoft selects Kount Anti-Fraud to protect its MMOs</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2912-NCsoft-selects-Kount-Anti-Fraud-to-protect-its-MMOs.html</link>
            <category>Payment Processing and Financial Fraud</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2912-NCsoft-selects-Kount-Anti-Fraud-to-protect-its-MMOs.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2912</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2912</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    &lt;strong&gt;NCsoft &lt;/strong&gt;has chosen &lt;strong&gt;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=10184&amp;amp;entry_id=2912&quot; title=&quot;http://www.kount.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.kount.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Kount&lt;/a&gt;&lt;/strong&gt;&#039;s &lt;strong&gt;fraud management&lt;/strong&gt; solution, according to a press release. The company has a range of technologies including &lt;strong&gt;device fingerprinting&lt;/strong&gt; and &quot;&lt;strong&gt;proxy piercing&lt;/strong&gt;&quot; and the usual features: &lt;strong&gt;geo-location&lt;/strong&gt;, and lots of &quot;&lt;strong&gt;data streams&lt;/strong&gt;&quot;, etc.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&quot;Fraud is readily apparent in our industry, plaguing online game publishers worldwide,&quot; said Steve Levy, global director of NCsoft Publishing Operations. &quot;The implementation of Kount helps us alleviate fraud, allowing us to provide a safe and secure gaming environment for our fans.&quot;&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Proxy piercing sounds kind of cool. My guess is that their is a piece of code that &quot;phones home&quot; to the company or some such with a unique ID that matches up with information that the game server gets.&lt;br /&gt;
&lt;br /&gt;
The service also automates review of purchases which may be the real driver for NCsoft... reducing operational costs..&lt;br /&gt;
&lt;br /&gt;
&quot;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=10185&amp;amp;entry_id=2912&quot; title=&quot;http://www.prnewswire.com/news-releases/kount-provides-fraud-control-to-global-online-game-publisher-ncsoft-90603739.html&quot;  onmouseover=&quot;window.status=&#039;http://www.prnewswire.com/news-releases/kount-provides-fraud-control-to-global-online-game-publisher-ncsoft-90603739.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Kount Provides Fraud Control to Global Online Game Publisher NCsoft&lt;/a&gt;&quot;, http://www.prnewswire.com/news-releases/kount-provides-fraud-control-to-global-online-game-publisher-ncsoft-90603739.html 
    </content:encoded>

    <pubDate>Thu, 15 Apr 2010 05:07:00 -0700</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2912-guid.html</guid>
    
</item>
<item>
    <title>Real Threat in Virtual Battleground: Hackers - QUOTED </title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2859-Real-Threat-in-Virtual-Battleground-Hackers-QUOTED.html</link>
            <category>Game Security</category>
            <category>Payment Processing and Financial Fraud</category>
            <category>Real Money Transactions ( RMT )</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2859-Real-Threat-in-Virtual-Battleground-Hackers-QUOTED.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2859</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2859</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    A. Martínez-Cabrera (2010), &quot;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9907&amp;amp;entry_id=2859&quot; title=&quot;http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/02/26/BU5D1C7QI1.DTL&quot;  onmouseover=&quot;window.status=&#039;http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/02/26/BU5D1C7QI1.DTL&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Real Threat in Virtual Battleground: Hackers&lt;/a&gt;&quot;, http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/02/26/BU5D1C7QI1.DTL&lt;br /&gt;
&lt;br /&gt;
I&#039;m quoted several times in this article about the threat of hackers/fraudsters to online games in the &lt;strong&gt;San Fransisco Chronicle&lt;/strong&gt;.  
    </content:encoded>

    <pubDate>Sun, 28 Feb 2010 13:05:58 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2859-guid.html</guid>
    
</item>
<item>
    <title>NOTED: Good Message from NCSoft on Aion Security</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2823-NOTED-Good-Message-from-NCSoft-on-Aion-Security.html</link>
            <category>Bots, Memory Editors, Macros, Triggers, and Duping</category>
            <category>Game Security</category>
            <category>Gold Frauders, Virtual Theft &amp; Property Rights</category>
            <category>Identity, Anonymity, and Account Phishing</category>
            <category>IT Security and Privacy</category>
            <category>Payment Processing and Financial Fraud</category>
            <category>Real Money Transactions ( RMT )</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2823-NOTED-Good-Message-from-NCSoft-on-Aion-Security.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2823</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2823</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    Scott Jennings and NCSoft have put out a good, thorough message on the state of the game&#039;s security issues. &lt;br /&gt;
&lt;br /&gt;
The message was posted very early this morning (the 20th) and within the first couple of hours has been viewed almost 10,000 times.&lt;br /&gt;
&lt;br /&gt;
People really care about the security of their accounts and their game.&lt;br /&gt;
&lt;br /&gt;
Security messages on the site get a lot of visits (see stats at the bottom of Scott&#039;s message). The last message on account security, from December 24th has had  over 131,000 views - far more than any other recent message thread.&lt;br /&gt;
&lt;br /&gt;
It will be interesting to see if this is followed up with any press releases or interviews to the games media.&lt;br /&gt;
&lt;br /&gt;
Hopefully, like Jagex, NCSoft will also pursue legal recourse against criminals who engage in account theft (a clear crime under computer security laws).&lt;br /&gt;
&lt;br /&gt;
S. Jennings (2010), &quot;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9717&amp;amp;entry_id=2823&quot; title=&quot;http://na.aiononline.com/board/notices/view?articleID=197&amp;amp;page=&quot;  onmouseover=&quot;window.status=&#039;http://na.aiononline.com/board/notices/view?articleID=197&amp;amp;page=&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;GSUs Message on Account Security&lt;/a&gt;&quot;, http://na.aiononline.com/board/notices/view?articleID=197&amp;page=&lt;br /&gt;
&lt;br /&gt;
via&lt;br /&gt;
&lt;br /&gt;
S. Jennings (2010), &quot;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9718&amp;amp;entry_id=2823&quot; title=&quot;http://brokentoys.org/2010/01/19/a-note-from-my-day-job/&quot;  onmouseover=&quot;window.status=&#039;http://brokentoys.org/2010/01/19/a-note-from-my-day-job/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;A Note From My Day Job&lt;/a&gt;&quot;, http://brokentoys.org/2010/01/19/a-note-from-my-day-job/ 
    </content:encoded>

    <pubDate>Wed, 20 Jan 2010 05:28:30 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2823-guid.html</guid>
    
</item>
<item>
    <title>Confessions of a Game Scammer (and Identity Thief)</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2819-Confessions-of-a-Game-Scammer-and-Identity-Thief.html</link>
            <category>Code Compromise, Theft, Privacy Breach, Data Disclosure, and Insider Problems</category>
            <category>Gold Frauders, Virtual Theft &amp; Property Rights</category>
            <category>Identity, Anonymity, and Account Phishing</category>
            <category>IT Security and Privacy</category>
            <category>Payment Processing and Financial Fraud</category>
            <category>Real Money Transactions ( RMT )</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2819-Confessions-of-a-Game-Scammer-and-Identity-Thief.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2819</wfw:comment>

    <slash:comments>8</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2819</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    &lt;strong&gt;Marcus Eikenberry&lt;/strong&gt; of &lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9692&amp;amp;entry_id=2819&quot; title=&quot;http://www.markeedragon.com/forums/ubbthreads.php/topics/3151925/Criminal_Mind_Interview_with_a&quot;  onmouseover=&quot;window.status=&#039;http://www.markeedragon.com/forums/ubbthreads.php/topics/3151925/Criminal_Mind_Interview_with_a&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;MarkeeDragon &lt;/a&gt;has a 38 minute interview with &quot;Patrick&quot; - a young man who made between $10,000 and $20,000 over the course of one year of criminal scamming: &lt;br /&gt;
&lt;br /&gt;
&lt;object width=&quot;425&quot; height=&quot;349&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/Wktdmhn9VP0&amp;border=1&amp;color1=0x3a3a3a&amp;color2=0x999999&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowScriptAccess&quot; value=&quot;always&quot;&gt;&lt;/param&gt;&lt;embed src=&quot;http://www.youtube.com/v/Wktdmhn9VP0&amp;border=1&amp;color1=0x3a3a3a&amp;color2=0x999999&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1&quot; type=&quot;application/x-shockwave-flash&quot; allowfullscreen=&quot;true&quot; allowScriptAccess=&quot;always&quot; width=&quot;425&quot; height=&quot;349&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
There are some fascinating details (here are my notes on the highlights):&lt;br /&gt;
&lt;br /&gt;
3:00 Started in Eve Online / GoonSwarm&lt;br /&gt;
&lt;br /&gt;
5:30 Scammed his own Eve Online Corporation as a Director (non GoonSwarm) stole 9B ISK in 2006&lt;br /&gt;
&lt;br /&gt;
6:30 WoW Scam/Griefing casual every month of so&lt;br /&gt;
&lt;br /&gt;
7:30 Lost his job and decided to sell his Eve Online Account.. he took the money and realized he didn&#039;t have to transfer the account  - there was no protection for intangible items in PayPal Terms of Service - He made $750... used it for rent.&lt;br /&gt;
&lt;br /&gt;
10:00 In order to &quot;beat PayPal&quot;, he mailed piece of paper with invalid information... got through Paypal security and send the Shipping Tracking information (PERSONAL NOTE: my company used physical shipments to validate shipments of license keys to avoid fraud problems in 2003).&lt;br /&gt;
&lt;br /&gt;
11:45  Scammers &quot;networking&quot; to develop tactics... Paypal changes and protect buyers, not sellers. Reverse scam to a &quot;Buyer Scam&quot;: Buy Item, dispute sale, Resell the account quickly &lt;br /&gt;
&lt;br /&gt;
13:30 Started identity theft ... used stolen name and SSN, to set up fraudulent paypal account tied to his Real bank account + fake ID (there is no cross verification of account names - Marcus is currently checking to see if this weakness still exists)...Patrick worked in HR as recruiter... had info of anyone who applied for a job at the company (IT IS SCARY HOW MANY PEOPLE HAVE ACCESS TO YOUR NAME AND SOCIAL SECURITY NUMBER) then close Paypal account quickly before they put in a dispute... age 21,22. Blames economy, desperation - rent &amp;amp; food problems.&lt;br /&gt;
&lt;br /&gt;
16:30 - All you need to create a PayPal account is a name &amp;amp; SSN (and your own bank account)&lt;br /&gt;
&lt;br /&gt;
16:50 - $10 to $20K in one year... was active for one year.&lt;br /&gt;
&lt;br /&gt;
17:30 - Why he was not caught - only small transactions... keep it under $1000. Paypal &quot;caught up with him&quot; eventually - then he started using other peoples accounts.. that is why he stared ID theft (but they didn&#039;t validate account, see above)&lt;br /&gt;
&lt;br /&gt;
19:00 - Paypal is so easy, much easier than direct deposit or wire transfer... a lot of scammers only do this (scamming) once.&lt;br /&gt;
&lt;br /&gt;
20:00 - Last Scam / Biggest Scam - started getting scared. Meet girls &quot;get them to love him&quot; and use their Paypal account (or get them to set up a Paypal account). &quot;Most interesting&quot; found he actually liked the girl. Got a real job and paid her back. Realized what he was doing.&lt;br /&gt;
&lt;br /&gt;
22;15 - Other most exciting was the first one. When you make over $500,... a &quot;means to get by&quot;.&lt;br /&gt;
&lt;br /&gt;
23:20 - Security advise... copy of drivers license &amp;amp; prove its actually the person... TrustWho works (NOTE: run by MarkeeDragon - 99.7%).. if they&#039;ve never done any sales before on the site, don&#039;t trust them... reputation at sites is a problem if you haven&#039;t done a sale before... TrustWho really &quot;ruined his (scam) business&quot;. He was not able to get TrustWho verified.&lt;br /&gt;
 &lt;br /&gt;
29:30 CraigsList is great place to scam people. Get 18 year olds with fresh money (after graduation).&lt;br /&gt;
&lt;br /&gt;
30:50 - Successful transactions in past, get drivers license (repeat)... scary how many people have your drivers license and SSN&lt;br /&gt;
&lt;br /&gt;
33:00 - Wrapup by Marcus Eikenberry - scamming women, HR attacks, name &amp;amp; SSN is all it takes&lt;br /&gt;
&lt;br /&gt;
I&#039;d echo Marcus&#039; comments. The potential for abuse by people in Human Resources and customer service is truly frightening, especially in this economy. It is also disheartening how weak our financial authentication systems are.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 18 Jan 2010 05:01:00 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2819-guid.html</guid>
    
</item>
<item>
    <title>World of Warcraft under stress from Gold Frauders via Phishing and Key Loggers</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2808-World-of-Warcraft-under-stress-from-Gold-Frauders-via-Phishing-and-Key-Loggers.html</link>
            <category>Game Industry</category>
            <category>Game Security</category>
            <category>Gold Farming &amp; Power-Leveling</category>
            <category>Gold Frauders, Virtual Theft &amp; Property Rights</category>
            <category>IT Security and Privacy</category>
            <category>Payment Processing and Financial Fraud</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2808-World-of-Warcraft-under-stress-from-Gold-Frauders-via-Phishing-and-Key-Loggers.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2808</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2808</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    Blizzard&#039;s customer service team for World of Warcraft seems to be at a breaking point over account theft due to key loggers, phishing, and such. First, there is a serious rumor via WoW.Com that Blizzard is considering making security tokens (from Vasco) manadatory. These tokens create a time-based password that is sent to the server in addition to a player&#039;s regular password.&lt;br /&gt;
&lt;br /&gt;
The second story is that Blizzard is apparently trying to divert customers away from getting their account restored towards accepting a standard &quot;care package&quot; in lieu of restoration. The package includes:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;&lt;br /&gt;
2,500 gold&lt;br /&gt;
2 Emblems of Frost&lt;br /&gt;
10 Emblems of Triumph for every day the players has had to wait to receive the care package&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
WoW.com contends that this approach is not good customer service and does not reflect the real needs or interests of players. A good restoration capability should be quite inexpensive to implement and would incur HUGE customer good will (I await the usual objections on &quot;economy damage&quot; and &quot;player abuse&quot; grounds).&lt;br /&gt;
&lt;br /&gt;
Making security tokens mandatory is an excellent suggestion. In the short run, it will push Gold Frauders to other games, but it is likely that attackers will move towards &quot;client hijacking&quot; on the player&#039;s computer... if the crook can take or maintain control of the game client (by keeping a session open with the server when the player thinks he has logged out, for example), he can do VERY BAD THINGS. This would not require a full client implementation as most of the attacks could be done via abstract account screens and such that are much easier to emulate than the whole game client.&lt;br /&gt;
&lt;br /&gt;
By the way, these guys are no longer Gold Farmers who simply violate Terms of Service, they are Gold Frauders - criminals who are exploiting the lack of control in World of Warcraft and other MMOs. This is pretty clearly a violation of standard computer security laws and should be of sufficient scale to catch the interest of law enforcement.&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Operationally, gold frauding is much cheaper than gold farming as you don&#039;t need to spend time building up characters, farming assets, and waiting to be banned. Since you are hitting accounts and looting them on a one-time basis, you are not going to trigger traditional gold farming detectors.... and if you get banned, on to the next victim. &lt;br /&gt;
&lt;br /&gt;
Game companies are going to really need to rethink their approach to customer service and security as this threat grows.&lt;br /&gt;
&lt;br /&gt;
Welcome to Gold Frauder 2.0.&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
A. Holisky (2010), &quot;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9632&amp;amp;entry_id=2808&quot; title=&quot;http://www.wow.com/2010/01/08/blizzard-giving-serious-consideration-to-mandatory-authenticator/&quot;  onmouseover=&quot;window.status=&#039;http://www.wow.com/2010/01/08/blizzard-giving-serious-consideration-to-mandatory-authenticator/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Blizzard giving serious consideration to mandatory authenticators&lt;/a&gt;&quot;, http://www.wow.com/2010/01/08/blizzard-giving-serious-consideration-to-mandatory-authenticator/&lt;br /&gt;
&lt;br /&gt;
A. Holisky (2010), &quot;&lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9633&amp;amp;entry_id=2808&quot; title=&quot;http://www.wow.com/2010/01/08/account-administration-told-not-to-restore-hacked-characters/&quot;  onmouseover=&quot;window.status=&#039;http://www.wow.com/2010/01/08/account-administration-told-not-to-restore-hacked-characters/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Account Administration told not to restore hacked characters&lt;/a&gt;&quot;, http://www.wow.com/2010/01/08/account-administration-told-not-to-restore-hacked-characters/&lt;br /&gt;
&lt;br /&gt;
both via &lt;a href=&quot;http://playnoevil.com/serendipity/exit.php?url_id=9634&amp;amp;entry_id=2808&quot; title=&quot;http://www.massively.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.massively.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Massively&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Fri, 08 Jan 2010 08:22:54 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2808-guid.html</guid>
    
</item>

</channel>
</rss>