<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WoW: Authenticator users targeted by trojan middleman attack</title>
	<atom:link href="http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/feed/" rel="self" type="application/rss+xml" />
	<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/</link>
	<description>MMO Exploits, Game Hacks, Guides, News</description>
	<lastBuildDate>Tue, 07 Feb 2012 03:57:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Coli</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-2435</link>
		<dc:creator>Coli</dc:creator>
		<pubDate>Sat, 31 Jul 2010 20:09:38 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-2435</guid>
		<description>Reverse engineering is irrelevant. The algorithm is actually public, but because it uses public key cryptography, you aren&#039;t going to be breaking it. I have written an implementation for Windows at http://code.google.com/p/winauth/.

What is important is keeping the secret key stored in the authenticator safe. This isn&#039;t a problem for the physical device. But for mobile devices, or the Windows one, your private key must be secured.

However all devices are still prone to a man-in-the-middle attack, but it is time-sensitive (you have a 30 second window).

At any rate, having an authenticator is still better than not.</description>
		<content:encoded><![CDATA[<p>Reverse engineering is irrelevant. The algorithm is actually public, but because it uses public key cryptography, you aren&#8217;t going to be breaking it. I have written an implementation for Windows at <a href="http://code.google.com/p/winauth/" rel="nofollow">http://code.google.com/p/winauth/</a>.</p>
<p>What is important is keeping the secret key stored in the authenticator safe. This isn&#8217;t a problem for the physical device. But for mobile devices, or the Windows one, your private key must be secured.</p>
<p>However all devices are still prone to a man-in-the-middle attack, but it is time-sensitive (you have a 30 second window).</p>
<p>At any rate, having an authenticator is still better than not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spitt</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-248</link>
		<dc:creator>Spitt</dc:creator>
		<pubDate>Mon, 08 Mar 2010 07:11:56 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-248</guid>
		<description>Just read some news where they have a Desktop Authenticator.  It was being tested in December, might be live now, or still being beta tested.  However the point is that a desktop authenticator would be easier to backwards engineer.  

Get the code, enter the code to get on the account.  Get the code again, to change the authenticator to your own desktop version.  Only need 2-3 codes and can then disable the previous owner&#039;s version and apply your own.  Sounds like a workable hack to me.  

Brilliant move by the account thieves, hopefully more people read this and read my System Protection post, to get better protected on their system.</description>
		<content:encoded><![CDATA[<p>Just read some news where they have a Desktop Authenticator.  It was being tested in December, might be live now, or still being beta tested.  However the point is that a desktop authenticator would be easier to backwards engineer.  </p>
<p>Get the code, enter the code to get on the account.  Get the code again, to change the authenticator to your own desktop version.  Only need 2-3 codes and can then disable the previous owner&#8217;s version and apply your own.  Sounds like a workable hack to me.  </p>
<p>Brilliant move by the account thieves, hopefully more people read this and read my System Protection post, to get better protected on their system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spitt</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-230</link>
		<dc:creator>Spitt</dc:creator>
		<pubDate>Sat, 06 Mar 2010 05:45:02 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-230</guid>
		<description>There is a talk of a authenticator that needs 3 codes to sync with a generic authenticator.  It&#039;s possible that someone took the iphone app and reverse engineered it, to make it work natively or possibly even emulated on something like linux or freebsd.  Since this thing sends the wrong code to Blizzard, it&#039;s possible that the people could be trying to grab 3 codes in order to apply it to a cracked authenticator.</description>
		<content:encoded><![CDATA[<p>There is a talk of a authenticator that needs 3 codes to sync with a generic authenticator.  It&#8217;s possible that someone took the iphone app and reverse engineered it, to make it work natively or possibly even emulated on something like linux or freebsd.  Since this thing sends the wrong code to Blizzard, it&#8217;s possible that the people could be trying to grab 3 codes in order to apply it to a cracked authenticator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: King_Yoshi</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-229</link>
		<dc:creator>King_Yoshi</dc:creator>
		<pubDate>Sat, 06 Mar 2010 04:31:59 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-229</guid>
		<description>They are key-log people, so they find out what key they used, and then just input the code into a program they created which tells them the password they used originally to create the key that the authenticator uses. From there they can input the proper codes as much as they want, when trying to log into the account they stole.</description>
		<content:encoded><![CDATA[<p>They are key-log people, so they find out what key they used, and then just input the code into a program they created which tells them the password they used originally to create the key that the authenticator uses. From there they can input the proper codes as much as they want, when trying to log into the account they stole.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: King_Yoshi</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-228</link>
		<dc:creator>King_Yoshi</dc:creator>
		<pubDate>Sat, 06 Mar 2010 04:31:39 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-228</guid>
		<description>They are keylog poeple, so they find out what key they used, and then just input the code into a program they created which tells them the password they used originally to create the key that the authenticator uses. From there they can input the proper codes as much as they want, when trying to log into the account they stole.</description>
		<content:encoded><![CDATA[<p>They are keylog poeple, so they find out what key they used, and then just input the code into a program they created which tells them the password they used originally to create the key that the authenticator uses. From there they can input the proper codes as much as they want, when trying to log into the account they stole.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bigsvenyo</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-217</link>
		<dc:creator>Bigsvenyo</dc:creator>
		<pubDate>Thu, 04 Mar 2010 22:49:59 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-217</guid>
		<description>This does not mean they&#039;ve been reverse engineered--it&#039;s a keylogging exploit</description>
		<content:encoded><![CDATA[<p>This does not mean they&#8217;ve been reverse engineered&#8211;it&#8217;s a keylogging exploit</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: King_Yoshi</title>
		<link>http://rpg-exploiters.com/news/wow-authenticator-users-targeted-by-trojan-middleman-attack/comment-page-1/#comment-210</link>
		<dc:creator>King_Yoshi</dc:creator>
		<pubDate>Thu, 04 Mar 2010 05:30:49 +0000</pubDate>
		<guid isPermaLink="false">http://rpg-exploiters.com/?p=1903#comment-210</guid>
		<description>ROFL! This just made my day.. I have been telling people that the authenticators had already been reverse engineered.. No one believed me..</description>
		<content:encoded><![CDATA[<p>ROFL! This just made my day.. I have been telling people that the authenticators had already been reverse engineered.. No one believed me..</p>
]]></content:encoded>
	</item>
</channel>
</rss>

