PDA

View Full Version : PreformAVEnabler steals players passwords



Worldwide
06-06-2010, 09:18 AM
The addon called PreformAVEnabler is stealing players logins and passwords. The server that it connects to is storing the accounts logins and passwords for a person to hack into their account and steal all of the gold including selling all items.
How do I know this? A friend in the game had recommended I use it to allow my characters in a raid to join AV without being in a group. He had his account stripped of his gear and lost all gold. One week after I installed the addon, my account had the same thing happen. I've never visited any websites other than blizzard.com, worldofwarcraft.com or battle.net. Also, I don't have anything running in my machine that would cause any form account theft. That is, I check my memory often with task manager and don't see anything that shouldn't be there.
The culprit is the PreformAVEnabler addon. Search for it on the web if you want to look at the addon code. But this is malicious and I am angry that addons are allowed to do this. There should be something to restrict an addon from stealing account logins and passwords.
If you don't believe me, keep using that addon and your account will eventually be stripped of all your gold.

Svpernova09
06-06-2010, 09:54 AM
AFAIK Addons themselves can't connect to a remote server, it had to be something bundled with the addon (IE a trojan)

Lax
06-06-2010, 10:55 AM
Search on the web if you want to find code that hides a program from task manager...

Also, Addons aren't loaded until you log into the game, and WoW Addons run in a restricted Lua engine that does not provide a method of accessing your login or password.

A week or two ago someone sent me an email saying they got hacked and they were certain it was because of my software (I didn't write AV enabler, but just as a related anecdote...). I explained to them that I've been in business since 2004 and it would be stupid -- and illegal -- for me to attempt to hack anyone's accounts when thousands of people rely on my software daily. I got an email back a few hours later with an apology, he checked his browser history and noticed that a link he clicked on in an email he got, sent him to one of the fake WoW scam sites (something related to cataclysm) and not the real one as it apparently looked like it would do.

I'm guessing something similar happened to you.

luxlunae
06-06-2010, 01:10 PM
Agreed. Addons CANNOT do this. They cannot connect to a server or have access to that information.

MiRai
06-06-2010, 01:13 PM
The addon called PreformAVEnabler is stealing players logins and passwords. The server that it connects to is storing the accounts logins and passwords for a person to hack into their account and steal all of the gold including selling all items.
How do I know this? A friend in the game had recommended I use it to allow my characters in a raid to join AV without being in a group. He had his account stripped of his gear and lost all gold. One week after I installed the addon, my account had the same thing happen. I've never visited any websites other than blizzard.com, worldofwarcraft.com or battle.net. Also, I don't have anything running in my machine that would cause any form account theft. That is, I check my memory often with task manager and don't see anything that shouldn't be there.
The culprit is the PreformAVEnabler addon. Search for it on the web if you want to look at the addon code. But this is malicious and I am angry that addons are allowed to do this. There should be something to restrict an addon from stealing account logins and passwords.
If you don't believe me, keep using that addon and your account will eventually be stripped of all your gold.
Addons can't do this, this is ridiculous. You specially created an account to come here and share this with us? Or maybe you made an 'alt' account so we wouldn't laugh you off the forum?

heyaz
06-06-2010, 01:17 PM
The addon called PreformAVEnabler is stealing players logins and passwords. T
How do I know this? ... He had his account stripped of his gear and lost all gold. One week after I installed the addon, my account had the same thing happen.

Post hoc ergo propter hoc.

Really, I thought this was going to be something good, I was already imagining doing some static code analysis on all my addons. But as I thought before, they can't do this.

EaTCarbS
06-06-2010, 04:34 PM
My question... where did you go to get the addon?

Shodokan
06-06-2010, 05:29 PM
My question... where did you go to get the addon?

Exactly... i've been using AVpreform since BC and it has never been a problem.

Velassra
06-06-2010, 06:20 PM
I visit porn sites alot. I've never been hacked.

I just wanted to throw that out there...

Maxion
06-07-2010, 07:38 PM
This same guy posted this on other websites forums too. Sounds like someone is just trying to get other people to stop using this addon so they'll meet less premades in AV.

coglistings
06-07-2010, 10:11 PM
But I am my own premade, of lvl 40 locks......

Iceorbz
06-08-2010, 01:18 AM
This same guy posted this on other websites forums too. Sounds like someone is just trying to get other people to stop using this addon so they'll meet less premades in AV.

Real premades dont use AV enabler ! We get on vent and say 1...2...(3/join). Then people who didn't get it when que pops join vent chat, and we decide whether or not to take the run.

EaTCarbS
06-08-2010, 02:45 AM
Prepared cross posted this on another website.

Malgor
06-13-2010, 07:24 PM
It was definitely a link scam. Happened to me last year. Keylogger was put on my computer and all my accounts hacked. Plus a credit card. I am wiser now, somewhat.

OzPhoenix
06-14-2010, 07:30 AM
Post hoc ergo propter hoc.

I would have bet serious money when I started reading this thread that I'd be the first to get to say this.... /sigh /lol

After it therefore because of it - fallacy of reasoning.

Also, that the poster made an account simply to post this smells awful fishy to me.

Poyzon
06-14-2010, 07:51 AM
Please lock/delete. Nothing worth seeing here.