Log in

View Full Version : Security concerns



ShadowKntSDS
07-26-2007, 12:29 PM
I start to try out dual boxing last night using synergy. I downloaded the modified version linked from this site that allows key broadcasting and played around for a bit.


I wake up this morning, and one of my passwords does not work. Luckily, this is not my primary account, and I am not really set back much by this, even if the account is lost for good.

I realize there are 3 million ways the account could of have compromised, but lets assume it was synergy that allowed it to happen. What can I do to prevent this in the future?

I am behind a router, so in theory I am behind a firewall. I have not clicked an keyloggers on in any of the forums. One of the machines I use is also a work laptop that is firewalled/virus scanned out the yin-yang.

here are some ideas:
-try a different program, hopefully one with some type of encyption (does multibox do this?)
-rotate the port i use so I am not on the default
-explictly block the port from external access
-avoid logging in w/ synergy running.

Any other ideas? I don't want to fear dual-boxing because of this incident. I don't beleive I did anything inherently stupid here.

keyclone
07-26-2007, 12:42 PM
sorry, but synergy is not a password thief. its been out there for quite a while with no reports of anything of the kind.

besides, why would the synergy folks want your game account?

depending on your game, the bandwidth may not be encrypted from your client to the game server. if so, then it is passed in the clear... at which point, anyone on your local segment could be sniffing it.

of course, if you don't live alone, i think i'd check my roommates first

ShadowKntSDS
07-26-2007, 12:58 PM
I am not suggesting that synergy actively did something to send my passwords to a master server or anything.

I am concerned that there is no authentication, and the data sent is not encrypted. This provides a hole for other people to connect to the synergy server, or snoop the data on my network.

deadarcher
07-26-2007, 12:59 PM
Call the WoW Tech support. Ask about lost passwords or whatever. If it truely is your account, they can reset the info for you.

(oh, and make sure caps lock isn't on :P)

ShadowKntSDS
07-26-2007, 01:07 PM
Call the WoW Tech support. Ask about lost passwords or whatever. If it truely is your account, they can reset the info for you.

(oh, and make sure caps lock isn't on :P)

Thanks, but I'm already on that. All my passwords are changed, even on the account that didn't have to problems. I am just trying to make sure it doesn't happen again. Just trying to cover all my bases.

Xzin
07-26-2007, 01:19 PM
If people are running rampart across your network, then them listening in to your synergy server is the least of your worries.

Kruiik
07-27-2007, 02:39 AM
Maybe you broadcasted your account info on one of the controlled machines in WoW?