EQ2Interface.com
Search Downloads


Go Back   EQ2Interface > Featured Projects > ProfitUI

Reply
Thread Tools Search this Thread Display Modes
  #1  
Unread 03-20-2008, 11:27 AM
tntent tntent is offline
A Brown Bear
 
Join Date: Feb 2005
Server: Antonia Bayle
Posts: 13
Default incorrect rumor about profit updater

I am just asking if someone can look into a rumor that the updater is installing a keylogger on update... a wizzy on unrest claims that the profit updater installed a logger and now his accounts got hacked.
Reply With Quote
  #2  
Unread 03-20-2008, 11:41 AM
Kaldran Kaldran is offline
A Griffon
 
Join Date: Nov 2004
Server: Valor
Posts: 358
Default

Actually I was waiting for someone to shift the blame for losing account control on the updater since I first released it

The updater is released under lgpl, so anyone is free to run through the code or compile it by themselves for security reasons.
While it would be theoretical possible to install a keylogger by compromising the web server files, this has not happened and is quite unlikely to happen as well.

For the next release the updater files will be digitally signed. While doing this has other reasons it will improve security even more, compromised files wouldn't be able to run at all.
Reply With Quote
  #3  
Unread 03-20-2008, 11:49 AM
ObsidianDragon ObsidianDragon is offline
A Berserk Golem
 
Join Date: Aug 2005
Server: Oasis
Posts: 57
Default

I suspect if you install the updater from that file your new guildie emailed you or posted on your guild page, then yeah, it might have a keylogger.

Always best to download from the source
Reply With Quote
  #4  
Unread 03-20-2008, 11:50 AM
pooka's Avatar
pooka pooka is offline
A Griffon
Interface Author - Click to view interfaces
 
Join Date: Dec 2004
Server: Antonia Bayle
Posts: 250
Default

To sum up what Kaldran said: No.

If you've got a keylogger you got it from somewhere else.
Reply With Quote
  #5  
Unread 03-20-2008, 11:53 AM
gm9 gm9 is offline
gm10-1
Premium Member
EQ2Interface Super Mod
Featured
 
Join Date: Feb 2006
Posts: 6,479
Default

Yes, this "claim" was unfortunately already raised on the official forums as well and had previously been sent in PM's to me. Kaldran already said all there is to say.

Please check SOE's tips on how to keep your account safe. And please tell those people spreading misinformation to kindly shut up. Thanks.
__________________
P R O F I T U I ∙ R E B O R N [Auto-Updater] | [Portal] | [F.A.Q.] | [Support Forums]
~ Retired ~
If it does not work, you likely installed it incorrectly. Always try a clean install before reporting bugs.
Reply With Quote
  #6  
Unread 03-26-2008, 02:16 PM
tntent tntent is offline
A Brown Bear
 
Join Date: Feb 2005
Server: Antonia Bayle
Posts: 13
Default

i said pretty much the same thing. sorry for the rumor mongering.
Reply With Quote
  #7  
Unread 03-30-2008, 03:31 AM
Dechau's Avatar
Dechau Dechau is offline
A Griffon
 
Join Date: Apr 2005
Server: Splitpaw
Posts: 151
Default

Why would anyone who put this much work into creating an UI which is if not the best there is, then in the top 3 for sure, destroy it all by putting in a logger ?

Everyone knows it would have been discovered eventually, and thus he would have lost the good reputation he spend years of building up.

Anyone who believe those rumours are just plain stupid, ofcourse there is no logger in the updater people.

Wake up and smell the coffee
Reply With Quote
  #8  
Unread 03-30-2008, 12:17 PM
Kaldran Kaldran is offline
A Griffon
 
Join Date: Nov 2004
Server: Valor
Posts: 358
Default

I wouldn't call it stupid, but for sure it is not the best option to blame software with open source
Actually there is no need to install a key logger, I guess most people have their login credentials saved in ProfitUI's textfile for auto login anyways (which is a Bad Thing(tm) btw :P ). No virus scanner would be alarmed by an application just reading a text file...
Reply With Quote
  #9  
Unread 03-31-2008, 01:24 AM
gm9 gm9 is offline
gm10-1
Premium Member
EQ2Interface Super Mod
Featured
 
Join Date: Feb 2006
Posts: 6,479
Default

It is never a bad thing to not blindly trust software, I tend to be pretty much paranoid with that myself. But yes, the open source aspect of Kaldran's updater does probably make you look stupid if like the person the OP mentioned you make accusations that everybody can easily show to not be true by looking at the source.

I'm not paranoid about the auto login textfile of ProfitUI however. I tend to think that if your system is compromised to the point that you caught an eq2 specific trojan that reads that file and is able to send the data out of your system then the bad guys could just as easily install a keylogger and thus target all eq2 users (as well as your login data for other services), not just those using specific custom UIs. Also I think the latter case is much more likely. So always keep your system secure.

Please note however that a malicious third party UI mod would easily be able to grab your login data and send it to a third party. I am not aware of such a malicious mod but the risk exists, so don't just blindly install mods you found somewhere on the web.
__________________
P R O F I T U I ∙ R E B O R N [Auto-Updater] | [Portal] | [F.A.Q.] | [Support Forums]
~ Retired ~
If it does not work, you likely installed it incorrectly. Always try a clean install before reporting bugs.
Reply With Quote
  #10  
Unread 03-31-2008, 01:54 AM
dragowulf's Avatar
dragowulf dragowulf is offline
A man among men
This person is a EQ2Map developer.
Interface Author - Click to view interfaces
 
Join Date: Dec 2004
Server: Nagafen
Posts: 934
Default

Quote:
Originally Posted by gm9 View Post
It is never a bad thing to not blindly trust software, I tend to be pretty much paranoid with that myself. But yes, the open source aspect of Kaldran's updater does probably make you look stupid if like the person the OP mentioned you make accusations that everybody can easily show to not be true by looking at the source.

I'm not paranoid about the auto login textfile of ProfitUI however. I tend to think that if your system is compromised to the point that you caught an eq2 specific trojan that reads that file and is able to send the data out of your system then the bad guys could just as easily install a keylogger and thus target all eq2 users (as well as your login data for other services), not just those using specific custom UIs. Also I think the latter case is much more likely. So always keep your system secure.

Please note however that a malicious third party UI mod would easily be able to grab your login data and send it to a third party. I am not aware of such a malicious mod but the risk exists, so don't just blindly install mods you found somewhere on the web.
I thought an open source program was unheard of. jk, but seriously.

The safest place to DL mods is right here at all of the interface sites (eqinterface, eq2interface, wowinterface). As gm9 said try to avoid downloading mods from a random website on the web.

The kid the OP is talking about sounds like a fool to think that. Especially that it is open source, which I have checked for any four play when I saw rumors.
__________________
May Jesus Have Mercy On Us
Reply With Quote
  #11  
Unread 03-31-2008, 02:30 AM
tknarr's Avatar
tknarr tknarr is offline
A Griffon
Interface Author - Click to view interfaces
 
Join Date: Jul 2006
Server: Unrest
Posts: 849
Default

One thing the people who're getting hacked tend to forget is that it's not necessarily about what software they use on their computer or what web sites they go to. Say you go to a friend's house and use their computer to check the SOE forums. You log on with your own username and password, and tell the browser not to remember the password. But your friend's computer is infected with a keylogger. Guess what just happened to your password. And I'll bet a lot of the people who can't figure how they got hacked because they never visit dangerous sites have in fact visited a safe site from a computer that they don't control and don't know the condition of and got caught that way.
Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 07:43 AM.


Our Network
EQInterface | EQ2Interface | WoWInterface | LoTROInterface | ESOUI | MMOUI