WARNING M A T T IS BACK! (General Discussion)

WARNING M A T T IS BACK! // General Discussion

1  |  

mrbruce

Jun 14, 2002, 4:51am
Yes I have crossed posted hacker and script kiddie M A T T is back in AW. He
has so far stolen two known cits please read the following grams.This
conversation took place at the AWGate.
Telegram from Travman, sent 27 minutes ago:
i unfortunately know who stole a few cits...including one of urs

Telegram from Travman, sent 26 minutes ago:
Aisley: oh my my
M a t t: YO
M a t t: WAZZZUP
Travman: (to M a t t) what
"AlexBor": u can only wisper if u r a citizen?
"SexyLady": wow
M a t t: remember me
Travman: in here
Aisley: I'm going to bed too. Night Everyone. Nice to meet you Travman.
Take care of yourself.
Travman: theres an option caretakers can change
Travman: u too, aisley
Travman: (to M a t t) of course
"AIexBor": hey lady, wanna cyber :D
"AlexBor": laila tov
M a t t: I stole this cit
M a t t: Stole 2 today
UsuL 2: good night {{{{{{{{{Aisley}}}}}}}}}
"AlexBor": jupiter stop it
Aisley: Lady.. just say no
Travman: (to M a t t) from who
Aisley: Night Usul :)
M a t t: TiffieBooBear
"SexyLady": maby later Alex
Aisley: Poor Usul... left to take care of these ummmm friendly folks
Travman: (to M a t t) why did u do that?
M a t t: cause I ain't paying shit
"AIexBor": i'm available now ;P
Travman: (to M a t t) ur gonna loose the cit though
M a t t: The other one I stole from MrBruce

Telegram from Travman, sent 27 minutes ago:
"AlexBor": sexylady i am not interested
"SexyLady": i know
M a t t: I'll just keep stealing them
"AlexBor": that's that little horny dog jupiter
"SexyLady": it was a joke
"AlexBor": or whoever it is
Aisley: Night Everyone :)
"Midnight Rider": Is there a certain time limit that this software can be
run?
"AlexBor": oh
"AIexBor": nah, i wasj/k about me not being interested, lady
Travman: (to M a t t) you need to learn at least a few morals
"Sheik Yerbuti": Which is the real Alex Bore?
"AlexBor": i was so scared :-)(
Travman: (to M a t t) i know mine arent high....but still
M a t t: alright TPCircuit
"AIexBor": there is only one alexbor
Travman: (to M a t t) im not TPCircuit
"AlexBor": tnx UsUl ...
Telegram from Travman, sent 28 minutes ago:
all the ones from M a t t were whispers btw

M A T T was banned from AW for hacking the X worlds universe.
He is presently sending some type of script that allows him to steal
passwords.
Details are sketchy at this time but M A T T is well known for this type of
activity and he is back. He come into A!!CT world just before my tourist
loan cit was stolen from its user. When approached he was in America world
with two citizens AdmiraL Red Dog cit number 348502 and Mike. o cit number
338620. I will not post the vulgar chat here as it contains vulgar profanity
used by both AdmiraL Red Dog and Mike. o
All three threatend to hack more cits and worlds.
I post this as a warning, heed it or make fun of it, but the AW hackers and
script kiddies are back, they will use a stolen cit to get it banned from
every world they can. Please warn people to NOT ACCEPT files in aw or emails
from possible AW related sites.
I personally have had worms sent to me on a junkie PC with virus protection
from email web addresses such as COF at activeworlds.com when I sent an email
back to this address it came back there is no such address.
World owners and citizens have to be careful what you click on in aw, a link
on a harmless sign in a build can contain hidden scripts and links to sites
that can plant or download malicious code or activeX files.

dion

Jun 14, 2002, 5:29am
so basically, don't be stupid and give out your pw or download stupid
programs!
[View Quote]

robbie

Jun 14, 2002, 5:36am
> M A T T was banned from AW for hacking the X worlds universe.

Not that I know of. No-one "hacked" X Worlds. We had a few problems, but
they were so trivial they dont qualify as "hacks".

> He is presently sending some type of script that allows him to steal
> passwords.

Well, to me he sounds like another little kid with nothing better to do. I
would be surprisd if he had the knowledge to compose a ActvieX script, let
alone exploit it to steal someones password. Furthermore I highly doubt he
can steal a pasword through a website. The best of people in AW havent found
around the machine specific encryption yet, so I doubt some little n00b has.

My two cents? Band him from your world if you want, dont talk to him if you
want. But dont make posts like this proclaiming him as some hacker becuase
its probably what he wants. AWCorp will ban the end of the week, I'd put my
money on it. Just send thme any evidence you have of him stealing
citizenships.

-Robbie

kah

Jun 14, 2002, 2:44pm
"mrbruce" <MrBruce406969 at aol.com> wrote in
news:3d099254$1 at server1.Activeworlds.com:

> Yes I have crossed posted hacker and script kiddie M A T T is back in
> AW.
><snip>

Do you have any idea of how many other people steal cits in AW? And it's
probably due to the user giving him the password anyway, this problem is
not going to vanish before uneducated users stop giving out their passwords
to people! If he managed to steal it using a website, he's a very good
programmer, and judging from your description and how these people usually
are, he probably couldn't even write a Hello world in BASIC. (that means
one, extremely simple linem, of code in an old, easy language) When you
give out cits to tourists, remember to stuff their heads full of "Never
give the cit password to ANYONE!", and you'll be lowering the risk hugely.
BTW hacker != script kiddie...

KAH

binarybud

Jun 14, 2002, 5:49pm
"If he managed to steal it using a website, he's a very good
programmer, "

what a load of crap..... anyone can cut and paste from an existing site
and create there own.
what these kids do is nothing more than fun and games for them... and it
does not take talent...just curiousity and time...:)

And FYI AW could do some things with the browser that would make it a lot
harder to steal accounts from unknowing newbies. It's just a matter of
priorities.

oh and "old and easy language" lol listen i could send you some
"easy BASIC" code that you'd spend a few weeks trying to decode... and
still not know what it's doing..;)

Leo :)




[View Quote]

bowen

Jun 14, 2002, 5:56pm
> oh and "old and easy language" lol listen i could send you some
> "easy BASIC" code that you'd spend a few weeks trying to decode... and
> still not know what it's doing..;)

Wouldn't be "easy" then. By easy I think he means PRINT "Hello World!"
Which is the extent of a script kiddie's abilities in most cases.

--Bowen--

Have $3... want a website?
http://www.smartpenguin.com/affiliate.php?id=12

mrbruce

Jun 14, 2002, 8:02pm
More info just came in. The cits were obviously telegrammed that they won a
prize of some sort and were told to change the email address contained in
the cits properties, once this was done M A T T tried logging into the cit,
not knowing the password he clicked I FORGOT and typed in his email address,
this caused the password to be emailed to him. Just posted this because
people of all ages should not do this nor accept files from unknown people!
[View Quote]

kah

Jun 15, 2002, 9:17am
"mrbruce" <MrBruce406969 at aol.com> wrote in
news:3d0a67de at server1.Activeworlds.com:

> More info just came in. The cits were obviously telegrammed that they
> won a prize of some sort and were told to change the email address
> contained in the cits properties, once this was done M A T T tried
> logging into the cit, not knowing the password he clicked I FORGOT and
> typed in his email address, this caused the password to be emailed to
> him. Just posted this because people of all ages should not do this
> nor accept files from unknown people! "mrbruce"

I knew it was something like this... As I said, remember to stuff the heads
of the people you give cits to with warnings ;-))

KAH

kah

Jun 15, 2002, 9:29am
"binarybud" <leom at knorrinteractive.com> wrote in
news:3d0a48c5$1 at server1.Activeworlds.com:

> "If he managed to steal it using a website, he's a very good
> programmer, "
>
> what a load of crap..... anyone can cut and paste from an existing
> site and create there own.
> what these kids do is nothing more than fun and games for them... and
> it does not take talent...just curiousity and time...:)
>
> And FYI AW could do some things with the browser that would make it a
> lot harder to steal accounts from unknowing newbies. It's just a
> matter of priorities.
>
> oh and "old and easy language" lol listen i could send you
> some "easy BASIC" code that you'd spend a few weeks trying to
> decode... and still not know what it's doing..;)

Cut and paste from an existing website?? You can't steal a PW with HTML
code lol, I meant that he'd have to write a Java applet that managed to
steal it from memory (since the on-disk version is encrypted)... But I
guess he could get the applet from somewhere though, I forgot about
that... Yes, but it is quite possible to avoid having your cit stolen by
not trusting everyone, especially with weird requests... For example,
Radon made a special version of his PW stealing bot (this was during 3.1,
before the PW was machine-specifically encrypted) for me because I've got
AW installed somewhere else than C:\Active Worlds\. Wasn't exactly hard
to guess that he was going to read my aworld.ini, so I replaced my PW
with bogus instead. If I had trusted him, he probably would've gotten my
PW. Easy BASIC code doesn't take weeks to decode lol, that's complicated
BASIC code... And BASIC is *relatively* easy, remember that everything is
relative :-)) I guess there's no need to tell that a Hello World in BASIC
only takes one line, which I wouldn't categorise as anything but
extremely easy lol

KAH

joeman

Jun 15, 2002, 8:15pm
Java runs in a sandbox, cant get to memory.

-Joe

[View Quote]

jerme

Jun 15, 2002, 9:17pm
sandbox? never heard that analogy before, but I know what you're talking
about. I'm still pretty sure you could access memory directly with Java.

--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Jeremy Booker - Owner
JTech Web Systems
www.JTechWebSystems.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[View Quote]

bowen

Jun 15, 2002, 9:21pm
Maybe he meant javascript instead of Java? :\ that's what it sounds like to
me.

--Bowen--

Have $3... want a website?
http://www.smartpenguin.com/affiliate.php?id=12

[View Quote]

ananas

Jun 16, 2002, 2:13am
In theory, Java really runs in a sandbox, but this sandbox
isn't 100% secure. And a lot of applications use JNI, which
makes it even more insecure. The only way to have real
security with a Java web interface is, to split it and put
the web part behind a firewall, with access through a
web service. This works only for servlets though, you
cannot have acceptable security (yet?) with Java running on
the client side, under control of IE or other browsers.

JavaScript has not much in common with Java except for a
similar syntax. Joeman did not mean JavaScript, as JS does
NOT run in a sandbox but is interpreted directly by the
web browser.

[View Quote]

pc hamster

Jun 17, 2002, 2:49am
Hi everyone:

[View Quote] If this is true, then WE ARE ALL DOOMED because all he has to do is simply
type in the name of ANY cit and get the password (which I give to NO ONE!)
AS WELL AS the cit. no. emailed to him.

It all goes back to what I keep saying about parents, their kids, and their
kids online activities. That is that parents MUST ALWAYS monitor what their
kids do on the Internet (not just take their word for it). Until parents in
this society start becoming more responsible (and taking responsibility for
the actions of their kids in situation where the parents are usually held
accountable), this problem will continue and only GET WORSE.

Just my $.02 worth....Cheers for now everyone :-)

PC Hamster

dion

Jun 17, 2002, 2:54am
The e-mail will only be sent if the email address entered matches the e-mail
adrress in the citizen's information.

Also, a 40yo guy could do this just as easily as a kid. If people are going
to be idiots about this, then they are going to lose. I'm not worrying
because I'm not dumb enough to do such a stupid thing.

[View Quote]

lioness e

Jun 17, 2002, 3:40am
heads up everyone: this evening M A T T showed up in a bingo world,
pretending to be one of the hosts...asked for the pw from the host and then
ejected everyone....Hamfon was notified and fixed the ejects and changed the
pw...one of the hosts got the IP and Ham is looking into it ;-"D




[View Quote]

mrbruce

Jun 17, 2002, 7:42am
Also links on signs and chat line can lead to websites that can do damage on
PCs that are not protected. Perhaps java scripts can contain malicious
codes. Remember once you click a link it brings you outside the safety of
AW's browser.
Although I am not a hacker, cracker or script kiddie and do not know alot
about doing things like that, I know alot of password stealers can be hidden
on links! Lets get rael here, anything is possible. Although some say these
kids were stupid for doing what they were told, how many of us click links
in the chat line?
how about visiting a world ran by password stealers that have a link on
their welcome message, that leads to such a link?
As lioness e said a bingo world host gave the password to M A T T thinking
he was a host!
M A T T is here for popularity, just like Bin Laden is popular and many
other villians, that become famous for corrupting soceity.
Does M A T T really bother me? Nah, in fact the jerk just makes my world
more popular at his exspense!
As for him stealing my tourist cits goes, I just call AW and change the
password! It gives the folks at AW and myself a reason to say hello.:-)
I only posted the warning here, to warn those that do not take kindly to
these games. But here it is SUMMERTIME and SCHOOLS OUT! So here comes the
bored little pee-ons who need something to do with all their sparetime.
Are they spoiling my fun in AW? Nah they just make it more entertaining!
Thats my view...what's yours?
MrBruce A!!CT world owner-have a good day!

[View Quote]

bowen

Jun 17, 2002, 12:52pm
How do you know he's a kid? Adults do this just as much as kids do.

--Bowen--

Have $3... want a website?
http://www.smartpenguin.com/affiliate.php?id=12

[View Quote]

dion

Jun 17, 2002, 1:02pm
first of all, it'd take one heck of a programmer to figure that out. And
even if they did, they'd only have your password that is encoded with sa
bunch of crap. You'd have to know how to decrypt it as well, which includes
lots of other computer information.

Quite frankly, matt is a dumbass and couldn't do any of that if his life
depended on it ;-)

[View Quote]

percipient

Jun 17, 2002, 2:20pm
Actually, all they'd need to do is replace their encrypted password in their
aw.ini file with the encrytped one they stole, and let the AW browser
decrypt it for them.

--
Percipient

"dion" <GovDion at subdimension.com> wrote...
first of all, it'd take one heck of a programmer to figure that out. And
even if they did, they'd only have your password that is encoded with sa
bunch of crap. You'd have to know how to decrypt it as well, which includes
lots of other computer information.


---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.370 / Virus Database: 205 - Release Date: 6/5/02

agent1

Jun 17, 2002, 2:29pm
That doesn't work anymore since Roland implemented machine-based encryption.

-Agent1

[View Quote]

dion

Jun 17, 2002, 2:33pm
yeh, unless you are on the same computer, that dun work ;-)

[View Quote]

kah

Jun 17, 2002, 3:31pm
> If this is true, then WE ARE ALL DOOMED because all he has to do is
> simply type in the name of ANY cit and get the password (which I give
> to NO ONE!) AS WELL AS the cit. no. emailed to him.
>
> It all goes back to what I keep saying about parents, their kids, and
> their kids online activities. That is that parents MUST ALWAYS
> monitor what their kids do on the Internet (not just take their word
> for it). Until parents in this society start becoming more
> responsible (and taking responsibility for the actions of their kids
> in situation where the parents are usually held accountable), this
> problem will continue and only GET WORSE.

You can enter my citname and your email, click the "I forgot my password"
button, but it won't send it to you, it might send it to me though :-)) It
sends it to the email address specified in the Preferences > User dialog,
so the victim does sign it's own "death sentence". I think it's silly that
parents sit and watch what their kids do, I've never done any of this crap,
and do you know why? Because my parents have told me about how bad it is,
and how stupid it is, and that they've managed to bring me up to be mature,
only immature people do this crap, so monitoring isn't really the solution
to the problem, it's education.

KAH

kah

Jun 17, 2002, 3:39pm
"mrbruce" <MrBruce406969 at aol.com> wrote in
news:3d0daf17 at server1.Activeworlds.com:

><snipped>

Actually, no, sites can't steal your password (at least not your AW
password). Only very good programmers (or people using apps made by very
good programmers) could at all manage to access memory and steal it that
way (the browser would have to be running though) from a Java applet, which
is the *only* way it could be done from a site. So don't worry about sites
stealing your AW password, because it won't happen :-)) And don't go around
telling people it will happen, it creates fear for no reason at all, and I
know you want to best for your visitors and friends (and fellow citizens)
:-)) Yup, people like this M A T T person are just stupid little script
kiddies that think they're really cool, but in fact are losers, I totally
agree, but I don't think it'll matter if schools are out, because script
kiddies and crackers aren't necesarely kids (or other < 18 people)!

KAH

d a n

Jun 20, 2002, 2:40pm
One of the most popular ways m a t t got peoples cits was faking out to be
MrBruce.

A1CTTourist5 to name one said that m a t t posed as MrBruce in the cit AW
Terroist 2

I never ever fall for punctuation or special characters due to I check using
MS Word to see if it is valid

Telegram from MrBruce., sent Fri Jun 14, 2002 20:36:
I need your ppw for a second please

This one was ovious the "." (dot) was a character to fool people. I didn't
fool for it and told him that he is not the real MrBruce.

A1CTTourist5 reported m a t t asking T5 to find out the real MrBruce's ppw.
Myself worked out that m a t t was planning to use a bot under MrBruce's ppw
and wipe the world. MrBruce used up his bot limit at this time running
paintball, ZBot and BuildBot yet this was still a risk.

I spoke to class 3 (PK) and he managed to get A!!CTSUX terminated.

*Keeping you informed*

<Dan>
[A1CT Network Manager]

------------------------------

A1CT Network: www.a1ct.tk

A1CT Forum: http://a1ct.gmnet.uni.cc

[View Quote]

slim smokey

Jun 30, 2002, 6:17am
Mike. o wouldn't do that...he's been having his cit hacked and he wasn't
using it 75% of the time :\

--
-chikka chikka Slim Smokey!
www.slimandmike.tk Oh and by the
way check out my town Willow Bay at
1100s 700w AWTeen
[View Quote]

1  |  
Awportals.com is a privately held community resource website dedicated to Active Worlds.
Copyright (c) Mark Randall 2006 - 2024. All Rights Reserved.
Awportals.com   ·   ProLibraries Live   ·   Twitter   ·   LinkedIn