[WARNING] I got my account hacked
I don't have access to steam version of PoE in my region so I can't test things there.
But I can throw a theory based on authentication used by Garena, it starts through their client and how it starts is a funny way! It just starts a game with token parameter which can be used to start a game from other places. Token is only valid for 6 hours though, if someone gained access to it I feel like that would be one of possible ways to hack into account. But I haven't tested logging in with it from different locations, maybe it wouldn't allow. But if it would allow login from any location with token then hacker only needs this one small piece of data. And I don't think that tool to read which parameters program was started with is a really hard one. Process Explorer shows it. Playing with 70-80ms ping, which is causing long loading between zones,
resulting in 2-4 minutes disadvantage in 1 hour races. (I was wrong, it wasn't a ping issue but something else on GGG side) |
![]() |
Stand alone client locks your account if somebody tries to login from another location so hackers need to control your email as well to unlock the game. I thought steam was more secure, but maybe not.
Guild Leader The Amazon Basin <BASIN>
Play Nice and Show Some Class www.theamazonbasin.com |
![]() |
" true in fact, hackers do have their way of hacking into account unconventional way it seems like. My friends that used stand alone account got their accts hacked before. For me, I am just unsure how this happened with steam. Steam will always send me a access code if someone else try to log in to my acct from any computer other than mine. Funny thing is it really happened within a matter of 5 hours too and I did not get sort of notification. |
![]() |
" Thanks for sharing your experience and information. However, I have to explain that I am not running 3 different programs concurrently. I have malware detector on and the other two are one virus program and another malware program which are ran manually to scan my computers and I do it pretty frequently. This should not cause any crashing or ineffectiveness in terms of protecting my computer. Nonetheless, its disappointing how steam did not notify me with my steamguard activated for many years. They only missed this one too.. |
![]() |
Doesn't the person need to somehow know both your poe password and email password to login? How does someone get both. IGN: Arlianth
Check out my LA build: 1782214 |
![]() |
That's really terrible.
I would be devastated if my account was wiped.. Not supposed to beable to happen.. do what you want to the girl, but leave me alone.
|
![]() |
Strange the guy must be a mid tier hacker like he bypassed
1) Steam guard 2) IP lock via your account 3) he also needs your core email Dys an sohm
Rohs an kyn Sahl djahs afah Mah morn narr |
![]() |
There are plenty of other plausible... perhaps more plausible... scenarios.
|
![]() |
Just to be clear, there is no way for someone to hijack a Steam account by using Procurement without changing passwords, which is immediately noticeable.
When you log into Procurement using a sessionid, that is a sessionid from pathofexile.com. At worst, someone get ahold of that sessionid could use it to reset a pathofexile.com username and password - but it won't get you backwards into Steam. If none of OP's passwords have been changed, then their Steam account was hijacked. There have been a few situations where Steam accounts have been vulnerable, maybe the OP was on a list of hijacked accounts during the July bust and reset his password to the same one or something and it just took this long for someone to take advantage of it. Also, it's pretty unlikely that a "hacker" bypassed Steam Guard, and logging into the account from another location would have triggered an e-mail at the very least. The only reasonable assumption here is that either OP's e-mail AND steam accounts have been compromised, or someone took control of his computer remotely. Both are pretty extreme. Pete's Simple Path of Exile Tools: http://exiletools.com
Item Price Lookup Macro, Ladder API, Price API, League Reports, Item Reports, and more! | |
"How can this happen?" My first guess is that somebody acquired your password—simple as that. If you use a weak password or use the same password for more than one login, the chances get worse for you.
The Analytical Engine has no pretensions whatever to originate anything. It can do whatever we know how to order it to perform.
|
![]() |