Page 1 of 2

Phishing via Shivtr

PostPosted: Tue Sep 08, 2015 12:11 pm
by Ohr
Just want to warn everyone that the admin of server name hidden is abusing shivtr to phish and steal nostalrius accounts. Here's his hack form http://www.server name hidden.com/shivtr/l.php. He injects it into Shivtr applications. We recently got an application called "Yes" and when you click it a window to log in to shivtr pops up. if you fill that out, he gets your details and steals your shit.

The way i managed to delete the app was to "inspect element" and delete the <iframe> code from his php inject script in google chrome. Be careful and spread the word to all the guilds using Shivtr and the standard Application form on it.

I didn't take screens as taking the app down asap was my main priority due to other applicants/guild members in risk of losing their accounts. If the staff wants to find out which server is doing this feel free to PM me, I'll give you more details.

Re: Phishing via Shivtr

PostPosted: Tue Sep 08, 2015 1:44 pm
by propergamer1978
Props to you warning everyone Ohr and a bump for you.

You're a great boon to this server. Keep it up man!

Re: Phishing via Shivtr

PostPosted: Tue Sep 08, 2015 3:47 pm
by pmizz
Your Nost pwrod should be 15 characters in a combination of

FawAl242Adm3TO4n

Re: Phishing via Shivtr

PostPosted: Tue Sep 08, 2015 4:28 pm
by Robotron
Thanks for sharing this.

Re: Phishing via Shivtr

PostPosted: Wed Sep 09, 2015 2:11 am
by chunass
Another bump to you, good man :>

Re: Phishing via Shivtr

PostPosted: Wed Sep 09, 2015 3:14 am
by ILikeEggs
Thanks for being a hero, Ohr. Just another reason why there should be easier ways to recover your account.(It's been a while, not sure if you still have to be logged out for 24 hours which is retarded, should be able to reset your password via the ORIGINAL Email for the account, regardless of if/when it was logged into)

Re: Phishing via Shivtr

PostPosted: Wed Sep 09, 2015 6:47 am
by Overtime
pmizz wrote:Your Nost pwrod should be 15 characters in a combination of

FawAl242Adm3TO4n


Password sentences are actually more reliable nowadays.

Re: Phishing via Shivtr

PostPosted: Wed Sep 09, 2015 1:18 pm
by Shadowbox
Mine is hunter2 but it's okay because it shows up as *******

Re: Phishing via Shivtr

PostPosted: Wed Sep 09, 2015 2:04 pm
by Atreidas
Shadowbox wrote:Mine is hunter2 but it's okay because it shows up as *******


Jet fuel can't melt dank memes

Re: Phishing via Shivtr

PostPosted: Wed Sep 09, 2015 6:57 pm
by draxyl07
Just as a reminder:

Passwords on WoW clients are not case sensitive, so keep in mind that you should use special characters to off-set this for heightened security.