Results 1 to 21 of 21

Thread: Hacked READ

  1. #1
    Join Date
    Mar 2013
    Posts
    58
    Mentioned
    0 Post(s)
    Quoted
    24 Post(s)

    Default Hacked READ

    Hello to all fellow botters,
    I recently got hacked for over 8m of resources when I was botting fletching at pest control using this script.
    http://villavu.com/forum/showthread.php?t=98699

    I have not used any other bot, put my username or password, or clicked on any suspicious link to get my account hacked from another source.
    I can confirm 100% that it was simba and it was most likely this script.
    As much as I like this script, I have decided to continue using it but with caution. I am not typing my username or password in the script to auto log me in.
    That was the only place I typed in my username and password.
    Now what does this mean for us? You can't trust any botting websites. The best you can do is transfer your resources over everyday from your botting accounts, Secure them with JAG and a bank pin, etc.
    Please don't tell me that it could have been something else or Jagex because if it was jagex then it would have been banned and + I did get a notification saying that the person that was trying to log on my account was indeed from the US. I did use the same PW for my email and for my runescape login which was quite unwise but then again, I thought I could trust this client because it was open source.
    Conclusion, don't put your username or password in the auto login, follow the steps above to be safe and never get hacked, always bank your items when you log out and always have a pin.
    Thanks.

  2. #2
    Join Date
    Aug 2007
    Location
    Colorado
    Posts
    7,421
    Mentioned
    268 Post(s)
    Quoted
    1442 Post(s)

    Default

    I just checked the script and there's absolutely nothing malicious in it. Now, a couple questions for you: where did you download Simba/SMART/SRL-OSR? And did happen to record the IP address of the last person who logged in? If so you can provide that to a moderator or administrator and they'll run it through the full list of everyone in this community for matches.

    Current projects:
    [ AeroGuardians (GotR minigame), Motherlode Miner, Blast furnace ]

    "I won't fall in your gravity. Open your eyes,
    you're the Earth and I'm the sky..."


  3. #3
    Join Date
    Apr 2013
    Location
    Las Vegas
    Posts
    111
    Mentioned
    1 Post(s)
    Quoted
    35 Post(s)

    Default

    Quote Originally Posted by heyaiam View Post
    Hello to all fellow botters,
    I recently got hacked for over 8m of resources when I was botting fletching at pest control using this script.
    http://villavu.com/forum/showthread.php?t=98699

    I have not used any other bot, put my username or password, or clicked on any suspicious link to get my account hacked from another source.
    I can confirm 100% that it was simba and it was most likely this script.
    As much as I like this script, I have decided to continue using it but with caution. I am not typing my username or password in the script to auto log me in.
    That was the only place I typed in my username and password.
    Now what does this mean for us? You can't trust any botting websites. The best you can do is transfer your resources over everyday from your botting accounts, Secure them with JAG and a bank pin, etc.
    Please don't tell me that it could have been something else or Jagex because if it was jagex then it would have been banned and + I did get a notification saying that the person that was trying to log on my account was indeed from the US. I did use the same PW for my email and for my runescape login which was quite unwise but then again, I thought I could trust this client because it was open source.
    Conclusion, don't put your username or password in the auto login, follow the steps above to be safe and never get hacked, always bank your items when you log out and always have a pin.
    Thanks.
    For the time being nobody can say for sure how your account got hacked, but to state that it was Simba without a doubt is just plain wrong.

    If you used the same password on both email & rs account, chances are you have used the same password on any of the millions of services that prompt you for a password; any of which could have been linked to your rs account resulting in your account getting hacked. Even if you used the same password only once & it was 3+ years ago, that is enough to come back and bite you in the ass one day.

    You claim that you can 100% confirm that the hacking was due to Simba, but you also state that you used the same password for your e-mail. Although it is extremely unlikely, it is possible that someone with access to the email provider's database was able to view your password and link it to your RuneScape account. Again, this is extremely unlikely, but the chances are above 0 which means you cannot be 100% sure that the hacking was Simba. You say to not 'tell you it could have been something else', but evidence from your own post proves that it could have in fact been something else.

    I personally believe you exposed your ass in other ways which you are not able to recognize at the moment and that is what caused the hacking. If this truly was Simba, chances are there would be a lot more pissed off victims spamming the forums with these types of threads. I also looked over the script in question and failed to find anything malicious. Another possibility is someone else using your computer accidentally downloaded a keylogger or perhaps even installed one with the intentions of hacking your account. Maybe someone saw you type in your password. Maybe someone is running a packet sniffer on your network and sniffed out your Runescape details. Maybe you are on the FBI watch-list and an agent going through your records plays Runescape. Maybe aliens used technology beyond our comprehension/imagination to hack your account from 92 million light-years away.

    The amount of unknowns are way too high to accurately isolate Simba as the culprit, but if nothing else the experience is an opportunity to learn.

  4. #4
    Join Date
    Mar 2007
    Posts
    5,125
    Mentioned
    275 Post(s)
    Quoted
    901 Post(s)

    Default

    You claim that '100% that it was simba and it was most likely this script.' Yet you provide 0 evidence to back it up

    Forum account issues? Please send me a PM

  5. #5
    Join Date
    Jan 2013
    Posts
    294
    Mentioned
    1 Post(s)
    Quoted
    121 Post(s)

    Default

    botting was never safe in the first place with any client.
    i never put in my pass/id in my bot cos i can always get back <6hrs.

  6. #6
    Join Date
    Apr 2013
    Location
    Las Vegas
    Posts
    111
    Mentioned
    1 Post(s)
    Quoted
    35 Post(s)

    Default

    Quote Originally Posted by dzpliu View Post
    botting was never safe in the first place with any client.
    i never put in my pass/id in my bot cos i can always get back <6hrs.
    It's not always about passwords you know. I wrote a script that can remote control your SMART window (and your account) without you even knowing. It can be packaged/disguised into any functioning script & on-command temporarily pauses the script while I do whatever I want with your account.

  7. #7
    Join Date
    Jan 2013
    Posts
    294
    Mentioned
    1 Post(s)
    Quoted
    121 Post(s)

    Default

    Quote Originally Posted by bob_dole View Post
    It's not always about passwords you know. I wrote a script that can remote control your SMART window (and your account) without you even knowing. It can be packaged/disguised into any functioning script & on-command temporarily pauses the script while I do whatever I want with your account.
    well that will only work for those who doesnt understand a thing with scripts. i am not good at scripting but i definitely able to spot suspicious function/procedures.

  8. #8
    Join Date
    Feb 2012
    Location
    Discord
    Posts
    3,114
    Mentioned
    37 Post(s)
    Quoted
    538 Post(s)

    Default

    Quote Originally Posted by dzpliu View Post
    well that will only work for those who doesnt understand a thing with scripts. i am not good at scripting but i definitely able to spot suspicious function/procedures.
    Not necessarily. It's fairly easy to hide code where its hard to spot.
    (hiding code is against the rules on scripts posted on srl)

  9. #9
    Join Date
    May 2012
    Location
    Somewhere in, PA
    Posts
    1,810
    Mentioned
    9 Post(s)
    Quoted
    226 Post(s)

    Default

    Quote Originally Posted by dzpliu View Post
    well that will only work for those who doesnt understand a thing with scripts. i am not good at scripting but i definitely able to spot suspicious function/procedures.
    Why don't you put your pass in scripts then?
    My First Build!, Selling Downloadable Games
    -------------------------------------

  10. #10
    Join Date
    Sep 2010
    Posts
    5,762
    Mentioned
    136 Post(s)
    Quoted
    2739 Post(s)

    Default

    It boggles my mind as to how 4,681 people have downloaded the script in the past 4 months and your the only one to claim that it was from the script :/

  11. #11
    Join Date
    Jan 2013
    Posts
    294
    Mentioned
    1 Post(s)
    Quoted
    121 Post(s)

    Default

    Quote Originally Posted by Austin View Post
    Why don't you put your pass in scripts then?
    lol why the hate against me? btw i mentioned my reason like 3 or 4 posts above you.

  12. #12
    Join Date
    Aug 2007
    Location
    Colorado
    Posts
    7,421
    Mentioned
    268 Post(s)
    Quoted
    1442 Post(s)

    Default

    Quote Originally Posted by Officer Barbrady View Post
    It boggles my mind as to how 4,681 people have downloaded the script in the past 4 months and your the only one to claim that it was from the script :/
    This is actually a good point; think about it.

    Current projects:
    [ AeroGuardians (GotR minigame), Motherlode Miner, Blast furnace ]

    "I won't fall in your gravity. Open your eyes,
    you're the Earth and I'm the sky..."


  13. #13
    Join Date
    May 2012
    Location
    Somewhere in, PA
    Posts
    1,810
    Mentioned
    9 Post(s)
    Quoted
    226 Post(s)

    Default

    Quote Originally Posted by dzpliu View Post
    lol why the hate against me? btw i mentioned my reason like 3 or 4 posts above you.
    You said it wasn't safe, but the only way it wouldn't be safe is if there was something phishy in the script.

    I'm just saying.
    My First Build!, Selling Downloadable Games
    -------------------------------------

  14. #14
    Join Date
    Sep 2010
    Posts
    5,762
    Mentioned
    136 Post(s)
    Quoted
    2739 Post(s)

    Default

    Quote Originally Posted by dzpliu View Post
    lol why the hate against me? btw i mentioned my reason like 3 or 4 posts above you.
    Hes not hating on you hes just pointing out that you won't put your username or password in scripts yet you can spot malicious procedures/functions just doesn't make sense

  15. #15
    Join Date
    Jan 2013
    Posts
    294
    Mentioned
    1 Post(s)
    Quoted
    121 Post(s)

    Default

    Quote Originally Posted by Officer Barbrady View Post
    Hes not hating on you hes just pointing out that you won't put your username or password in scripts yet you can spot malicious procedures/functions just doesn't make sense
    i'm just trying to play safe, i'm really thankful for all the scripts here but i think i can manage reloading RS every 6Hrs. i had no problems with any scripts in villavu regarding password thieving or watsoever, just trying to lessen the risk.
    Everyone has their own way of playing/botting right?
    it doesn't mean that if anyone liked to fill in passwords into the scripts so i should follow anyone who does that right :/

  16. #16
    Join Date
    Sep 2008
    Posts
    754
    Mentioned
    8 Post(s)
    Quoted
    275 Post(s)

    Default

    Sorry to hear that you were hacked, i know the feeling.. It sucks.

    A moderator could help you by trying to find if the IP (given the premise the hacker didn't use a vpn/proxy) matches any of the users ip's on srl forums.

    It would be truly helpful if you could take a screenshot of the email sent to your inbox from Jag showing the ip that was blocked while trying to login to your eoc account (or just pm it to a moderator, that works too).

    Hopefully you manage to bounce back up and not let this deter you from playing 07scape.. Jagex needs to improve security on that game..
    Quit gaming

  17. #17
    Join Date
    Aug 2010
    Posts
    173
    Mentioned
    0 Post(s)
    Quoted
    9 Post(s)

    Default

    I'd really like to see some proof to this because I botted to 99 with that script and never had any issues or saw anyone on the forums saying that they had stuff stolen. I'll back up that script any day because its the best script I've seen for 07

  18. #18
    Join Date
    Mar 2013
    Posts
    58
    Mentioned
    0 Post(s)
    Quoted
    24 Post(s)

    Default

    I don't have the IP at the moment.

  19. #19
    Join Date
    Jun 2012
    Posts
    4,867
    Mentioned
    74 Post(s)
    Quoted
    1663 Post(s)

    Default

    Quote Originally Posted by heyaiam View Post
    I don't have the IP at the moment.
    Do you think that you will later?

  20. #20
    Join Date
    Jan 2012
    Posts
    1,596
    Mentioned
    78 Post(s)
    Quoted
    826 Post(s)

    Default

    Quote Originally Posted by heyaiam View Post
    I thought I could trust this client because it was open source.
    Oh this one... Thats false. This argument/comment always comes up when someone alleges that they were hacked by simba. Yes you can go look at the code and read through it all, but have you? Who else has? Probably not many.

  21. #21
    Join Date
    Mar 2012
    Location
    127.0.0.1
    Posts
    3,383
    Mentioned
    95 Post(s)
    Quoted
    717 Post(s)

    Default

    Quote Originally Posted by Turpinator View Post
    Oh this one... Thats false. This argument/comment always comes up when someone alleges that they were hacked by simba. Yes you can go look at the code and read through it all, but have you? Who else has? Probably not many.
    Heck, the source might not have a virus, put the compiled version for download might, I assume 99% of people here don't read the source and then compile it.


    Not saying Simba does, because it doesn't.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •