It has been a rather disturbing past two days or so as I recover from the horrid hack on both my WordPress blog and my actual Runescape account itself. I will not give too many details other than to say:
(1) A prior post on my WP blog was titled “0wn3d”, infamously written in ‘hacker-speak’ and I attest that I did not post the entry, having been super busy outside of both gaming or keeping up with daily blogs/sites. I found the entry as an unpublished draft later marked Private on the ‘Manage/New Post’ page and am not sure if anyone actually had read it or not. What someone thought was a reference to my personal life clearly isn’t true and I suppose I need to keep more personal secrecy when it comes to the Internet. There was a personal congratulatory remark in closing which linked to a RS friends’ site–my only hope is it wasn’t some form of earmark for anything to come.
(2) While my Runescape account ‘fweese’ had been compromised, it seems as though there are no lasting effects… my trusty bank PIN seemed to keep all but my current equipped items and inventory safe. I lost my seasonal outfit (the noticeable Kyatt hunter gear), Cooking Cape and Gauntlets, Rune Defender and Magic Secauter. Those items are easily replaceble–God forbid if my entire bank was cleared out! Naturally I do often unequip and bank all items prior to logging out but as luck would have it, after experiencing no ill situation like this before, I placed a bit of faith that my account was fine. I think it hilarious that short of the Kyatt no other item was tradable–making for one very displeased hacker. edit: My friend/ignore list was deleted
and no notice yet from Jagex whether any reportable offenses occurred while I was away.
I initially suspended viewing of this blog–the reason for the censor was to eliminate any further attempts at exploiting information until some time passes, but why tuck tail and hide?
My own computer system is fine; a comprehensive virus and spyware scan turned up nothing. I am assuming there may have been a password capture of some sort on a shared machine. So the normal rigamarole of changing passwords and other security settings should suffice.
A drawback with WordPress is that whenever someone visits your blog their IP address isn’t in any way revealed to the blog owner unless they post a comment. I’m sure if I really wanted to I could contact WP and impress upon getting that information… I feel it would reveal in some way where the hack came from as a review of my blog traffic for about a week has shown ext. search queries like ‘fweese stats’, ‘fweese bank’, ‘fweese setup’, ‘fweese real-life’. Odd terms for a random visitor to search for and I should’ve considered it a flag that something wasn’t right.
This minor, trivial “hit” will not keep me from commenting on my favorite online game or out of touch with you. I’ll just be more cautious of posting ideas that may allow speculation of my personal life, career, and such.
Oh, and yes, I’m stiiiiillllll waiting for Summoning! 