General

OFFICIAL: Phisher/Keylogger Alert!

Hello Basilers,

Yep, every year the Birthday event comes with this one unwanted accessory: a phisher. Right now a phisher's on the loose in the forums, trying to trick people into visiting his/her site and asking for their info.

Open door: [b]don't give him your info![/b] Every website that asks for your GMS info and isn't part of the nexon.net domain is a guaranteed [i]fake[/i].

We're trying to take this guy down, but the reports box is stuffed. When you report him we don't immediately see your report. We'd greatly appreciate it if you PMed one of us, or all of us, as soon as you spot the phisher and his/her threads. We'll take remove the threads and forward the phisher's accounts to MrBoss who can block his/her IP address.
He uses a repeating BasilID, but I forgot it (because I'm an idiot) so I can't track him/her down myself. -_- If you see him/her and PM him/her I'll be able to find his/her other BasilIDs until he decides to stop the trend.

Thanks for your help and I hope you'll have a nice event,

Pav

PS: Basil Market does not do "survival of the fittest" or "Hail the phisher for ridding our community of dumb people!", but if you feel this person's doing a good job by all means demonstrate that by not reporting him/her. If you encourage people to visit his/her site your account will suffer the same fate as his/hers.

May 4, 2013

47 Comments • Newest first

Pavchka

[quote=metaghost4]@Pavchka: You're sick-minded, even for a mod.[/quote]

I've heard that one before in various shapes and forms. Basil's version of "I'm a doctor, not a ...", so it seems.

Reply May 7, 2013
BobR

With all the problems Maplestory has been having, people should be on the lookout for this slimeball to try to take advantage of people by posting fake Nexon "compensation" pages. Remember, Nexon does NOT give away 25k NX just for "logging in" anywhere.

Anything you see posted like that is FAKE and trying to steal your Maplestory account.

Reply May 7, 2013
Pavchka

[quote=metaghost4]Gimme your info!

Although I'm not a phisher, I'm not trying to trick you. I'm being straight and direct with you. Isn't that kind of trustworthiness worth giving me your info? c:[/quote]

I don't know what it is today, but people keep posting things that cause dirty jokes to pop up in my head which I can't post because of rule #3.

[quote=NekoChan]I'll take him down to hell with me when I go and get myself banned again, I promise you that.[/quote]

Feel free to send him down while staying...
This phisher's been plagueing (sp?) us for years, it'd be impressive if you managed to drag him down to the fiery depths of non-Basil. @_@

Reply May 6, 2013
callmerailage

I once fell for a phishing website many years ago on Runescape.

Lucky for me I was very poor, BUT...

They stole my Black Halberd that I was so proud of >.<

Oh Railage you naive child.

Reply May 6, 2013 - edited
Pavchka

I doubt you were actually the phisher, Garen. It seems more like *ahem*urmom and you were the same guy on two accounts. Well, MrB's quick.

@Ravnica: I wish I could help you, but I haven't logged into the game for a while because my laptop and modem seem to have joined forces against the Downloader. I can't seem to download GMS at the moment.

Reply May 6, 2013 - edited
Ravnica

Unrelated but I can't make a new thread:
Is there a way to get a Scroll Synergizer? Is there a way to get a Mastery Book Synergizer?

Thank you so much!

Reply May 6, 2013 - edited
Pavchka

[quote=Drag0nLlght]Umm you know that those site take your info directly off your computer right? putting in your info onto won't do anything[/quote]

Do you mean a RAT infection? RATs usually require a download of some sort (we've had plenty of RAT threats as well).

EDIT: Let's stay nice.
I haven't been the phisher any more, by the way. I noticed MrB's been around today. Maybe he took care of him/her.

Reply May 6, 2013 - edited
lightwin

again to the guy talking about MAC addresses when u dont know what ur talking about please shut it

Reply May 5, 2013 - edited
Drag0nLlght

[quote=KelvinCEO]I saw this the other day one guy made a thread and when I click on it it sends me to a site sign in put ur info for free 30k nx it was a scam so I put random letters on login and password and it sends me directly to real nexon site after that.[/quote]

Umm you know that those site take your info directly off your computer right? putting in your info onto won't do anything

Reply May 5, 2013 - edited
Hilario70

@BobR: lol wow.. I honestly only read the first sentence.. >.<
It's called [b]cmd[/b] btw.. Don't be too technical now >.<

Reply May 5, 2013 - edited
BobR

[quote=Hilario70]Trust me, I studied in Computer Networking. [/quote]

Did you study ARP..?
ARP resolves MAC addresses on a LOCAL network, but does NOT transmit them over the Internet.
TCP/IP does NOT use MAC addresses to identify source or destination.
The router maintains an ARP table, isolated on the private side, not accessible from the public side.
The only MAC address on the public side is the WAN interface of the router, and even that isn't transmitted over TCP/IP.
ARP (and MAC) operate on layer 2 of the OSI model, TCP (the Intenet) operates on layer 3. There's no need for MAC info to be transmitted over the Internet, so it's not.

About the only way you can determine the MAC address of a computer over the internet would be to inject a program onto the victim computer to extract and transmit that data (ie, Spyware). Systems that use any kind of "MAC locking" to prevent you from running the program on more than one computer have that built into their application because you CAN'T get the computer's MAC address just from the Internet.

How this relates to the topic-
If it was that easy to determine MAC addresses, sites like Basilmarket (and Maplestory for that matter) would use it to prevent situations exactly like we're talking about here where some kind of misanthrope is trying to victimize other users, or at least make it more difficult for the sleazeballs trying to do it.

Reply May 5, 2013 - edited
Hilario70

[quote=ILoveKaiser]No, you need to be using the same router as the person who is phishing... so unless the master goes to his physical address and hacks into the router, then yes he can find out the MAC address.. but honestly I do not see how the master will do that(:[/quote]

lolwut?
Getting a MAC Address is easier than you think..
MAC Addresses CAN be changed believe it or not..
Trust me, I studied in Computer Networking.

Reply May 5, 2013 - edited
BobR

[quote=exterZ]You sound like a GM but then you call yourself an idiot so I'm confused.[/quote]

She's modest.
Everybody makes mistakes sometimes, but not many people have the balls to admit it.
Even though in Pav's case that metaphor is inapplicable.

Reply May 4, 2013 - edited
wolfexe

[quote=exterZ]You sound like a GM but then you call yourself an idiot so I'm confused.[/quote]

He's saying he isn't perfect. Everypony.... well... almost everypony anyway, makes mistakes.

Reply May 4, 2013 - edited
exterZ

You sound like a GM but then you call yourself an idiot so I'm confused.

Reply May 4, 2013 - edited
wolfexe

It might also be worth noting that phishers might also make a matching domain name. example being like a nexon(.not net) in an attempt to catch careless users. As well as try to match the real sites layout in an attempt to make theirs look like the real site.

Reply May 4, 2013 - edited
BobR

[quote=Pavchka]I haven't seen the phisher return after I forwarded his/her account again today. I wonder if or when s/he'll pop up again...[/quote]

I was sort of expecting to see some kind of "Oh golly, we're sorry about that Phantom hack yesterday, here's 30k NX to make up for it, just enter all your details here"
garbage pop up. This kind of slime usually doesn't miss any opportunity to steal other people's stuff.

Reply May 4, 2013 - edited
Pavchka

[quote=ajwright92]@pavchka Ah I see , at least there is work being done on it. Even still at least the community is at least keeping a lookout.[/quote]

We're actually delaying the release of the Deputy system until it's been perfected. MrB is able to launch it any moment as far as I know, he's waiting for us to give him the green lights. I'm afraid the rules won't change. I appealed for them to be simplified, but MrB believes they're fine the way they are right now (technically it's not the rules that are complicated, it's the policies). Ah well ah well!
So technically it can launch any moment. @_@

I haven't seen the phisher return after I forwarded his/her account again today. I wonder if or when s/he'll pop up again...

Reply May 4, 2013 - edited
ajwright92

@pavchka Ah I see , at least there is work being done on it. Even still at least the community is at least keeping a lookout.

Reply May 4, 2013 - edited
Pavchka

@LazyLazyLazy
The Euromod thanks the Chat section's correspondent but would rather not remove said correspondent's comment because that can currently only be done through the Warning system, which is bugged, causing the Warned to receive a dispropotionate 6 hour posting restriction.
*beep*
Back to you, Cuthbert.

Reply May 4, 2013 - edited
Nolen

Hello, I am a correspondent from the Chat Section and I request attention towards a slight trouble maker. http://www.basilmarket.com/user/WhereDaHoodDat
Also if the troublemaker I have listed disappears, please delete my comment discretely.

Reply May 4, 2013 - edited
Pavchka

[quote=nc4228]I believe a lot of people are in high school or college taking advanced chemistry and math courses given that many people I trade with here claim they can't get on because they have college exams and the number of people I see asking for homework help.[/quote]

True, there are lots of high school students here, there are also much younger people and a few older people. I myself am a 27 year-old Bachelor of Arts going for Master in Linguistics. o.o I've grown old and wise enough to learn about keyloggers and phishers etc (and all that from Basil! I hardly visit other fora) but the young children aged 10-14 often have a few things to learn about the more sinister aspects of the Internet. I really don't want them to learn about this stuff the hard way, I already have the idea many of today's teenagers are somewhat more bitter and cynical than I was when I was of their age.

[quote=ajwright92]@Pavchka Ah it pays to have a undercover agent
Year most people like that aren't quite smart enough to change the name , hopefully people will look out for that name.
Has Mr.Basil came up with anymore information about the sheriff job?[/quote]

I know right. Someone's got to have the brains when mine aren't working properly.
We're in the process of finalising the Deputy system, it'll need some more adjustments and then it should be ready for launch. No clue when that'll happen, though. We requested quite some changes that'll take a while to implement. Many of them are supposed to make stuff easier on users, like mod comments (we can't post mod comments very easily at the moment so many users don't know what they did wrong) and a somewhat different suspension system (shorter and more consistent suspension lengths). Right now we don't know if or when they'll be implemented since MrB has the final say in things, but we hope they will be.

EDIT: Skyenets is right. A good hint: Links to Nexon's official website go with a small red leaf symbol on Basil*.
That's safe. We will have to assume that every link that pretends to be Nexon but does [i]not[/i] display the leaf symbol is [b]fake[/b] and therefore cannot be trusted!

* I mean... usually it does. Why didn't it for me? Grr

Reply May 4, 2013 - edited
ajwright92

@Pavchka Ah it pays to have a undercover agent
Year most people like that aren't quite smart enough to change the name , hopefully people will look out for that name.
Has Mr.Basil came up with anymore information about the sheriff job?

Reply May 4, 2013 - edited
nc4228

[quote=Pavchka]You're entitled to believe so, of course, but Basil's policies in that area differ for reasons I'll not go into unless requested. You're not obliged to report the phisher.

@Dbkim20: A phisher pretends to be a company or organisation (for example your bank or in this case Nexon) that asks for your information, informing you of some "emergency" or offering you rewards of some sort. When they have your info they'll try to access your account and steal whatever Mesos/NX/money you have on it. They especially prey on the not so Internet-savvy or young people.
Basil is full of people who are very young and don't have much experience with the Internet yet. I personally don't want them to learn what phishers are the hard way.

8 PM 4th of May, will be back in two minutes.[/quote]

I believe a lot of people are in high school or college taking advanced chemistry and math courses given that many people I trade with here claim they can't get on because they have college exams and the number of people I see asking for homework help.

Reply May 4, 2013 - edited
Pavchka

[quote=ajwright92]HI @Pavchka
Was it @papasali6
Because he occured twice, in my list of names.[/quote]

Jeesh. See? I'm a moron. XD I completely forgot to check your PMs for the guy's name. I even found it in my history. I'm sooooooo glad I'm only working on "public relations" right now and not on reports.
Thanks. There's no Papasali8 or 9 (yet). Maybe he has yet to turn up or has changed to a different BasilID.

Reply May 4, 2013 - edited
BobR

[quote=ajwright92]Was it @papasali6
Because he occured twice, in my list of names.[/quote]

Yes, that was one of the names being used by the "person" posting these phishing sites.

Reply May 4, 2013 - edited
Skyenets

Something everyone should keep in mind:
[b]Nexon's official domain is Nexon.net. A subdomain would be maplestory.nexon.net. Nexon can make unlimited subdomains. So any domain that isn't [i]something[/i].nexon.net, is false.[/b]

Reply May 4, 2013 - edited
BobR

[b]ANY thread that says ANYTHING about getting NX Cash for Free from a Maplestory event is FAKE and is trying to STEAL YOUR ACCOUNT[/b]

This slimeball has been using variations on the same thing, posting that Nexon is giving away 30K NX or whatever, as part of whatever Maple event is going on.

[b]THESE ARE ALL FAKE[/b]

The site he sends you to looks EXACTLY like a Nexon login page, but if you enter your info, you're [b]giving HIM your password[/b] and the next time you try to play Maplestory your account will be STRIPPED.

Like Pav said, we're removing his garbage as quickly as possible, but if anyone sees this kind of thing, PM one of us as soon as you see it and we'll take care of it as soon as we can.

And for all the "anyone who falls for this stuff deserves it" kind of comments- not everyone is born knowing EVERYTHING like you experts, and if these things didn't work sometimes, the sleazeballs who do them wouldn't bother with it.

Reply May 4, 2013 - edited
bluebomber24

I will help you take out the trash.

Reply May 4, 2013 - edited
ImBlue1562

Thank you Pavchka , If I see any suspicious link I will PM you ASAP.

Reply May 4, 2013 - edited
Pavchka

@Star375: The phisher has been advertising different sites and the one you listed was one of them. Looks extremely fishy (no pun intended). EDIT: Andwoos nailed it. Always listen to MapleTip!
By the way, would you mind editing it out of your comment so gullible users won't visit it out of curiosity? I just put the name in the filter so he'll have a harder time advertising it. Thanks for pointing it out.

[quote=firedannyX]@pavchka why don't you sticky this on the top of the forums so everyone can see?[/quote]

Moderators don't have sticky powers. We have to resort to Officials. I'd have stickied this if I had the ability.

[quote=PressF13]Well, if you can't find the phisher by looking around threads, then he can't be that much of a threat.[/quote]

There are too many threads for the two or three or so active moderators to handle. That's why we really need the community to help us out.

Reply May 4, 2013 - edited
Andwoos

[quote=Star375]So (edited out) is fake?

If so I know the phisher.[/quote]

Yep, that's a phishing site. Nexon will never need your account password or PIC.

Reply May 4, 2013 - edited
PressF13

Well, if you can't find the phisher by looking around threads, then he can't be that much of a threat.

Reply May 4, 2013 - edited
Wehyg

LOL Im getting 30k NX in only 5 months!
EDIT: Meh, all my characters are nude and i lost my mesos and items, mabye a glitch.
EDIT2: All my lv 200s getting deleted? Must be a rollback
EDIT3: Wow, I did a stupid thing. Must have been that stupid Evony ad that gave me a keylogger!

Reply May 4, 2013 - edited
firedannyX

@pavchka why don't you sticky this on the top of the forums so everyone can see?

Reply May 4, 2013 - edited
Pavchka

[quote=ilikefoodand]There was a guy pming me, asking me for nudes.
Is this the same guy?[/quote]

Probably a different person. I forked all "yucky spammers" over and their accounts are still intact, so MrB probably didn't get to them yet. If they'd been the phisher those accounts would probably have been erased along with his/hers. o.o
Ech, why can't I remember that BasilID? I was something with palali...

Reply May 4, 2013 - edited
ilikefoodand

There was a guy pming me, asking me for nudes.
Is this the same guy?

Reply May 4, 2013 - edited
evilslasher

Time to visit basil during the night and spam warning messages in caps in said threads.

Reply May 4, 2013 - edited
Pavchka

[quote=SmashDragoon]Just pointing out a small thing, but I think it should be a him/her, since we don't know for sure if the person is male or female.
I'll send in a PM if I happen to see him too myself.[/quote]

True. So far the person has been taking random male characters off the rankings so I used "him" instead of "him/her".
-sigh- Commemoration Day. It's always a sad day...

Reply May 4, 2013 - edited
SmashDragoon

Just pointing out a small thing, but I think it should be a him/her, since we don't know for sure if the person is male or female.
I'll send in a PM if I happen to see him too myself.

Reply May 4, 2013 - edited
MystChronic

[quote=ILoveKaiser]It is basically impossible to trace somebodies MAC address....
There is a TINY chance but it is a very slim chance....[/quote]

true, but in sense that no ordinary or uni person could. the person would need to be in a networking field and probably work for rogers and those types of company.

Reply May 4, 2013 - edited
Pavchka

[quote=TheNutCracker]Whoever falls for this trick deserves it, i mean entering your own info on a website other than nexon, well that is amazing(not unless your trying to troll the phisher)[/quote]

You're entitled to believe so, of course, but Basil's policies in that area differ for reasons I'll not go into unless requested. You're not obliged to report the phisher.

@Dbkim20: A phisher pretends to be a company or organisation (for example your bank or in this case Nexon) that asks for your information, informing you of some "emergency" or offering you rewards of some sort. When they have your info they'll try to access your account and steal whatever Mesos/NX/money you have on it. They especially prey on the not so Internet-savvy or young people.
Basil is full of people who are very young and don't have much experience with the Internet yet. I personally don't want them to learn what phishers are the hard way.

8 PM 4th of May, will be back in two minutes.

Reply May 4, 2013 - edited
MyEyesHurt

Thats our pav

Reply May 4, 2013 - edited
KelvinCEO

I saw this the other day one guy made a thread and when I click on it it sends me to a site sign in put ur info for free 30k nx it was a scam so I put random letters on login and password and it sends me directly to real nexon site after that.

Reply May 4, 2013 - edited
WhoIsDead

[quote=ILoveKaiser]well the phisher can easily use hotspot shield to hide his IP address...[/quote]

There's also MAC address banning.

Reply May 4, 2013 - edited
Dbkim20

What's a phisher lol

Reply May 4, 2013 - edited