ACCOUNT SECURITY FAQ
General
Hacking
Viruses
Summary
Resources

General

Why should I be concerned about account security?

Each user is responsible for regulating the activity on their machine as well as for keeping private their account information. NCsoft does not compensate for any losses due to an account breach, so it is essential that every player take every precaution necessary when it comes to their game account.

This document has been written to promote game account and system security, as well as to help players understand what steps are required to prevent any unauthorized access on their account.

Isn't it NCsoft's job to provide a safe environment in which to play?

NCsoft maintains secure systems as well as rules and regulations that offer as much protection to our customers as possible. However, NCsoft cannot be responsible for the security of computer systems not on or network, nor can we be accountable for any decision that a user makes regarding their account information.

Why can't I share my account name and password with anyone?

Sharing account information is the most common cause of account theft. Many of the cases of claimed hacking come from individuals who share their accounts with people they previously considered friends. Others are due to a fallout in a personal relationship, while even more are results of someone befriending a user with the ulterior motive of stealing what's on that account. Regardless of the reason, something that could have been prevented - it is absolutely vital to keep this information to yourself.

How can someone get my password?

There are many ways someone can get your password - the most obvious is when it is shared willingly. NCsoft employees will never ask you for your password while trying to help you and you should never give it to someone claiming to be NCsoft support or any NCsoft employee. Additionally, you should avoid giving out your password to anyone else - friend, foe, or other.

A computer criminal could guess your password if they know something about you, so remember to use caution in online group environments. The more information you share about yourself, the easier you make it for crooks to guess your login(s) or password(s). The best thing you can do is pick a random password that you will be able to remember, but that is not remotely related to you. Many people place numbers in their passwords to make it even more difficult for someone to guess a password. For instance: F1L3tRansfer. This is the phrase "file transfer" with random capital letters, a 1 in place of the I and a 3 in place of the E in the word "file." You may also choose a random string of letters and numbers such as: b23fz5d. These are more difficult to remember, but probably the least likely to be guessed.

The most common way for people to get your password is by retrieving it using the Account Management tools on the PlayNC website (https://secure.plaync.com/cgi-bin/accountManagement.pl.) If you share your e-mail account with someone and use that e-mail account on your game account, it is possible that they could retrieve your password if they know your account name. (A similar thing can happen if you use certain instant messenger programs and share your account with someone… they could easily get access to the free e-mail account that you get with IM programs.)

Another way for computer criminals to get a password is to go through a list of all possible passwords, given they know an account name. This might seem tedious, but hackers do it with the help of computer programs that quickly cycle through all potential letter and number combinations. Should this happen (while unlikely, it does happen), the infiltrator needs your account name next. You should guard your account name if you can; avoid making your user name something that is readily accessible or easily guessed. For instance, don't use the name of your main character as your account name.

Remember, if someone has remote access to your system, it is very possible that they will be able to get your password if you have the password saved on your computer. There are two things you can do to prevent this from happening: never leave a save password box checked and keep your system cleared of viruses, particularly Trojans (which are discussed later in this document). Leaving a save password box checked means the password will be stored somewhere on your local drive. While this makes logging into websites or games easier, it also gives crooks a head start in getting your passwords.

Hacking

What does being hacked mean?

NCsoft considers "hacking" to be the criminal act of creating and distributing malicious software onto your machine without your consent, usually via a keylogger or Trojan.

It is important to understand that NCsoft does NOT recognize a "hacked" account to be the theft of items resulting from account sharing, trading, or selling. The integrity, security and interactions of characters on an account are the sole responsibility of the account owner, and not NCsoft's.

There are several ways that users can unknowingly create security holes on their system... instant messaging, websites, e-mail, and third party programs can all be used to gain access to your computer. However by using the right tools, you can make it more difficult for a hacker to get into your computer.

What does a hacker do?

Hackers go through great lengths to gain access to your system - especially if you have a high-speed, uninterrupted Internet connection…. most especially if you do not have a firewall and/or port monitor protecting your system.

If a hacker gains access to your system, he or she could abuse any information you store on your computer: credit card numbers, bank account numbers, game accounts, online shop accounts, and more. They can send spam e-mail from your system, potentially getting your account or IP address banned, and may even attack other computers from your system.

In terms of your game account, a hacker accessing your information could:

  • Kill your character over and over, making your character level down
  • Commit negative actions with your character
  • Transfer in-game property to other characters (namely theirs)
  • Delete any or all in-game items from your character
  • Convince your friends in game to allow the user in the account to "borrow"(steal) their in-game items and property
  • Delete your main or other characters

It is important to reiterate that NCsoft does not have the ability to protect systems outside of its network, and cannot control the actions of any user which may be using your machine, and that it is each user's responsibility to keep secure their computer system and keep private their account information. Because of this, we will not be able to reimburse you in any way for anything else done to your account by a computer criminal.

In order to have NCsoft review the matter, please contact the local authorities to file a criminal complaint about the activity. The act of writing and distributing malicious code is a criminal act, one that the police need to investigate. During the investigation, police will likely need to contact us with a subpoena request to identify and track down the perpetrators. This can be done by writing or faxing NCsoft at the contact below:

NC Interactive, Inc.
Account Administration Department
6801 North Capitol of Texas Highway
Austin, Texas 78731
Fax Number: 512-498-4099

Once we receive this request, we will submit the relevant account information to the police. At that time, we are able to consider this a true “hack” event, and can review the situation to take appropriate action on anyone responsible.

How would a hacker get access to my computer?

Most people are hacked by downloading files from a source they know nothing about or by trusting someone they have met online. In doing this, the hacker has found a way to get your IP address.

In order to connect to the Internet you must have an IP address. Your ISP assigns one to you when you log onto the Internet. Like a telephone number, IP addresses allow other systems to contact you. In other words, this is how data is routed through the Internet. This is how you get your e-mail. This is also how hackers can get into your computer.

Important! It is not possible for a hacker to get your IP address through the game client. The most likely way for someone to gain this information is via contacts you make outside the game.

Security holes are not created by the game client, but you may meet a computer criminal within the community. Hackers can only get information you offer to them. However, most infiltrators can learn things about you - like your IP address - through other forums including, but not limited to:

  • Bulletin Boards (posts may include your IP address)
  • Instant messaging/chat programs
  • IRC chats
  • Direct link Internet games (FPS, RTS)
  • File sharing programs

While finding out your IP address is a popular way to infiltrate your system, it is not the only way. There are lots of hacking programs and tools available to help computer crooks get into your system. Leaving your computer on and unattended for long periods of time - especially if you have an always-on Internet connection - could give hackers access. Viruses are also used to this end. Beware of executable files from sources you do not trust, even if it is a funny slide show or mini game. Hackers frequently use Trojans embedded in executable files to open a port to your computer. Viruses will be discussed later in this document.

Can I tell if I've been hacked? How?

There are ways you can tell that you have been hacked. Unfortunately, most people are infiltrated well before they know. Some indications are:

  • Unauthorized charges to your credit cards
  • Unauthorized actions in your bank or investment accounts
  • Unauthorized use of your game accounts
  • Being accused by other individuals or ISPs of sending spam e-mail you know you have not sent
  • Running a virus scanner discovers Trojans or backdoor software installed on your machine
  • Strange computer behavior (random reboots, sounds suddenly playing, windows popping up unexpectedly, passwords being locked out, and so forth)

There have been reports that a hacker could even erase your hard drive! It is important to protect yourself from this type of malicious behavior.

What do I do if I've been hacked?

If you find evidence of a Trojan or other virus on your system, you should disconnect your computer from the Internet and contact your local authorities to report the crime.

We also advise that you contact one of our support teams in order to have your account suspended while you clean your machine. Once that is completed, and you feel you are secure, we will be happy to reactivate the account.

Viruses

What is a Virus?

Viruses are small software programs that "attach" themselves to other programs. Once a program is run, the virus begins to replicate itself and attach itself to other files resident on the machine.

What do viruses do?

Viruses do many different things. Many lay dormant for a long time and then can cause problems on your system when a certain file is used or on a certain day. They can be like little mischievous gremlins or they can cause a lot of damage, like wiping your hard disk. Others make themselves present every time you boot your system. Viruses are also transmitted and shared by attaching themselves to outbound e-mails or files saved to portable storage devices such as CD-ROMs and floppy disks. This allows them to spread much like a communicable virus from person to person.

What is a Trojan?

Trojan viruses are named after the famous story of the Trojan horse. Long ago, the Greeks were attempting to gain entrance into the city of Troy. They built a large wooden horse and hid a force of soldiers inside if it. The people of Troy saw the horse as a gift and moved it inside the city walls. Sometime during the night the Greek army made their way out of the horse and opened the gates to the city, giving the rest of the army access to the city. They burned down and killed many of its inhabitants. Much like the story, a Trojan is a seemingly harmless program that once installed on your machine will then open up a gateway to allow others to gain remote access to the computer.

Trojans allow people to access your system and remove, add, or manipulate files. Any action done on your computer can be seen or copied, allowing hackers to obtain private information on your computer, copy your credit card numbers, or learn the passwords you enter while performing online banking, purchases, or gaming on the Internet.

This can all happen without your knowledge in the background of your computer, and this is what makes Trojans such a popular and successful way for hackers to gain access to your system.

How do I get a Trojan?

Actually, you inadvertently install a Trojan by running an infected executable program on your system. Trojans take advantage of the fact that so many programs that we use process other things in the background. Additionally, the executable programs come disguised as pictures of a "friend," as funny multimedia clips, as mini programs that offer some helpful tool, and the like. This makes it very important to never download or run programs from someone you don't trust implicitly, or that are not from a trusted web resource.

The two most common Trojans are Back Orifice and NetBus. Both are very difficult to detect. They provide any potential hacker a way into your system. Once these programs are installed, any computer criminal can simply scan random IP addresses. When they find one that has a NetBus or Back Orifice connection at the other end, they can get into your system.

How do I protect myself from viruses?

Unfortunately, there is no way to get 100% protection from all past, present and future viruses. Security companies are constantly playing catch up, as computer criminals change their code in old viruses to make them undetectable, and invent new ways and code structures to get into your system. All you can do is your very best to protect your computer and your private information. Some ways to protect you include:

  • Always have updated anti-virus software actively running on your computer.
  • Before installing or running executable files (i.e.: joke.exe files or mini games) sent to you - even by your friends - ask yourself, "How badly do I want to see this? Is it worth it?"
  • Run virus scanning software on any files you are about install.
  • Update your operating system often with the latest updates concerning security or vulnerability issues.
  • Acquire back door scanning software that can detect and remove spyware and/or Trojans. Spyware is programming that is put in someone's computer to secretly gather information about the user and relay it to advertisers or other interested parties, including hackers.

What else should I be aware of?

One of the features in Windows 95, 98, NT, 2000, and XP is the ability to share your files with other computers. Whether these computers are on a local area network or on the Internet, you should always make sure you are very careful about file sharing. If you have enabled file sharing, you should always make sure to password protect your hard drives.

You should NEVER go away from your computers (also known as "afk," for "away from keyboard") while your character is in the game world. People that play in game rooms should be especially careful of this - even turning your back for a minute or dashing away while a "trusted friend" watches your game can have disastrous effects in some cases.

Additionally, if you play in game rooms, you should be especially careful of people that watch over your shoulder when you log into the game. It is possible that someone could watch you type your login name and password and then guess what it is. This could happen even if they don't see the actual characters you type.

Summary

How do I protect my computer system from being hacked or accessed by others without my permission?

  • Install a firewall on your system
  • Install a port monitor
  • Never accept files from people you do not know and trust
  • Avoid downloading programs from unfamiliar sources
  • Avoid downloading programs from sources that do not provide some way of reaching them should something with the download go wrong
  • Install a virus scanner; keep it active on your system and ensure you always have the most up-to-date virus scanning files
  • Run the virus scanner on files received prior to installing or executing them
  • Never give your account password (or any other passwords, for that matter) to anyone
  • Change your account password at least once every three months.
  • Use a complicated password structure (number, extended characters and mixed case) at least seven characters long
  • Use caution when giving out your instant message ID(s)
  • Use caution when accessing instant message and chat programs
  • Do not name your characters the same as your user name or login ID

Resources

How do I protect my computer system from being hacked or accessed by others without my permission?