Forum.Tip.It: Stay Safe: A Guide to Account Security - Forum.Tip.It

Jump to content

  • (2 Pages) +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Stay Safe: A Guide to Account Security How to have a secure account and protect against scammers

#1
User is offline   tripsis  [ View Display Name History ]

  • The Fuzz
  • View blog
  • View gallery
  • Group: Administrators
  • Posts: 19,744
  • Joined: 29-October 05
  • Location:England, UK
  • Status:P2P
  • RSN:Tripsis
Hey Tip.It'ers :)

Especially with the re-release of free trade, the Tip.It Staff has noticed a significant increase in scamming attempts. As such, we'd like to give you all a few reminders and tips to keep your account safe!

Scam E-Mails

    There have been a few scam e-mails being sent out lately. These e-mails will say that they are from Jagex and the content typically reads something like:

    Quote

    Dear RuneScape player,

    This is an automated email from Jagex Ltd., makers of RuneScape and FunOrb, sent because your account has been compromised by a third party hijacker.

    To verify your account, please click on this URL: <URL HERE>

    Many thanks,
    Jagex Ltd.


    E-mails such as this are a scam. If you hoover over the URL (which appears to be an official RuneScape URL) and look at the status bar on your browser, you will notice that the URL actually leads elsewhere. If you enter your account details on a website other than www.runescape.com, your account username and password will be stolen. That brings us to our next point...

RuneScape URLs

    Double - or even triple - check URLs that appear to lead to somewhere on RuneScape.com. It is very easy for people to disguise URLs to make them appear to lead to RuneScape.com, but actually lead elsewhere. To check a URL, put your cursor over it (do not click!!), and then look at the bottom of your browser at the Status Bar. The Status Bar will tell you where the URL truly leads.

    However, in order to stay 100% safe, do not use URLs provided by other users at all. If someone wants to direct you to a RuneScape Official Forum thread, do not click their link. Instead, manually go to the RuneScape Official Forum and input the Quick Find Code for the thread that you are attempting to view. If someone wants to direct you to a RuneScape News Post, manually go to RuneScape.com and view the news post rather than clicking a user link. It is always safest to do your own navigating rather than relying on URLs provided by other users!

    When logging into RuneScape.com via FireFox, look for the following:

    Posted Image

Other RuneScape Account Precautions

    There are several other ways to protect your RuneScape account and prevent yourself from getting scammed. Here are a few tips:

      Account Security
    • Choose a complicated password. Do not select a dictionary word or any personal information (name, birth date, etc.). Choose a password that contains both letters and numbers (ideally random ones). The longer the better!
    • Never give your password to anyone. Doing so is a violation of the RuneScape rules anyway (account sharing) ;)
    • Make sure your recovery questions are set and that the answers could not be guessed by anyone - not even friends.
    • If you have an e-mail address registered to your account, ensure that your e-mail account is well protected. Choose a complicated password, tough recoveries and use an e-mail that is not shared with anybody. Do not use this e-mail for any other websites (including fan sites).
    • Always set a bank PIN and deposit all of your valuables into your bank each time before logging out.
    • Do not visit any suspicious websites and run virus/malware scans regularly. An important part of keeping your RuneScape account safe is ensuring that your computer is safe and free of keyloggers and other viruses.

      Protect Against Item Scamming/Luring
    • Now that we have free trade, unbalanced trades are permitted. Ensure that you are always paying the correct value for an item. Check the trade window to see the price guides Jagex has put up. Ensure that you are buying an item for a similar amount of gold pieces than the recommended trade value. If you are paying outside of that range, ensure that you have used multiple reliable sources to confirm that the price you are paying is fair.
    • Know when you are entering the wilderness! Historically, people would lure other players into the wilderness in order to kill them and take their items. There is a wilderness wall that separates the wilderness from the normal world. When you cross this wall, other players will be able to attack you!
    • Armour trimming does not exist. Other users cannot trim your armour for you.

When In Doubt, Ask

    If you are ever unsure about whether something is legitimate or not, always ask. Be sure to ask someone that you trust, or best of all, a Tip.It Staff member or Jagex Moderator. The Tip.It Staff is here to help all of you and we care very much about your safety and account security. If you ever have any questions or doubts, you may send any of us a private message. Click here to view the Tip.It Staff List.


Spread the Word

    Help your friends and peers by spreading the word! You can add one of these images to your forum signature:

    Posted Image

    [url=http://forum.tip.it/topic/286405-stay-safe-a-guide-to-account-security/][img]http://tip.it/runescape/images/crew/safety-forum.jpg[/img][/url]


    Posted Image

    [url=http://forum.tip.it/topic/286405-stay-safe-a-guide-to-account-security/][img]http://tip.it/runescape/images/crew/safety-forum.jpg[/img][/url]


    Posted Image

    [url=http://forum.tip.it/topic/286405-stay-safe-a-guide-to-account-security/][img]http://tip.it/runescape/images/crew/safety-forum.jpg[/img][/url]

To find out more information on account security you can read Jagex's RuneScape Wiki article.

Have fun and stay safe! :)

- Tip.It Staff
Posted Image

Posted Image
- 99 fletching | 99 thieving | 99 construction | 99 herblore | 99 smithing -
- 99 runecrafting - 99 prayer - 125 combat - 95 farming -

- Blog - DeviantART - Relationship Advice - Book Reviews & Blog

#2
User is offline   foursideking  [ View Display Name History ]

  • Varrock Guard
  • Group: Members
  • Posts: 1,350
  • Joined: 26-March 09
  • Location:alternating between dimensions
  • Status:Semi-Retired
  • RSN:magermanmye
  • RSN2:bowmastermye
  • Clan:Aether Source
A tip to all p2pers: turn accept aid off to prevent scammers 'accidentally' group tele'ing you to wildy....
[img]<a href="http://www.danasoft.com"><img src="http://www.danasoft.com/sig/FoursideKing.jpg" border="0"></a><div style="font-family:arial,sans-serif;font-size:11px;"><p>Sign by Danasoft - <a href="http://www.danasoft.com">For Backgrounds and Layouts</a></p></div>[/img]

#3
User is offline   Sy_Accursed  [ View Display Name History ]

  • Troll General
  • View blog
  • Group: Members
  • Posts: 11,596
  • Joined: 22-December 04
  • Location:Nottingham
  • Status:P2P
  • RSN:Sy Accursed
  • RSN2:Sy Blessed
  • Clan:Legacy of Honour

View Postfoursideking, on 03 February 2011 - 05:05 PM, said:

A tip to all p2pers: turn accept aid off to prevent scammers 'accidentally' group tele'ing you to wildy....


Last I checked you got a confrimation screen to accept or reject all group teles.

However it is a good ideam to have it turned off anyway as an older, but popular scam, that might return is spamming such teles on u at barrows etc. so that u die as u have to deal with the notification.
Posted Image
Posted Image

#4
User is offline   TaylorSwift  [ View Display Name History ]

  • Rat Meat
  • Group: Members
  • Posts: 27
  • Joined: 04-February 11
  • Status:P2P
  • RSN:Taylor Swift
Passwords on Runescape aren't case sensitive. So don't bother mixing upper and lower case.

If you don't believe me, then try logging in with Caps Lock on ;)
Posted Image

#5
User is offline   tripsis  [ View Display Name History ]

  • The Fuzz
  • View blog
  • View gallery
  • Group: Administrators
  • Posts: 19,744
  • Joined: 29-October 05
  • Location:England, UK
  • Status:P2P
  • RSN:Tripsis

View PostTaylorSwift, on 04 February 2011 - 10:34 AM, said:

Passwords on Runescape aren't case sensitive. So don't bother mixing upper and lower case.

If you don't believe me, then try logging in with Caps Lock on ;)

Looks like you're right :lol: Thanks, I'll change that!
Posted Image

Posted Image
- 99 fletching | 99 thieving | 99 construction | 99 herblore | 99 smithing -
- 99 runecrafting - 99 prayer - 125 combat - 95 farming -

- Blog - DeviantART - Relationship Advice - Book Reviews & Blog

#6
User is offline   Jaffy1  [ View Display Name History ]

  • Ice Giant Melter
  • Group: Members
  • Posts: 3,556
  • Joined: 07-May 06
  • Location:The Netherlands
  • Status:P2P
  • RSN:Ms Julie

View Postfoursideking, on 03 February 2011 - 05:05 PM, said:

A tip to all p2pers: turn accept aid off to prevent scammers 'accidentally' group tele'ing you to wildy....

I would not consider having it on as dangerous.
Always have mine on as I do group farm runs with friends a lot, and since you do get the confirmation screen before moving it really isn't like *POOF* now you're in the wilderness.
Posted Image
Posted Image


Posted Image Tip.It Website Crew Leader
Quotes

#7
User is online   Assume Nothing  [ View Display Name History ]

  • Ice Giant Melter
  • Group: Members
  • Posts: 4,011
  • Joined: 23-November 08
  • Location:Places.
  • Status:Semi-Retired
Golden rules of thumb:

EDIT - I thought this is particularly important, so I'd say it outside the hide tag.

Change your password NOW! This applies especially to anyone reading this has botted in the past, because malicious code was used in one of the more common bot sites, and they have only scammed 10% of their 'list' of players.

These 'hackers' are still going through a 'list' of 10 thousand players at random, thus it is important to change your password to keep your account secure.

Oh, and they tracked RuneScape bank pin's too, so if anyone reading this has botted before, change your bank pin, and delete any .ini files you have downloaded

Wall of text


#8
User is offline   TaylorSwift  [ View Display Name History ]

  • Rat Meat
  • Group: Members
  • Posts: 27
  • Joined: 04-February 11
  • Status:P2P
  • RSN:Taylor Swift
The list of players only includes botting players though, so if you didn't bot, no need to change your password :)
And if you did bot, then you're going to get a big rollback or a ban, soooo.... gf :P
Posted Image

#9
User is offline   Rainy_Day  [ View Display Name History ]

  • Better than Obfuscator
  • View gallery
  • Group: Administrators
  • Posts: 8,491
  • Joined: 27-January 07
  • Location:Somewhere in Europe
  • Status:P2P
Just to say, a big thanks to people reporting the scam threads/warning others of the fake links. Some people are in too much of a rush to pay attention to the fake link, and as such, fall victim! We're updating our censors/banlists daily to keep up with the current influx.
Posted Image

#10
User is offline   FallonDawn  [ View Display Name History ]

  • Chicken Feather
  • Group: Members
  • Posts: 2
  • Joined: 16-February 11
  • Status:P2P
  • RSN:fallendawn1
I've seen a few so called "players" outside RS who have posted links to RS Forum pages claiming that it was an important announcement. The green security bar that you see in the URL when you log into your account will be missing (the hackers conveniently recreate the complete page, plus the warning.) I've seen a few people who entered their account info, and got hacked as a consequence. I'm seriously starting to wonder if bringing back Free Trade was such a great idea. The number of botters have increased dramatically; before the change I might see one or two in a game session, but now its rare to see anything less than 6 to 8. Scam attempts have skyrocketed. Hacking attempts are also getting out of hand.

I know a lot of people wanted Free Trade back, but surely Jagex could have planned this better. There seems to be absolutely no checks in place to stop the onslaught.
I am the Dark Horizon.
I am the Darkness before the Dawn.

#11
User is offline   Rohanlord  [ View Display Name History ]

  • Spider Egg
  • Group: Members
  • Posts: 75
  • Joined: 30-August 10
  • Status:Hide
I just fell for the dumbest scam ever. Now my password is changed and I've applied for recovery. Thankfully there's a pin on my bank (what happens if it is continuously guessed wrong?) and it's not like they can reduce my skills...or CAN they :o

But seriously, always make sure your on the Runescape site when you type in your account details and not [site name removed]. I can't believe I actually though I was on the Runescape forums...

This post has been edited by Gandorf61: 17 February 2011 - 12:08 AM
Reason for edit: Removed site name as all it does is advertises it ;)



Notable solo drops: x3 Bandos boots, x2 Dragonic Visage, x2 Bandos Tassets, x1 Bandos Hilt, x1 Bandos Chestplate

#12
User is offline   jrkerr  [ View Display Name History ]

  • Rat Meat
  • Group: Members
  • Posts: 37
  • Joined: 23-February 11
  • Location:texas
  • Status:P2P
  • Clan:i will not join a clan
I ran my own website and forum for a bit.

I know one of my primitive tools would give me a list of all IPs that visitied/used my site.

Tip it does not seem heavily vested in triumvirate, clan, or whatever pursuits... and I am given comfort to have seen that the first few editorials on wildy/free trade said they voted no, but...

what measures are there to dump IP logs from offsite clans trying nuke, hash, steal, or w/e the IP log for this site?
wouldn't they get a list of IPs to ping storm to knock a whole bunch of players off a world if tip it tried a nex event or clan wars challenge?

I have some faith in you guys, but please tell me you shred some of that conspicuous data after a month or so... or./.. y'know... don't tell me....
and then just like do what it is you do for security anyway without informing malicious stalkers.

cheers.

#13
User is offline   Sy_Accursed  [ View Display Name History ]

  • Troll General
  • View blog
  • Group: Members
  • Posts: 11,596
  • Joined: 22-December 04
  • Location:Nottingham
  • Status:P2P
  • RSN:Sy Accursed
  • RSN2:Sy Blessed
  • Clan:Legacy of Honour

View Postjrkerr, on 23 February 2011 - 05:44 PM, said:

I ran my own website and forum for a bit.

I know one of my primitive tools would give me a list of all IPs that visitied/used my site.

Tip it does not seem heavily vested in triumvirate, clan, or whatever pursuits... and I am given comfort to have seen that the first few editorials on wildy/free trade said they voted no, but...

what measures are there to dump IP logs from offsite clans trying nuke, hash, steal, or w/e the IP log for this site?
wouldn't they get a list of IPs to ping storm to knock a whole bunch of players off a world if tip it tried a nex event or clan wars challenge?

I have some faith in you guys, but please tell me you shred some of that conspicuous data after a month or so... or./.. y'know... don't tell me....
and then just like do what it is you do for security anyway without informing malicious stalkers.

cheers.



Tip.it is secure enough to not let people get that data so dumping it isn't an issue.

Besides if someone really wants to to ddos attack you they can easily do so without forum ip logs.
Images can easily log ips that have viewed them, especially stat signatures that are a form of script anyway.
Prime example being runetracks does it (though they don't let you see the full ip obv); from just leaving a rune track sig on my tip.it sig for a few hours to get the 10 unique ip hits required for runetrack to track you I got 231 unique ip hits.
Posted Image
Posted Image

#14
User is offline   tripsis  [ View Display Name History ]

  • The Fuzz
  • View blog
  • View gallery
  • Group: Administrators
  • Posts: 19,744
  • Joined: 29-October 05
  • Location:England, UK
  • Status:P2P
  • RSN:Tripsis
Just so you guys know, I have confirmed with Jagex that they never send e-mails about bans/mutes/offenses. They only send e-mails in relation to account recovery requests and the occasional RuneScape newsletter. If they ever decide to start sending e-mails in the future for bans/mutes/offenses, they will never include any links. So if you receive any e-mails in regards to bans/mutes/offenses, you can know right off the bat that it is a scam and should be deleted immediately. Jagex will always contact you via your message center.
Posted Image

Posted Image
- 99 fletching | 99 thieving | 99 construction | 99 herblore | 99 smithing -
- 99 runecrafting - 99 prayer - 125 combat - 95 farming -

- Blog - DeviantART - Relationship Advice - Book Reviews & Blog

#15
User is offline   Speedyshel  [ View Display Name History ]

  • Retired Crew
  • Group: Members
  • Posts: 1,190
  • Joined: 28-June 08
  • Status:None
  • RSN:Speedyshel
And just for what it's worth, it's minor but might make a difference to someone in the future.
Like the old scam of trimming armour, the idea of players doubling money is a scam. Players want you to give them some cash then accept the trade, then they'll return a second trade offer with the doubled amount. Don't fall for it!
Like I said, small but may be a big deal to someone.
Retired Crew Member
Website Updates and Corrections

Posted Image

*..It is better to be hated for who you are than loved for who you're not..*

#16
User is offline   the_korny  [ View Display Name History ]

  • Bear Fur
  • Group: Members
  • Posts: 257
  • Joined: 22-February 07
  • Status:Hide
  • RSN:the korny
MEGA Props for posting this! Hope it helps people!
I've never seen Sixth Sense nor Inception nor many other popular movies and I intend to keep it that way.

#17
User is offline   dartagnan  [ View Display Name History ]

  • Chicken Feather
  • Group: Members
  • Posts: 5
  • Joined: 16-April 10
  • Status:Hide
This is pretty interesting you post this, as I just "JUST" received an e-mail from someone claiming to be Jagex. I knew it was fake immediately because they sent it to my tip.it e-mail i registered here with. .. I run my own domain so i use random e-mail address on every site i visit .. easy way to track where the e-mail was stolen from if i ever start getting spammed.

So ... for those that have their e-mail address registered here and on your rune account .. triple check someone is obviously obtaining their new e-mail list from here.


oh and ... My contact info is set to "Private" Soooooo forum owners .. Any idea's on which one of your staff is trying to steal accounts ?

#18
User is offline   tripsis  [ View Display Name History ]

  • The Fuzz
  • View blog
  • View gallery
  • Group: Administrators
  • Posts: 19,744
  • Joined: 29-October 05
  • Location:England, UK
  • Status:P2P
  • RSN:Tripsis

View Postdartagnan, on 20 February 2012 - 09:44 PM, said:

oh and ... My contact info is set to "Private" Soooooo forum owners .. Any idea's on which one of your staff is trying to steal accounts ?

None of our staff members are trying to steal/recover accounts. However, our database was compromised in October and that's likely how this person received your e-mail. You can read this news post for more information.
Posted Image

Posted Image
- 99 fletching | 99 thieving | 99 construction | 99 herblore | 99 smithing -
- 99 runecrafting - 99 prayer - 125 combat - 95 farming -

- Blog - DeviantART - Relationship Advice - Book Reviews & Blog

#19
User is offline   Den  [ View Display Name History ]

  • Movie Director
  • Group: Members
  • Posts: 7,792
  • Joined: 03-August 08
  • Location:Runescape
  • Status:P2P
  • RSN:Rainy

View Posttripsis, on 20 February 2012 - 10:43 PM, said:

View Postdartagnan, on 20 February 2012 - 09:44 PM, said:

oh and ... My contact info is set to "Private" Soooooo forum owners .. Any idea's on which one of your staff is trying to steal accounts ?

None of our staff members are trying to steal/recover accounts. However, our database was compromised in October and that's likely how this person received your e-mail. You can read this news post for more information.


It's possible to have your e-mail visible in your tip.it profile as well iirc.

#20
User is offline   tripsis  [ View Display Name History ]

  • The Fuzz
  • View blog
  • View gallery
  • Group: Administrators
  • Posts: 19,744
  • Joined: 29-October 05
  • Location:England, UK
  • Status:P2P
  • RSN:Tripsis

View PostDen, on 21 February 2012 - 02:25 AM, said:

View Posttripsis, on 20 February 2012 - 10:43 PM, said:

View Postdartagnan, on 20 February 2012 - 09:44 PM, said:

oh and ... My contact info is set to "Private" Soooooo forum owners .. Any idea's on which one of your staff is trying to steal accounts ?

None of our staff members are trying to steal/recover accounts. However, our database was compromised in October and that's likely how this person received your e-mail. You can read this news post for more information.


It's possible to have your e-mail visible in your tip.it profile as well iirc.

Yes it is :) dartagnan said his was private though so it couldn't have been gotten off his profile.
Posted Image

Posted Image
- 99 fletching | 99 thieving | 99 construction | 99 herblore | 99 smithing -
- 99 runecrafting - 99 prayer - 125 combat - 95 farming -

- Blog - DeviantART - Relationship Advice - Book Reviews & Blog

Share this topic:


  • (2 Pages) +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users