<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: CardBoosterShop Bot (CBSBot) for Magic Online (mtgo) has an account-stealing backdoor!</title>
	<atom:link href="http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article</link>
	<description>How can a crappy site with boring games waste more space?</description>
	<lastBuildDate>Sun, 18 Jul 2010 22:32:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nerdmaster</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-4420</link>
		<dc:creator>Nerdmaster</dc:creator>
		<pubDate>Fri, 13 Feb 2009 19:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-4420</guid>
		<description>&lt;p&gt;I&#039;m betting somebody could do this pretty easily with a small amount of research.&lt;/p&gt;

&lt;p&gt;However, that will no longer allow one to run the bot - it now stores all data remotely, so if you don&#039;t allow it to contact the CBS site, you effectively have no bot.  I keep meaning to write a &quot;mock&quot; site so that a little hackery (/etc/hosts kind of thing, but for windows) could allow me to run a &quot;safe&quot; bot, but the work involved just isn&#039;t worth it....&lt;/p&gt;

&lt;p&gt;And that&#039;s not even the full problem - it could be that the software &lt;strong&gt;still&lt;/strong&gt; has password-stealing mechanisms where the author types in a special command and your bot spits out the password in a trade window.  I don&#039;t know if this is the case, but it&#039;s not something I can rule out easily these days.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I&#8217;m betting somebody could do this pretty easily with a small amount of research.</p>

<p>However, that will no longer allow one to run the bot &#8211; it now stores all data remotely, so if you don&#8217;t allow it to contact the CBS site, you effectively have no bot.  I keep meaning to write a &#8220;mock&#8221; site so that a little hackery (/etc/hosts kind of thing, but for windows) could allow me to run a &#8220;safe&#8221; bot, but the work involved just isn&#8217;t worth it&#8230;.</p>

<p>And that&#8217;s not even the full problem &#8211; it could be that the software <strong>still</strong> has password-stealing mechanisms where the author types in a special command and your bot spits out the password in a trade window.  I don&#8217;t know if this is the case, but it&#8217;s not something I can rule out easily these days.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Marius</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-4192</link>
		<dc:creator>Marius</dc:creator>
		<pubDate>Thu, 05 Feb 2009 04:35:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-4192</guid>
		<description>&lt;p&gt;Ok im not an expert in any field of some sorts, but i was reading this and it got me thinking isnt it possible to run a program that blocks ALL internett connections except from the required to wizards, i bet they have spesific adresses like login.mtgo.wizards1.com for example and such? and just block everything apart from the ones your really need?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ok im not an expert in any field of some sorts, but i was reading this and it got me thinking isnt it possible to run a program that blocks ALL internett connections except from the required to wizards, i bet they have spesific adresses like login.mtgo.wizards1.com for example and such? and just block everything apart from the ones your really need?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Richaal</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-2514</link>
		<dc:creator>Richaal</dc:creator>
		<pubDate>Tue, 09 Dec 2008 00:36:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-2514</guid>
		<description>&lt;p&gt;Hi, wow i started playing today since mtgo v2 and i see this whole mess with cbs. I remember the good old yatbot that used to be good. I was gonna use cbs but i think i wont know. Im gonna start developing a yatbot like bot that trades cards for cards and cards for tix ive done bots for mmorpgs and for mtgo v2 so im expecting a beta version 2 months from now well xmas is near so maybe earlier lets see if i can get most of the job done during these vacations. I warn you guys its gonna be a basic bot, dont expect anything better than trading cards for cards or tix untill 2-4months after the realease of the basic bot. Only issue is you might need a dual-core quad-core to run more than one bot.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi, wow i started playing today since mtgo v2 and i see this whole mess with cbs. I remember the good old yatbot that used to be good. I was gonna use cbs but i think i wont know. Im gonna start developing a yatbot like bot that trades cards for cards and cards for tix ive done bots for mmorpgs and for mtgo v2 so im expecting a beta version 2 months from now well xmas is near so maybe earlier lets see if i can get most of the job done during these vacations. I warn you guys its gonna be a basic bot, dont expect anything better than trading cards for cards or tix untill 2-4months after the realease of the basic bot. Only issue is you might need a dual-core quad-core to run more than one bot.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Nerdmaster</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-2166</link>
		<dc:creator>Nerdmaster</dc:creator>
		<pubDate>Mon, 01 Dec 2008 07:05:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-2166</guid>
		<description>&lt;p&gt;Yeah, I had some other tips, but it appears the latest obfuscator is just insane, so none of my contacts has had much luck really checking out the latest bot.&lt;/p&gt;

&lt;p&gt;I continue to be botless, but better that than having my computer compromised, I suppose.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Yeah, I had some other tips, but it appears the latest obfuscator is just insane, so none of my contacts has had much luck really checking out the latest bot.</p>

<p>I continue to be botless, but better that than having my computer compromised, I suppose.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Formerbotuser</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-1670</link>
		<dc:creator>Formerbotuser</dc:creator>
		<pubDate>Thu, 20 Nov 2008 17:50:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-1670</guid>
		<description>&lt;p&gt;Hi, After the problems posted on the gleemax forum about this bot i went looking into Reverse Engineering the bot cause i want to know what the maker was able to see (paypal pass maybe?!?!). But since i&#039;m not exactly a computer genius it didnt work out for me although i found a program that should give you the opportunity to take a look into the code (coded with autoIt3 i believe).
On this forum: http://defcon5.biz/phpBB3/viewtopic.php?f=5&amp;t=234&amp;st=0&amp;sk=t&amp;sd=a&amp;start=50 
you can read about how to get the code.. It doesnt seem to work for me atm, but ill try to contact the programmer of myAut2Exe if he could help me out here..&lt;/p&gt;

&lt;p&gt;Ill keep you posted...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi, After the problems posted on the gleemax forum about this bot i went looking into Reverse Engineering the bot cause i want to know what the maker was able to see (paypal pass maybe?!?!). But since i&#8217;m not exactly a computer genius it didnt work out for me although i found a program that should give you the opportunity to take a look into the code (coded with autoIt3 i believe).
On this forum: <a href="http://defcon5.biz/phpBB3/viewtopic.php?f=5&amp;t=234&amp;st=0&amp;sk=t&amp;sd=a&amp;start=50" rel="nofollow">http://defcon5.biz/phpBB3/viewtopic.php?f=5&amp;t=234&amp;st=0&amp;sk=t&amp;sd=a&amp;start=50</a> 
you can read about how to get the code.. It doesnt seem to work for me atm, but ill try to contact the programmer of myAut2Exe if he could help me out here..</p>

<p>Ill keep you posted&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Nerdmaster</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-1201</link>
		<dc:creator>Nerdmaster</dc:creator>
		<pubDate>Wed, 29 Oct 2008 03:17:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-1201</guid>
		<description>&lt;p&gt;No idea....  I&#039;ve found one that actually looks like the ripped-off version of CBS the author was talking about.  So if anybody finds a legit bot out there, I&#039;d LOVE to hear about it!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>No idea&#8230;.  I&#8217;ve found one that actually looks like the ripped-off version of CBS the author was talking about.  So if anybody finds a legit bot out there, I&#8217;d LOVE to hear about it!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: botwanted</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-1151</link>
		<dc:creator>botwanted</dc:creator>
		<pubDate>Sat, 25 Oct 2008 07:16:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-1151</guid>
		<description>&lt;p&gt;what&#039;s a safe bot to use?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>what&#8217;s a safe bot to use?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Newbunkle</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-1017</link>
		<dc:creator>Newbunkle</dc:creator>
		<pubDate>Tue, 14 Oct 2008 15:38:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-1017</guid>
		<description>&lt;p&gt;As I posted over on the Magic forums, this is both terrifying and awesome. I haven&#039;t been so interested in a scandal like this since Limbo of the Lost. You&#039;re a genius for figuring this out, well done.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>As I posted over on the Magic forums, this is both terrifying and awesome. I haven&#8217;t been so interested in a scandal like this since Limbo of the Lost. You&#8217;re a genius for figuring this out, well done.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Nerdmaster</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-995</link>
		<dc:creator>Nerdmaster</dc:creator>
		<pubDate>Sun, 12 Oct 2008 20:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-995</guid>
		<description>&lt;p&gt;Andrew, rasguy, I actually considered that at first, but after some investigating, that string is exactly the same no matter what user or password you type into the bot.  I can&#039;t figure out why the author did that, other than perhaps to claim that it&#039;s always been like that or something.  Or maybe to confuse me into trying to decrypt it.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Andrew, rasguy, I actually considered that at first, but after some investigating, that string is exactly the same no matter what user or password you type into the bot.  I can&#8217;t figure out why the author did that, other than perhaps to claim that it&#8217;s always been like that or something.  Or maybe to confuse me into trying to decrypt it.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: rasguy</title>
		<link>http://blog.nerdbucket.com/cardboostershop-bot-cbsbot-for-magic-online-mtgo-has-an-account-stealing-backdoor/article/comment-page-1#comment-991</link>
		<dc:creator>rasguy</dc:creator>
		<pubDate>Sun, 12 Oct 2008 14:01:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nerdbucket.com/?p=82#comment-991</guid>
		<description>&lt;p&gt;I don&#039;t think that is a dummy string.  I believe it&#039;s the same information encrypted.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think that is a dummy string.  I believe it&#8217;s the same information encrypted.</p>]]></content:encoded>
	</item>
</channel>
</rss>
