Jump to content

Recommended Posts

Posted

Hi everyone,

This is not an advertisement for my server.

My Facebook group with 1,300 real players was hacked. I was the only owner of the group, and I don’t understand how someone could change admin rights and remove me from it.

All my accounts have two-factor authentication (2FA), so there’s no way anyone could have accessed my account to give admin rights to another profile.

I contacted Facebook for help and even paid $20 for faster support from Meta. They basically ignored me and said they couldn’t help or make any decisions regarding this situation.

I found some information about the person who took over the group – it seems to be an admin of L2CALIGULA (FLOYD) – and it looks like my group isn’t the only one affected.

 

https://www.facebook.com/MdsFael/posts/pfbid02LYPDAaxmjECuKY6g1xhMsnmixUH3x1asAVt2RtVKjV8yvegQ9erVHeWAdrJyjonal

 

As it stands, the group still exists on Facebook and all the information is visible, but I have no control over it anymore.

 

l2mid group: https://www.facebook.com/groups/l2official

 

Can anyone explain how this is even possible and how I can prevent it in the future?

Regards!

 

 

Posted
11 minutes ago, Splicho said:

Of course someone can access your account. All it needs is just a session.

Sounds to me like you were info stealed.

 

https://chatgpt.com/share/68a50e59-0708-8012-b63c-98fe3fa87f88

 

Lets assume someone has access to my account..
I havent seen any email notifications about it.. any sms /msgs, and there is no information in the activity logs on FB logins from other IPS or devices. It all seems very strange.

Ive reached out to FB regarding the restore form and the hacked group. Lets see what they say. 🙂

Posted (edited)
2 minutes ago, SkyLord said:

 

Lets assume someone has access to my account..
I havent seen any email notifications about it.. any sms /msgs, and there is no information in the activity logs on FB logins from other IPS or devices. It all seems very strange.

Ive reached out to FB regarding the restore form and the hacked group. Lets see what they say. 🙂

Yeah sounds like session hijacking imho. Strange none the less. Did you open any suspecious websites where u needed to facebook login in the last 24-48h or opened weird .exe's ? or anything similar?

 

Meta support is a joke.

Edited by Splicho
Posted

Hello, I don't think someone hacked your FB account but gained remote access to your PC. Did you join any l2 server lately to check something etc? Running any Remote desktop service? Check windows logs.

Posted
11 minutes ago, Splicho said:

Yeah sounds like session hijacking imho. Strange none the less. Did you open any suspecious websites where u needed to facebook login in the last 24-48h or opened weird .exe's ? or anything similar?

 

Meta support is a joke.

There’s no way that could have happened with me. 🙂

8 minutes ago, FixerRay said:

Hello, I don't think someone hacked your FB account but gained remote access to your PC. Did you join any l2 server lately to check something etc? Running any Remote desktop service? Check windows logs.

I’m well protected,.. Facebook isn’t 🙂

I just spoke with Facebook support. Honestly.. i was surprised at how quickly they reacted to my report. Woman from India contacted me and told me to install a program so she could get into my computer. I was like, “Are you kidding me?”

She was even laughing on the phone and said, “No problem”
😄

 

Facebook reviewed the case and told me they’ll give me my group back in a few days. So, good luck to that guy from Brazil or wherever he’s from.

Thanks!

 

gkGHA2w.png

 

tNQQvTk.png

 

Posted
2 hours ago, SkyLord said:

There’s no way that could have happened with me. 🙂

I’m well protected,.. Facebook isn’t 🙂

I just spoke with Facebook support. Honestly.. i was surprised at how quickly they reacted to my report. Woman from India contacted me and told me to install a program so she could get into my computer. I was like, “Are you kidding me?”

She was even laughing on the phone and said, “No problem”
😄

 

Facebook reviewed the case and told me they’ll give me my group back in a few days. So, good luck to that guy from Brazil or wherever he’s from.

Thanks!

 

gkGHA2w.png

 

tNQQvTk.png

 

Run a program lol...

 

Well, well done! Happy to hear you get your group back 🙂

Posted
13 hours ago, Trance said:

Using your browser session, they don’t need any login credentials.. Facebook will recognize that session as you.

If your pc and browser are clean (no malware, no extensions, nobody else has access)

then its not possible for anyone else to use your FB session. 

Posted
2 hours ago, SkyLord said:

If your pc and browser are clean (no malware, no extensions, nobody else has access)

then its not possible for anyone else to use your FB session. 

It is still possible. If someone manages to steal your active Facebook session cookie (somehow), Facebook will recognize them as you and they can bypass both your password and 2FA. This is called session hijacking

Posted (edited)
8 hours ago, melron said:

It is still possible. If someone manages to steal your active Facebook session cookie (somehow), Facebook will recognize them as you and they can bypass both your password and 2FA. This is called session hijacking

changing password or settings on account/groups still needs re-authorization so no.

 

imo it was either facebook exploit which is unlike or network-level attack, why i tell u this? because i once had similar issue with my tiktok account, a guy logged into my account without using a sms code which was the only way to enter my account, and the funny part was that i didnt even receive a sms xD now u may say that this is what session hijack is but i saw a completely different device in my devices list which indicates that it wasnt a hijack. 

Edited by BruT
Posted (edited)
1 hour ago, BruT said:

changing password or settings on account/groups still needs re-authorization so no.

 

imo it was either facebook exploit which is unlike or network-level attack, why i tell u this? because i once had similar issue with my tiktok account, a guy logged into my account without using a sms code which was the only way to enter my account, and the funny part was that i didnt even receive a sms xD

Session Hijacking bypasses that.
 

 

Edited by Splicho
Posted
11 minutes ago, Splicho said:

Session Hijacking bypasses that.
 

 

bypassing what exactly? passwords? or the logging, if u talk about my situation i should see the same device as mine in my devices not different, because sessions are bind to devices.

Posted
6 hours ago, BruT said:

bypassing what exactly? passwords? or the logging, if u talk about my situation i should see the same device as mine in my devices not different, because sessions are bind to devices.

Exactly, if somebody hijacks ur sessions, then u wont see a new device in your "Devices List".

And with that hijacked session you are able to change whatever you want unless you have 2FA enabled. And I believe changing a group owner doesn't trigger 2FA.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Hi everyone, A while ago, I needed to extract some L2 textures and found that acmi's L2Tool was a good way to do it. There might be other methods out there but I'm not aware of them, so I decided to fork this project and improve it to suit my needs. I built this using BellSoft Liberica JDK 17. Since modern Java versions no longer include JavaFX by default, I've made the app handle it automatically. You don't need any manual setup—just use the  run.bat  and it will automatically extract the required JavaFX modules on the first run. Key features of this fork: UI Overhaul: I've tweaked the interface to give it a cleaner look with Dark Mode and more detailed metadata for each texture. Export Formats: You can now extract textures in WEBP, PNG, and DDS. Individual or Batch Export: Flexible options to export a single selected texture or the entire package at once.     I'm leaving the link here in case it's useful to anyone!   Installation and Execution:     Clone the repository:   https://github.com/Ak4n1/l2tool cd l2tool          2.Build the project:   ./gradlew build              3. Run the application:         ./run.bat      Or simply double-click on run.bat.    
    • Wtb full account or items on l2 warland 
    • https://discord.gg/k53SZ4DM5z   Interlude Client L2Old Pride is a L2 Pride Interlude Based All functional skills (Not archer/mage server)   L2Old Pride Helper (Works like Woundrous Cubic) https://imgur.com/iYqmHQY Farm Zones: Cave of Trials and Elven Ruins (Chaotic) Olympiads: Every 15 days Various Cosmetic Items https://imgur.com/uoeU6Jw https://imgur.com/oCS2Zed PvP Zone: Gludin Village (No-Parties, Disguised) More than 100 new Skills https://imgur.com/6RaPsQV Max Level: 90 https://imgur.com/z4QVJKZ Gaining Xp by PVP https://imgur.com/LRqI31T Purchasable S-grade items +10 or +20 with random chance to enchant +5 Purchasable Custom Items Depends on Tier Mysterious Merchants https://imgur.com/2ZwWyPH Auto Enchant Via PvPing (with low chance) Custom Raid Bosses Siege Every Weekend (Aden, Rune, Giran) Autofarm / Drop Tracker https://imgur.com/Vz3rha6   RATES: • Start Level 80 • Max level 90  • EXP: 5000x • SP: 5000x • ADENA 6000x   ENCHANT: • Maximum enchant S Grade Items: +35. • Maximum enchant Unique/Epic Items: +25. • Maximum enchant Legendary Items: +18. • Maximum enchant Relic Items: +14. •Descriptions for rate at scrolls!   EVENTS: • TEAMS vs TEAMS • CAPTURE THE FLAG • DOMINATION • DEATH MATCH • DICE OF DEATH • CHAOTIC ZONE   OTHERS: Assistance system in pvps. Where support classes are enabled to receive pvp with a low chance, for supporting a party member during pvp. •  /sit to regen HP/MP/CP • Custom Shots Glows https://imgur.com/FLK0DmR • Achievements System • Daily Tasks System • Monthly Tasks System   CUSTOM ARMORS SETS Dread Armor/Titanium Armor Pride Armor Rykros Armor https://imgur.com/SPxoQp1   CUSTOM WEAPONS SETS Unique Weapons Pride Weapons Legendary Weapons Relic Weapons https://imgur.com/kOHNXhS   CUSTOM ACCESSORIES Standard Superior Legendary https://imgur.com/zPqNiiX   CUSTOM JEWELS/TATTOO Legendary Nightmarish https://imgur.com/gcqS28P There are many more features that you will only understand by playing and following. Beta testing server is currently open. Follow us on our discord and join our server to test it.
    • You shouldn't use rev 382, not sure why everyone keep using that.   I don't make changesets for fun, I don't make new revisions for nothing.   Follow the revisions.
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock