PSA: Here's where the web store is (but don't take my word for it)

DNA3000DNA3000 Member, Guardian Posts: 19,841 Guardian
Now that MCOC has its own brand new web store, I'm guessing a lot of people are going to be looking for it very soon, when the Summer sales for 2023 start up. Here is where it is located:

https://store.playcontestofchampions.com

HOWEVER. DO NOT TRUST ME OR ANYONE ELSE TO GIVE YOU THIS LINK DIRECTLY

It is far too easy to set up a fake store site then attempt to lure players to it. Since you have to log into it, they can harvest your login credentials and then do all sorts of nasty things. If you go far enough, they can also harvest your payment information. That's worse.

So what should you do? Here's DNA's four part safety procedure for using the web stores for players who are concerned about online safety (which should be everyone).

One: Do not click on links to the store posted in public areas. No No No No No No No. It doesn't matter if you think you recognize the link.

For those unwilling to take this advice, here's the link to the store again: https://store.playcontestofchampions.com
(note: the link is a safe demonstration of the principle)

Do not trust links from untrusted sources. They are a convenience, but when safety matters they are also a hazard.

Two: Do link to the store from a known official site.

The official game site is playcontestofchampions.com. The site name is the same as the forum domain name, without the "forums." In the upper right hand corner is a site menu, and that site menu has a link to the web store:



Alternatively, type the name in yourself. The name of the site is the same domain name of these forums, just replace "forums." with "store." And if you do, double check for typos. Triple check for typos. One way fraudsters try to capture victims is to set up nearby domain names. If you accidentally type playcontestofchamps.com instead of playcontestofchampions.com and you just assume you typed the right thing because "it worked" you might have accidentally landed on a fraudulent site instead.

Three: Verify that you are connected to the right site name with SSL.

In other words, you should be going to https:// and not http://. Also, verify that when you do, the SSL certificate for the site is valid. That's the little lock icon that most browsers have.



If you are not connected SSL or that lock isn't present, do not use the site. And if you aren't sure if the lock is locked or not, every browser has their own version of clicking on the lock and double checking:



You want to drill into that and see this:



Secure connection, valid certificate. Anyone can make up a fake site. It is a lot harder to forge valid digital certificates that will be valid for the correct domain names.

None of this will help if an attacker hacks the actual store. There I can't offer a four part easy way to keep yourself secure. But don't make yourself an easy target. It isn't easy to hack online stores. It is really easy to just ask you for your passwords and payment info and have you hand it over. Don't do that.

And finally, Four: use credit cards whenever possible on the web store.

The web store offers payment options from (believe it or not) Apple Pay to debit cards to freaking Chuck E Cheese (no, that's not a joke). But my advice is: use credit cards. They are your last line of protection against fraud. If you do not get the items you purchased, and you believe you were suckered into a fraudulent site, you can always revoke the transaction and attempt to get a refund. My recommendation is if you realize you went to the wrong place, revoke the transaction immediately. If you think you went to the right place and everything was fine but you did not get the items in a timely manner, open a support ticket. If Kabam support says they have no record of the transaction, *then* revoke the transaction immediately.

I recognize not everyone has this option, and in fact you may be trying to use the web store specifically because you want alternate payment options. If so, see the first three recommendations above. However, if credit cards are an option, I always recommend them for internet transactions.


Remember, if you hand your money to some total stranger who claims to be Kabam, Kabam can't help you. They can't refund money they didn't get. They can't give you the items you didn't pay for, even if you have otherwise lost the money. The in-game store is still the safest option, but if you're going to use the web store, and there might be advantages to using the web store, do so carefully. I do not want to be responding to forum posts next week from people who lost their money to scammers and want to know what they can do about it. There is very little they will likely be able to do about it.

Comments

  • DarkestDestroyerDarkestDestroyer Member Posts: 2,888 ★★★★★
    So are the links up there legit?

    Says the link, and then tells us to not trust him lol.

    Is that the link 🤷🏻‍♂️
  • Malreck04Malreck04 Member Posts: 3,328 ★★★★★
    I think a good resource to link would be this video explaining how there was this typeface in which some other character looked exactly like the letter a and was used to trick people into thinking it was the apple website. Can’t remember the video’s name for the life of me
  • SpideyFunkoSpideyFunko Member Posts: 21,954 ★★★★★

    Pikolu said:

    Remember guys, the link to the store is here https://store.playcontestofchampions.com/

    Some would say it’s better to have been scammed…
    And some would be wrong. All hail the Rick.
  • TyphoonTyphoon Member Posts: 1,861 ★★★★★
    DNA3000 said:

    Typhoon said:

    Anyone have a link to the store?


    I trust you bro!
  • winterthurwinterthur Member Posts: 8,110 ★★★★★
    Interesting that an email id created for game login (not a genuine email which can receive messages) can access the store (did not try purchase).
  • rcm2017rcm2017 Member Posts: 625 ★★★
    Thanks @DNA3000 i had made a post few days back when I noticed a url redirection while checking out the webstore. I guess while authenticating with ingame credentials there is a check that happens via xsolla.com, some said xsolla work with kabam. So yeah thats there too in between.
  • InsaneSkullInsaneSkull Member Posts: 334 ★★
    edited June 2023
    @DNA3000 Appreciated. Nice work.
  • SummonerNRSummonerNR Member, Guardian Posts: 13,167 Guardian
    Someone else correctly pointed out in another thread that on the TOP of the very FORUMS that you are reading this in, there is a big LOGO, with wording of…

    MARVEL
    CONTEST OF
    CHAMPIONS

    And actually clicking on that link will take you to the official MCOC Website (aka, minus the “Forums (dot)” beforehand, as DNA pointed out).
    So you don’t have to type it out, or click on any links that forum users (no matter how trustworthy) might put into their forum replies.

    At least on the Full page view, not sure if that big logo shows on the Mobile/phone view of these Forums (?)

    From there, go to the 2-bar icon on the Upper-Right Corner (aka, a menu icon, although most websites will use a 3-bar icon), and the STORE will be listed in that drop-down menu.

    Also as noted, XSOLLA is the processing company that Kabam choose to use for payment processing for the Store, so you will see some redirects related to Xsolla, as well as some important (to some, while others or most people probably don’t care) option choices for whether you consent to Marketing, etc, (aka, use of your private information, blah, blah. Go ahead and watch that “human centiPad” episode of South Park before just blindly clicking “accept” without reading).

  • At least on the Full page view, not sure if that big logo shows on the Mobile/phone view of these Forums (?)

    On mobile it just takes me to the "Community Home" page of the forums
  • SUPREME77SUPREME77 Member Posts: 144
    You're doing god's work here
  • DNA3000DNA3000 Member, Guardian Posts: 19,841 Guardian
    rcm2017 said:

    Thanks @DNA3000 i had made a post few days back when I noticed a url redirection while checking out the webstore. I guess while authenticating with ingame credentials there is a check that happens via xsolla.com, some said xsolla work with kabam. So yeah thats there too in between.

    As SummonerNR notes, Xsolla is the processing company, although I suspect Kabam outsourced the entire site construction to them. From what I can see, the MCOC store has a lot of structural similarities with other Xsolla-based stores.

    I have heard some people express concerns about Kabam making their own store, and to be honest I’d be a bit concerned as well, but they appear to have outsourced store construction to someone that specializes in and has many independent clients using their technology. That doesn’t mean they are perfectly secure, but it’s much more likely that the web store won’t have to go through a learning curve to implement reasonably secure transactions.
  • Geronimo3124Geronimo3124 Member Posts: 30
    The store does not seem to work on mobile when selecting one of the options. It just pulls up a blank screen.
  • DeaconDeacon Member Posts: 4,271 ★★★★★
    Internet safety is always paramount .... especially in text messages and emails which is the majority of delivery methods for any kind of phish/spam attempt.

    If you must use the store, just come to the game's main hub. Simple.
  • phillgreenphillgreen Member Posts: 4,185 ★★★★★
    The IT department at work, which is an evil privately owned global megacorp (lets call them Globex) seem to love me for some reason, probably because I keep them in a job by clicking their internal phishing test emails they keep sending me, hey, if I don't click the link how will I know if I will get that pay rise the email offered and I certainly don't want to miss out on my celebratory gift voucher for being employee of the month, even though we don't actually have an employee of the month award.

    Also, being rickrolled is nowhere near as nasty as being "protein twirled" Trust me on that.
Sign In or Register to comment.