my ebay account was hijacked!

guycrunch

AzB Silver Member
Silver Member
imagine my surprise last night when i couldn't log onto ebay with my own password. i was able to get onto the ebay real-time help line and they figured out that someone took over my account, changed the name to "tina wenger" and the address to a nigerian address and sent out about 50 letters like this:

Hello seller,
I'm interested in the immediate purchase of this item,which is needed in my store urgently in next 5 days for my customers, how much will you offer for the total cost of the item including shipping & insurance via USPS Global Express MAIL, because i m always unable to place bid due to my nature of work and i will be paying you through a trusted name PAYPAL.reply asap with your paypal email account which you want you money to be credited too so that i can send your money right away into your account.please send your paypal account include your email address in your reply so that can contact you anytime.i will be glad if you can end auction for the item now.Reply Asap NB:i would like buy the item to one of my store , pls let me know if you can ship Tomorrow immediately you confirm the payment from PayPal .
Regard
Tina Wenger.
ewawahl@yahoo.com
ewawahl@hotmail.com.

Sincerely ."

the ebay rep was able to send notices to everyone who received the letter and warn them that it was phony. then he was able to secure my account. then, from my laptop i changed all of my passwords to everything and reformatted and reloaded my regular computer in case there was some sort of trojan that recorded my keystrokes. i never thought it could happen to me, but i hadn't changed my password since 1998. i will be a lot more careful from now on.

guy
 
I no longer visit ebay...full of scams. Not to mention that it's the world's largest fencing operation. (ask any cop) Me? I'll buy cues and cases new before I'll buy through ebay....ditto anything else that I have an interest in...
 
Guy (and everyone else),

There are a lot of phishing scams out there around getting ppl's passwords. The most common involves receiving an email that looks like a totally legit ebay email (the right ebay logos, wording, fonts, colors etc). The email might be about an item you're selling or placing a bid on, or a question on an item. Again everything looks totally legit as do the links in the email. Clicking the link takes you to what looks like the normal ebay login page, so you login, and BAM you've been phished, and someone has your password.

There's one obvious give away to this sort of scam, after you click the link that takes you to the login page, look up at the address bar in your browser and make sure the first portion of the URL looks something like "http://something.ebay.com/..." ie make sure that "ebay" is the domain name, that's one thing they can't fudge.
 
Hey guycrunch, If you pay your ebay account with a credit account you should contact them right away as they may have gotten that account as well. Mine was hijacked a while ago and they attempted to access my master card account.
Just a warning, hope all is well,
Dan
 
If you take the proper precautions, your account can't get stolen unless someone knows you or you use a password like (password) :D.

Never open a link form an email. NEVER. Stick to well known web sites. Remember, there are "game sites" out there whose sole purpose is to harvest usernames and passwords.

They then "test" those passwords out by using them on Ebay. For the people that use the same username and password everywhere, they have you, hook line, and sinker..

So, as a computer tech who has had quite a bit of security training, I would suggest you stick to well known websites like Yahoo!, Amazon, Ebay, etc... If you use web forums or any other sites you are not "sure" about, DO NOT USE THE SAME PASSWORDS as for the sites that are linked to you financially.

NEVER ENTER YOUR PASSWORD after following a link, under ANY circumstances! Trust me, these jokers are getting more and more sophisticated at making a bad website look legit.

As an example of warning: I have been on the internet for years, am computer security trained, and I got caught once... It was only ONCE, and I changed that password within probably 2 minutes, simply because I "got a bad feeling". There was nothing about the situation that screamed "phishing", but the mere fact that I was fooled into putting in a password should be enough to tell you that anyone can be caught.

So, to sum up:

Don't ever input usernames or passwords after following a link. Browse to the website yourself, and check to see if you have notifications of actions required..

Do not click on links to websites you do not know!! If your security settings are low enough and your computer is not properly patched, that website can use vulnerabilities to later load keyloggers and/or trojan files..

Don't "cross contaminate" usernames and passwords between entertainment sites and "pay sites". This is verrrry important. If I were a hacker, I would create a "free game site" and would harvest usernames and passwords that way. I would require an email address as a username, and I would find out what Ebay's password requirements were, and I would mirror that password policy. That would funnel users into choosing a password they are familiar with. A large percentage would use their Ebay password. Gotcha!

Hopefully, this will help you all avoid getting taken advantage of on the net. Some people are scared of using credit cards on the net, and there is good reason, but in general, you can protect yourself pretty easily. Just stay on the sites of legitimate, real world companies.

Example: Find and go to the website for Victoria's Secret.. It is almost 100% guaranteed to be safe, because the company can afford good IT personnel, and which can get sued if their employees mess you over.

Russ
 
Last edited:
Phite the Phish !!!

Russ Chewning said:
If you take the proper precautions ...

Yeah, Russ is right-on about all his advice. I have been real lucky -- never been caught -- but I know there are probably times, years ago, I should have been.

They do this stuff with bank account notices, PayPal notices, eBay notices and a whole bunch of other similar stuff. REMEMBER, ALL of these places do not send out any such notifications to their clients/customers. You are ALWAYS encouraged to MANUALLY log first onto their correct site, THEN log onto your account from a secure https:-type log-on page.

These "notifications" and "queries" always contain what looks like a legitimate link. But, if you look at the FULL MESSAGE HEADER first, before you do anything else, you will see what the TRUE address of the fake link is. If you can copy and paste this correct address, you can have a little fun fighting "phish." Go here and check this out:

http://phishfighting.com/

Have fun ... :D :D :D
 
Ebay Toolbar

If you download the Ebay toolbar, the window at the very top of Internet Explorer turns green when you go to Ebay. This confirms you're not at a spoof site. I didn't care for the toolbar and deleted it. My window still turns green on Ebay and Paypal. I think they should offer just this feature as a stand alone.
 
guycrunch said:
{SNIP}imagine my surprise last night when i couldn't log onto ebay with my own password. i was able to get onto the ebay real-time help line and they figured out that someone took over my account, changed the name to "tina wenger" and the address to a nigerian address and sent out about 50 letters like this:

{SNIP}

I can't say for sure how it happend; but never log into ebay (or paypal for that matter) from an email sent to you. There a lot of Phishing sites out there trying to get you to log in and bam, they now know your password. I have the newest version of internet explore that does a good job catching these sites; it did it a few times in the past.
 
I almost got caught myself, and I'm extra careful.. when selling my viking, I got a eBay message within eBay's messaging center in the form of an 'ask the seller a question' from a member asking 'is this you they are talking about in the forum?'.. then a link to a store.ebay.com site. The link was legitimate, to an eBay.com site, so I clicked.. they had setup an eBay store with an eBay login and html that redirected input to one of their own sites.. very clever.. as often as eBay asks for my password, I began to enter it, thinking it was forum or store login, or that my cookie had expired.. having just done it twice (once to get into eBay, then again after clicking on My Ebay), it didn't strike me as odd to be entering it once again. A fraction of a second before hitting enter, I thought better of it, viewed source, and found that it would redirect away from eBay.. they are getting VERY clever..
 
guycrunch said:
then, from my laptop i changed all of my passwords to everything and reformatted and reloaded my regular computer in case there was some sort of trojan that recorded my keystrokes. i never thought it could happen to me, but i hadn't changed my password since 1998. i will be a lot more careful from now on.

guy

Since Nov 2006, I have formatted my computer 7 times to get rid of trojans, with no success except for my last format. I will tell you something to try in just a minute. But first, I will tell you all of the things I tried:

I had used Darek's Boot and Nuke to wipe the hard drive. I had used Norton's wipe disk - 7 times DOD style. I had used DLink firewall. I had used antivirus and firewalls from Norton, Panda, Kaspersky, and Zone Alarm, which all got compromised. The bastards loved Norton, where they wrote their own rules for the firewall. I used AVG and Sysinternal Tools to detect the bastards and they reappeared like clockwork.

Everytime I redid my computer I notice that a port was being listened to by a file with a mid-eastern name......with the sand bastard characters.

To make a long story short, the key was to flush my BIOS. I got a file from Hewlett Packard - it overwrote my old BIOS and then turned off the computer (my laptop is 4 years old so this is easy to do - the new laptops have backup BIOS etc. and I haven't figured out yet how to flush them). When I rebooted, I used White Canyon's Wipe Drive from the CDrom to wipe the hard drive good. It is important to not access the hard drive until everything has been blasted. I did find a hidden partition and deleted the mother fu*#er using Fdisk that comes with White Canyon (this is a famous technique used by the Trojans). Then I was clean!!!! And I will say that with a big 'luckily', because todays Trojans use sophisticated machine language to hide in the hardware devices with chips that can be written to, CMOSes, and everything else under the sun.

I like MacAfee because it has a SITE ADVISOR which indicates if an internet site is safe or not, and even this is not even 100% fullsafe.

MacAfee also warns you if something is trying to write to your registry, and gives you the chance stop it. White Canyon has a Secure Clean product that wipes your deleted and hidden files (DOD style if you like) and other places that Trojans like to hide.

Granted, a good 'ROOTKIT' (or Trojan) can bypass all of these safeguards with the greatest of ease. If anyone is interested in what dangers exist out there, go to Sysinternals website and visit the forum. This tools are completey free and safe, as Sysinternals was bought out by Microsoft.

Remember that viruses are not rootkits. Viruses spread. Rootkits stay on your computer and do anything they want to, like log your keystrokes, or log onto sites while you are even not aware. All I can say is that one must be wary and look out for any signs that your computer is behaving oddly, like the internet running slower than normal.

Good luck, you (and I) will need it.:D
 
Last edited:
Russ Chewning said:
Bastian,

Did you email Ebay and let them know about that?

Russ

Oh most definitely.. and they sent me a link to 'how to protect yourself from eBay scams'.. seems they are too inundated to do much about it, but I couldn't let it go unmentioned.
 
I don't know which is worse on your computer - Ebay or Limewire.....
We had FOUR separate home computers and both of my laptops crash and burn last year.
And we get hammered almost daily now that my wife has started an Ebay store.....
We have a ton in security programs and it still doesn't help.
And this whole redirecting away from sites is annoying anyway, without the world's biggest conglomeration of internet thieves at one great location.
Although I'd dearly love to get some of these scammers on a table a few times a month......
 
was this a mass attack junk email that u got or a question from a member, if it was junk email u should turn up your spam filter, to avoid getting spam i make a separate email that i only use to sign up for websites and what not, i've had the same main email for 3 years now and i get less than 5 junk emails a week, also u may try not to make a email name thats too common that'd already be on a junk email list

the fake logins have been around for awhile and the only people who fall for them are the ones that dunno they exist, if u only click on links from your favorites then u won't have to worry about them, when logging into anything it's a good habit to check and make sure the url is that of the actual site and not some fake login page, if u have doubts about a login then just put in a bogus pw and if it works then the page is fake

for online account security, make all your pws different, it shouldn't be something u can look up in the dictionary or a # under 8 digits, i wouldn't use caps cause u want something that is ez to remember, i like pws that use numbers as letters, also write down your pws if u make them all different just in case, if u r worried about someone finding them incode them, too be over cautious u could make all your usernames different, u also want to be aware of what pws u use on forums/other sites because the can be viewed by the owners

another thing that most people don't secure is their personal info, i dont like how sites like this list peoples bdays, on hotmail all u need is someones zip and a correct answer to their secret ? to get into their account, on yahoo u need zip/country/bday, since finding personal info really isn't that difficult it's very important that your secret question answers aren't guessable/crackable, make them 2-3-4 word answers
________
 
Last edited:
Johnson said:
....for online account security, make all your pws different, it shouldn't be something u can look up in the dictionary or a # under 8 digits, i wouldn't use caps cause u want something that is ez to remember, i like pws that use numbers as letters, also write down your pws if u make them all different just in case, if u r worried about someone finding them incode them, too be over cautious u could make all your usernames different, u also want to be aware of what pws u use on forums/other sites because the can be viewed by the owners

Passwords should be AT LEAST 8 CHARACTERS. Why? - because the code crackers' time is increased a hundred fold.

Don't use names in the passwords, or words that are in a dictionary, because the is the first thing the code crackers go for. Use a combination of upper and lower case letters, a few numbers, and a few symbols (!@#$% etc.)

Create a separate non-administrative account to get on the internet with.

And trust me when I say this, PASSWORDS WON'T DO YOU ANY GOOD when a good trojan happens upon your computer. This is my wife's conclusion also as we both have been hacked into at least 50 times. She has a warchest of printed out virus code and has even called the FBI.

BTW, the FBI wasn't interested apparently. But last month the FBI announced that it was going to notifiy 1 million users that they had been compromised and that their computers were being used as bots (controlled by hackers). They had used a 'HONEY POT' to catch these hackers and as a side bar took note of all our computers being used.

I would be even money that 50% of the home users in the US have rootkits on their computers and they don't even know it. The FBI's estimate is higher. You see, I have been telling you guys this for months and you still think I am crazy :D Bottom line: don't do any form of online banking. The hackers love Ebay and PayPal. This industry is now bigger that drug trafficing.

Have a good day everyone :)
 
Back
Top