Home
Home

Directory
Directory

Articles
Internet News
Security News
Ecommerce News
Domain News

Site Tools
Site Speed Test
Keyword Research
Resolve Hostname
DNS Tools
Register Domains
Affiliate Programs
Open Source

Shopping Carts
Cart Reviews
SSL Certificates

Enter your email address to subscribe to our updates:

Delivered by FeedBurner


Venue Charts
Channel Traffic Rankings
OAI Stock Quotes and Charts
eBay's Worst Feedback

Forum
Forum Home
TulipTools News
Advertising
Blogging
Computer Hardware
Domain Names
Ecommerce
Financing
Int'l Trading
Graphics and HTML
Internet Access
Legal Issues
Internet Business
Auction Sites
Classified Ad Sites
Fixed Price Venues
Operating Systems
Programming
Search Engines
Internet Security
Software
Web Hosting
Webmaster Issues
Reviews
Announcements
Off Topic Discussion

Web Hosting
TulipHosting

Domain Names
TulipDomains

Web Stats
TulipStats

Forum Rules
Forum Rules
Privacy Policy

Site Map
Forum Sitemap
Sitemap Topics




Directory| Forums| Internet News|Cart Reviews| DNS Tools| Keyword Research| Site Speed Test| Security| | Domain Marketplace| Domain Blog
TulipTools Internet Business Owners and Online Sellers Community
  • Home
  • Search
  • Member List
  • Calendar
Hello There, Guest! Login Register
TulipTools Internet Business Owners and Online Sellers Community › Online Auction Industry, B2B Trading Sites, Classified Ad Sites, Fixed Price Venues, and Malls › Online Auction Industry Discussion › Auction Sites › eBay › Frauds, Scams, and Rip Offs v
1 2 3 4 5 … 14 Next »

eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks

  
Pages (3): 1 2 3 Next »
Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Threaded Mode | Linear Mode
eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
12-10-2005, 12:34 PM, (This post was last modified: 12-10-2005, 12:36 PM by Kristijntje.)
Post: #1
Kristijntje Offline
Super Moderator
******
Posts: 1,200
Likes Given: 0
Likes Received: 0 in 0 posts
Joined: Oct 2005
Reputation: 0
eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
Quote:Scammers have found a new way to try to trick eBay members into giving them their personal information.

The new technique effectively hijacks links on listing or search results pages, taking people to an official-looking eBay log-in page that is actually phony.

In one example the Mercury News viewed this week, several listings were added to eBay's ``Totally bizarre'' category, a section intended for offbeat items, with the title ``Movie!With me and Laura!My best friend!Sexy show!1$''

When eBay users clicked on the listing titles, their Web browser was immediately redirected to the fraudulent log-in page. Making matters worse, the phony page appears to download a virus onto users' computers.

...EBay said the people behind the scam appeared to have added malicious JavaScript code to their listings...

full article: http://www.miami.com/mld/mercurynews/business/13376864.htm?source=rss&channel=mercurynews_business
Al draagt een aap een gouden ring, het is en blijft een lelijk ding
Like Post Reply
[+]
12-10-2005, 03:13 PM,
Post: #2
bargainbloodhound Offline
Lawnmower Mouth
********
Posts: 4,372
Likes Given: 0
Likes Received: 4 in 4 posts
Joined: Jul 2005
Reputation: 0
Re: Phishers attack eBay using new technique: Malware on eBay Listing Pages
Well this is one case where it is definitely not safe to shop or even browse on the "safe" eBay site.  Laughing7

I think eBay should bear part of the financial burden and compensate anyone who has had their info stolen as a result of this phish because it was their lax security that allowed it to happen.

*putting on my web site owner's hat and taking off my seller's hat before this next sentence*  Smile  Allowing anyone to place javascript in their listings or in anything else that they place/upload on your site is a fr_ck'n security problem waiting to happen...and it looks like eBay's bad judgement has allowed it to happen.
"Well, Jay was so giddy that someone named Jay was involved with this site we posted our first non-eBay listing in 3 years here at Lunarbid (we tried two items at Yahoo once upon a time, they bombed)" -Marie posting in a LunarBid thread at OTWA in 2005 wins the award for 'most moronic reason ever given for choosing a venue"

"thanks twat u must have nothing better 2 do. do u talk to all your members like that. will not be recomending your site.
best way to put it is TULIPTOOLS.COM IS REALLY SHIT. DONT JOIN." -pubescent owner of rinky dink off2auction.com in 2011
Like Post Reply
[+]
12-10-2005, 10:29 PM,
Post: #3
regic Offline
Administrator
*******
Posts: 2,825
Likes Given: 0
Likes Received: 2 in 2 posts
Joined: Jul 2005
Reputation: 0
Re: Phishers attack eBay using new technique: Malware on eBay Listing Pages
Quote:EBay has tools that automatically scan new listings for computer viruses and malicious JavaScript, spokesman Hani Durzy said. In this instance, the hacker apparently used code that sneaked past the screening process.

Your scanner doesn't work, time to find a new programmer

http://jobsearch.monster.com/jobsearch.asp?q=programmer&fn=&lid=&re=104&cy=us&x=0&y=0

Happy001
Like Post Reply
[+]
12-11-2005, 02:13 AM,
Post: #4
xppman Offline
Tulip Fanatic
*******
Posts: 2,406
Likes Given: 0
Likes Received: 0 in 0 posts
Joined: Jul 2005
Reputation: 0
Re: Phishers attack eBay using new technique: Malware on eBay Listing Pages
I say the more the BETTER.

F2#%@K ebay.
Wonder how many of these problems are from folks who had their PP accounts FROZEN or were suspended without due process from the bay.

You GO hackers.  Sign10
.
Like Post Reply
[+]
12-11-2005, 09:41 PM,
Post: #5
catholicemporium Offline
Tiny Tool
**
Posts: 28
Likes Given: 0
Likes Received: 0 in 0 posts
Joined: Sep 2005
Reputation: 0
Re: Phishers attack eBay using new technique: Malware on eBay Listing Pages
[quote author=regic link=topic=1668.msg5911#msg5911 date=1134253794]
Quote:EBay has tools that automatically scan new listings for computer viruses and malicious JavaScript, spokesman Hani Durzy said. In this instance, the hacker apparently used code that sneaked past the screening process.

Your scanner doesn't work, time to find a new programmer

http://jobsearch.monster.com/jobsearch.asp?q=programmer&fn=&lid=&re=104&cy=us&x=0&y=0

Happy001
[/quote]

Anything that comes out of Hani Durzy's mouth is nothing but spin.  I have made this comparison before, and I will re-iterate it:  Hani Durzy is just like Baghdad Bob (was that his name?).  The Iraqi official who insisted the Americans weren't anywhere near Baghdad while the tanks rolled by.
Like Post Reply
[+]
12-12-2005, 03:40 AM,
Post: #6
dimucci Offline
Full Member
****
Posts: 138
Likes Given: 0
Likes Received: 0 in 0 posts
Joined: Jul 2005
Reputation: 0
Re: Phishers attack eBay using new technique: Malware on eBay Listing Pages
Hani b.s.ing in a past life http://www.revenews.com/advice/news/060200a.html
Like Post Reply
[+]
12-13-2005, 02:16 AM,
Post: #7
xppman Offline
Tulip Fanatic
*******
Posts: 2,406
Likes Given: 0
Likes Received: 0 in 0 posts
Joined: Jul 2005
Reputation: 0
Re: Phishers attack eBay using new technique: Malware on eBay Listing Pages
Quote:Anything that comes out of Hani Durzy's mouth is nothing but spin.

Look up Hani Durzy.
You will see the
[Image: wach2.gif]
.
Like Post Reply
[+]
12-22-2005, 03:42 AM, (This post was last modified: 12-22-2005, 03:48 AM by bargainbloodhound.)
Post: #8
bargainbloodhound Offline
Lawnmower Mouth
********
Posts: 4,372
Likes Given: 0
Likes Received: 4 in 4 posts
Joined: Jul 2005
Reputation: 0
eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
eBay's recent attempt to blame lax computer security habits of its users for a sharp rise in account hijackings are a bunch of B.S.  eBay shares equal blame for account hijackings because it knew about and ignored warnings that a security hole existed on its site through which a user could place malicious code in a listing on the ebay site or on an about me page that would redirect them from the eBay site to an off ebay phishing site.

Almost 1 year after this vulnerability was pointed out to eBay, hackers did in fact take advantage of this hole in December 2005 to phish users on the ebay site .

The GulfTech warning and article below were issued in January 2005...eBay did nothing despite the warnings.

Quote:Last year GulfTech Security Research found several security flaws in eBay and the eBay owned half.com. These security flaws could allow attackers to execute malicious code in the context of a victim's browser, and could easily be used to hijack accounts, and in phishing, and other scams. Unfortunately only some of those security flaws were fixed, and the most dangerous of the bunch still remain even after being made public. Additionally, GulfTech Security Research found similar security vulnerabilities in the well known amazon.com website. Like eBay, the amazon.com vulnerabilities still exist.


Should I Be Worried?
If you make use of eBay or amazon.com you could be put at risk simply by visiting a link, or viewing a malicious web page. The eBay vulnerability is an especially nasty one because all an attacker has to do in order to acquire victims is place an auction or fill out their "about me" page with malicious data. Once the malicious auction is placed a victim's cookie based credentials can be stolen silently, and even worse an attacker can hijack certain Document Object Model elements and cause anyone who clicks on the "place bid" button to be redirected to a bogus login page or worse. Below is an example "about me" page put together by us that will demonstrate how this vulnerability could be used for phishing.


The full article: http://www.gulftech.org/?node=research&article_id=00064-01042005

Based on the fact that eBay knew about this security vulnerability for almost a year and did nothing, I think they would have a hard time defending themselves in court if anyone who was victimized (had their personal info stolen or account hijacked) decided to sue them.
"Well, Jay was so giddy that someone named Jay was involved with this site we posted our first non-eBay listing in 3 years here at Lunarbid (we tried two items at Yahoo once upon a time, they bombed)" -Marie posting in a LunarBid thread at OTWA in 2005 wins the award for 'most moronic reason ever given for choosing a venue"

"thanks twat u must have nothing better 2 do. do u talk to all your members like that. will not be recomending your site.
best way to put it is TULIPTOOLS.COM IS REALLY SHIT. DONT JOIN." -pubescent owner of rinky dink off2auction.com in 2011
Like Post Reply
[+]
12-22-2005, 05:26 AM,
Post: #9
jezebel Offline
Tulip Fanatic
*******
Posts: 1,385
Likes Given: 0
Likes Received: 0 in 0 posts
Joined: Jul 2005
Reputation: 0
Re: eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
Corporate bureaucracy is to blame for their not fixing the software.  The programming guys probably need approval from 50 supervisors just to take a piss.  Laughing7
Like Post Reply
[+]
12-22-2005, 11:48 AM,
Post: #10
mandy Offline
Administrator
*******
Posts: 9,932
Likes Given: 0
Likes Received: 6 in 5 posts
Joined: Feb 2011
Reputation: 0
Re: eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
Quote:Should I Be Worried?
If you make use of eBay or amazon.com you could be put at risk simply by visiting a link, or viewing a malicious web page. The eBay vulnerability is an especially nasty one because all an attacker has to do in order to acquire victims is place an auction or fill out their "about me" page with malicious data. Once the malicious auction is placed a victim's cookie based credentials can be stolen silently, and even worse an attacker can hijack certain Document Object Model elements and cause anyone who clicks on the "place bid" button to be redirected to a bogus login page or worse. Below is an example "about me" page put together by us that will demonstrate how this vulnerability could be used for phishing.


I would be worried if I was a member of the site.  Smile
Like Post Reply
[+]
« Next Oldest | Next Newest »
Pages (3): 1 2 3 Next »




Possibly Related Threads…
Thread Author Replies Views Last Post
  German court orders eBay to do more to fight counterfeits on its site mandy 0 2,210 07-28-2007, 09:33 AM
Last Post: mandy
  How was eBay able to get into our bank account? mandy 0 2,145 05-08-2007, 08:40 AM
Last Post: mandy
  eBay's security problems: Vladuz and account hijackings via redirect page on eBay mandy 26 12,124 03-15-2007, 08:56 AM
Last Post: mandy
  Tall Lanky Blond Meg Whitman: Phishers Could Destroy Customers' Trust in eBay mandy 5 3,789 03-10-2007, 09:01 PM
Last Post: BellisimaJ.
  B.C. Ferries' security department to question eBay seller Blissmeister over logs mandy 26 12,902 11-27-2006, 09:05 PM
Last Post: blissmeister
  eBay Motors Redirect Security Hole Allows Scammers to Hijack Buyers regic 4 3,377 11-14-2006, 11:02 PM
Last Post: sneakymagenta
  On eBay, let the seller also beware: an account hijacking story mandy 0 2,242 07-03-2006, 10:42 AM
Last Post: mandy
  WHINING eBay Australia Security Chief COMPLAINS Security Community is Unfair mandy 1 2,360 05-23-2006, 06:09 PM
Last Post: dnc_ont
  Scotland has appointed its first "eBay detective" as online auction fraud soars mandy 0 2,072 05-21-2006, 10:46 AM
Last Post: mandy
  Russian Web Site Selling eBay Users Account Info for $5 per Account Shut Down mandy 3 3,111 03-26-2006, 05:18 AM
Last Post: bargainbloodhound

  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread
Forum Jump:


Users browsing this thread: 1 Guest(s)
  • Contact Us
  • TulipTools Internet Business Owners and Online Sellers Community
  • Return to Top
  • Lite (Archive) Mode
  • RSS Syndication
  • Help
Current time: 02-07-2026, 01:11 AM Powered By MyBB, © 2002-2026 MyBB Group. Theme created by Justin S.
powered by Apache

powered by Linuxpowered by CentOS

Copyright 2000-2013 TulipTools.com. All rights reserved.