Slashdot Log In
Ebay Hacked, User Info Posted
Posted by
CmdrTaco
on Wed Sep 26, 2007 09:52 AM
from the hate-when-that-happens dept.
from the hate-when-that-happens dept.
An anonymous reader writes "This morning a hacker posted the personal contact information and credit card data of 1,200 ebay users on the eBay.com Trust & Saftey forums. eBay pulled the Trust & Safety forums off line, but not before one user made a video of the hacked forums and posted it on youtube.com. eBay response is on the eBay chatter page, and seems to try and down play this "fraudster"'s activity."
Related Stories
Firehose:Ebay hacked, users personal information posted by Anonymous Coward
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Fraudster? (Score:5, Insightful)
(Last Journal: Monday November 28 2005, @12:21PM)
Re:Fraudster? (Score:5, Interesting)
(http://fnarg.com/)
Sometimes, when someone doesn't listen to your kind advice, you have to make them listen.
Re:Fraudster? (Score:5, Informative)
(http://judebert.com/)
Re:Fraudster? (Score:5, Insightful)
This kind of behaviour is reprehensible. If you wanted to let EBay know they have a security problem, tell them, anonomously if you must, but posting other peoples indentifying information is like shooting an automatic weapon into a crowd of innocent people. I think along with fines, restrictions and imprisonment, spanking should be added to the list of punishments for this type of behavior.
I wonder ... (Score:5, Insightful)
Given that Ebay's response is along the lines of "It's a hoax, our security is fine, don't worry" I really wonder if keeping things like this under wraps is enough to keep companies like Ebay honest. I'm not optimistic since any admissions on their part cost them money, dent their public image, may cost them customers, and could make them easier to sue in case accounts are abused (either before or after the data becomes public).
Of course it's irresponsible to publish this sort of information (credit-card numbers, contact details) on the web. And yes ... perhaps there should be an independent authority (e.g. the police, the FBI) where you can go with your information and be certain that action will be taken instead of making it accessible to the world and his dog.
In the absence of a clear-cut authority to report to I'm still not quite convinced that the "shock-and-awe" effect of bluntly putting the data on the web isn't needed to prod Ebay into action to take measures.
Re:Fraudster? (Score:5, Informative)
(http://www.xwin.net/)
Re:Fraudster? (Score:5, Insightful)
Re:Fraudster? (Score:5, Informative)
(http://www.fusioncomm.net/)
http://www.beachnet.com/~hstiles/cardtype.html [beachnet.com]
...and adobe as well ;) (Score:1)
http://www.heise.de/newsticker/foren/go.shtml?read=1&msg_id=13602017&forum_id=124661 [heise.de]
When will EBay notify? (Score:5, Insightful)
Re:When will EBay notify? (Score:5, Insightful)
Even as it stands, unless E-bay can show beyond a shadow of a doubt that only those posted were the ones stolen, anyone credit card number that e-bay has should be held as suspect for potentially having been stolen. Ebay has really dropped the ball. It will be interesting to see how they scramble to deal with this.
Re:When will EBay notify? (Score:5, Funny)
Whitehat? (Score:5, Informative)
So I wonder: are these 1200 users the kinds of people who post up an auction for a picture of a coveted item hoping to scam someone out of buku bucks? Are these users that took the money and ran? Or are these legitimate users caught in a genuine hack?
Can't watch the video, and the ebay PR rundown doesn't (and wouldn't) say, but since ebay happily protects fraudulent sellers and refuses to give defrauded buyers any means to recover their losses from the scammers it seems to me like this has potential to be a hacktivism move.
am I affected? (Score:2)
(http://www.halley.cc/ed/)
Since it's gonna happen.... (Score:1)
(Last Journal: Thursday June 28, @12:06AM)
On the other sports page...
Exactly how the guy got the information is a good guess. Probably via phishing scams. In all, this ain't Ebay's fault that people are giving their information away. Now, what Ebay does now that they know.....
Virtual credit card (Score:5, Informative)
I got mine for free from my bank and have used it for lots of online purchases - it's fucking awsome.
Re:Virtual credit card (Score:5, Informative)
Everything is tied to your main account, but if 'they' get the temp number, it's useless. It doesn't count towards having a new line of credit, maxing out your card (unless you max out your Account) or how long you've had the card. I think in the last year I've made 100+ of them. Used for everything for bills (Who in their right mind would send valid credit card information though the mail, then they have *everything*) To online orders.
No big deal. (Score:5, Insightful)
1200 posted but where ALL accounts compromised? (Score:1, Insightful)
alphabetical (Score:3, Informative)
Chances are I am wrong, but if thats the case then that narrows the list down, and I wouldn't have to worry.
hacked? (Score:3, Interesting)
i only ask because i had a better-than-usual phishing attempt this morning telling me my ebay account had been 'restricted' and it wouldn't be too hard to harvest 1200 passwords from the above without hacking ebay itself.
email text:
"A33 TKO NOTICE: Restricted Account Access
We have taken steps to secure your eBay account, including review of your
personal information and placing a temporary restriction on your account. Any
activity has been cancelled and any associated fees have been credited to your
account. We assure you that your credit card and bank details are stored on a
secure server and cannot be viewed by anyone.
Your account is currently blocked from listing and bidding on items, and from
sending email through Ask Seller a Question or Contact eBay member. To restore
full access to your account, please follow the instructions in this email."
login to your account link was:
http://us.ebayobjects.com/2c;13012399;10693575;h?http://61.9.146.244/signin.ebay.co.uk/ws/?eBayISAPI.dll?co_partnerid=2&siteid=0&UsingSSL=1 [ebayobjects.com]
ie it had a susipicious 2nd address in url, one which resolves to australia
One point to be made-- (Score:5, Informative)
(http://gmail.com/)
The guy had to have either:
A) Made them up
B) Gotten them somewhere else.
Regardless, he's just a troll trying to create bad press for eBay.
Bet 20$ none of those users had the Secure dongle (Score:2, Interesting)
in fact my number right now is 342498 GO and hack my account now.... oh wait. it just changed... 096443 is the new number, you got 25 seconds.
Lying by omission to try to remove this info (Score:2)
Perhaps it was The Decepticons! (Score:2, Funny)
ebay Statement (Score:5, Informative)
(http://www.spacerogue.net/ | Last Journal: Friday September 17 2004, @08:23AM)
Trust & Safety forums issue this morning
Some of our readers may have learned of an issue that occurred early this morning on one of our discussion forums. I've been talking with our Account Security and Legal teams, and I'd like to share some more details about this incident.
Very early this morning, a malicious fraudster posted on the Trust & Safety forum on eBay.com posing as approximately 1,200 eBay users. The fraudster made these posts in a way that was intended to appear as though he logged in with their accounts. The posts contained name and contact information, which appears to be valid, and could have been secured as part of an account take over.
The posts ALSO appeared to contain credit card information -- however, these credit cards are not associated with financial information on file for these users at eBay or PayPal. We're in the process of reaching out by phone to these members to, so that if the information is valid somehow -- regardless how this fraudster acquired the information -- these members can take the steps they need to take to protect themselves.
eBay and our forums vendor, LiveWorld, began taking steps to remedy the situation within an hour after it started. As things evolved behind the scenes, a decision was made to make the the Trust & Safety forum unavailable to our Community. It's still temporarily inaccessible, as the teams work on this issue.
I'll update this story later as we have more to share.
Forum Vendor? (Score:1)
(http://www.ibjhb.com/ | Last Journal: Tuesday May 04 2004, @07:05AM)
I'm curious, why would a company the size of eBay (in both $ and employees) use a third party vendor for their forums? Why wouldn't they just invest in developing their own forums and avoid potentially embarrassing publicity?
WHAT HAPPENED: Fradulent Items on eBay (Score:5, Interesting)
eBay item (Score:1)
(http://www.dosspot.com/)
No (Score:1)
E-Bay response (Score:2)
(http://www.paxconsultoria.com/)
I just read that response. I for one find it very professional and correct.
What did you expect ? That E-Bay would just come forward and say: "oh, we haven't fully checked on this yet, but since it was a post on the forum, we are sure it is correct, so we are confirming it".
They are investigating. They are contacting the users that are potentially affected (just in case).
They are not silent. They are not denying that it could have happened. They are even taking preventive measures. What more did you want ?
Here is the list of account names (Score:2)
http://shenemanfamily.com/comp.html [shenemanfamily.com]
i was a victim (Score:1)
(http://www.seededfury.com/)
how nice of them... (Score:1)
(http://www.brianbotkiller.com/ | Last Journal: Saturday August 07 2004, @05:44AM)
revenge (Score:1)
(http://googtube.blogspot.com/)
This video has been removed due to terms of use .. (Score:2)
(http://stefanco.com/ | Last Journal: Sunday October 14, @11:09AM)
This video has been removed due to terms of use violation. [youtube.com]
CC numbers are probably valid (Score:2, Insightful)
The Register contacted at least two of the people whose info was posted and they confirmed their accounts had been hacked.
See the story here [theregister.co.uk].
As for the credit card numbers not belonging to the people affected my first thought was the hacker posted the correct contact info but, perhaps to be benevolent, scrambled the credit card numbers. In other words, the card numbers displayed are correct but they're just shown as belonging to someone else. eBay may be realizing this now when they search their databases for the people those numbers really belong to.
I'm a little happy when things like this happen. (Score:1)
This may be redundant, but I, being absolutely ignorant in that area, like it when they do helpful things.
Hmm (Score:1)
Link, anyone? (Score:2)
I am probably not on the list (I know a phish when I see one), but just in case...
my account is just fine. (Score:2)
(http://www.gamerslastwill.com/)
Then you can't log in without it.
I'm not worried about my account.
i have no doubt (Score:1)
(http://www.seededfury.com/)
Bill Cobb can suck a fat one (Score:1)
(http://www.theaudiorevenge.com/)
late action (Score:1)
Identity theft schemes (Score:1)
Re:Just beautiful. (Score:2)
Re:Just beautiful. (Score:5, Funny)
Real Deal EBay (Score:5, Informative)
I get EBay phish email all the time, and I get real EBay email all the time.
It's easy to tell them apart. EBay never ask for credit card information (they don't have it); the phishers always do. EBay know my name, and use it. The phishers don't.
...laura
Re:My question is... (Score:2)
(http://www.dpaton.net/ | Last Journal: Friday May 17 2002, @04:09PM)
Re:My question is... (Score:2, Redundant)
(http://www.biochem.ucl.ac.uk/ | Last Journal: Thursday November 01 2001, @09:11AM)
"The posts contained name and contact information, which appears to be valid, and could have been secured as part of an account take over. The posts ALSO appeared to contain credit card information -- however, these credit cards are not associated with financial information on file for these users at eBay or PayPal. "
Re:My question is... (Score:1)
Re:video? (Score:2)
(http://www.e3servers.com/ | Last Journal: Thursday January 26 2006, @12:17PM)
Re:Just beautiful. (Score:2, Funny)
(http://www.jokertoke.co.uk/)
Re:My question is... (Score:3, Informative)
Re:Let me be the first to say.. (Score:2)
Re:Microsoft-IIS/5.0 (Score:4, Funny)
Re:My question is... (Score:2)
Re:How about "eBay not hacked,you morons" as headl (Score:2)
(http://harvardace.blogspot.com/)