rec.bicycles.marketplace · Public discussion

EBay security alert: they may have been hacked.

Started by Werehatrack · · Last activity · 10 posts · 317 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
rec.bicycles.marketplace
Published
27 September 2006
Last activity
28 September 2006
Original author
Werehatrack
Posts
10
Discussion status
Public discussion
Total views
317
Views / 30 days
0
Topics

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 1–10 of 10
Posts remain in their original chronological order.

Text size
  1. Just now, I was on a real eBay search results page, and when I clicked
    on one of the item descriptions, I was redirected to a bogus eBay
    login page on what appears to be a hacked system in Corpus Christi,
    TX.

    The redirect happened FROM AN EBAY SEARCH RESULTS PAGE.

    It is no longer safe to assume that a page reached by a link that
    *should* take you only to another spot within ebay is really going to
    do so.

    If you get plopped on to an eBay login page, LOOK CAREFULLY AT THE
    URL. If it's on any domain except ebay.com, my advice is ENTER
    NOTHING.

    EBay, in its finite wisdom, does not have a contact phone number on
    its website that I could find. I've submitted a report via the web
    interface, but it could be hours before anyone reads it, and it's not
    at all certain that the person who reads the message will be able to
    understand the issue and kick it up to where it needs to go.

    This is easily the most serious ecurity breach at eBay that I have
    ever seen.

    Given that many of the users of this group frequent eBay, I am posting
    this here because it is a marketplace *safety* issue.

    If you have direct contacts at eBay to whom you can get this info
    relayed, do it with my blessing.
    --
    Typoes are a feature, not a bug.
    Some gardening required to reply via email.
    Words processed in a facility that contains nuts.

  2. Update: the hack is via the use of a script; the script redirects the
    user's browser to an off-eBay phishing site. If you have *all*
    scripting disabled, the page will not redirect. If you have any
    scripting working, it will plop you on to a phishing site.

    I have contacted eBay by phone and alerted them of the issue.

    --
    Typoes are a feature, not a bug.
    Some gardening required to reply via email.
    Words processed in a facility that contains nuts.

  3. "Werehatrack" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    Just now, I was on a real eBay search results page, and when I clicked
    on one of the item descriptions, I was redirected to a bogus eBay
    login page on what appears to be a hacked system in Corpus Christi,
    TX.

    The redirect happened FROM AN EBAY SEARCH RESULTS PAGE.

    You mean by clicking on an Item Title link? If so, that's very bad.

    Greg

  4. "Werehatrack" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    Update: the hack is via the use of a script; the script redirects the
    user's browser to an off-eBay phishing site. If you have *all*
    scripting disabled, the page will not redirect. If you have any
    scripting working, it will plop you on to a phishing site.

    I have contacted eBay by phone and alerted them of the issue.

    That's what I figgered. XSS exploits are extremely popular these days, just
    looked at a site on Monday with hundreds of open examples. Ebay should be
    doing better a job, though.

    Greg

  5. On Wed, 27 Sep 2006 14:59:00 -0700, "G.T." <[email hidden]>

    Quoted message said:


    "Werehatrack" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    Just now, I was on a real eBay search results page, and when I clicked
    on one of the item descriptions, I was redirected to a bogus eBay
    login page on what appears to be a hacked system in Corpus Christi,
    TX.

    The redirect happened FROM AN EBAY SEARCH RESULTS PAGE.

    You mean by clicking on an Item Title link? If so, that's very bad.

    Exactly.

    The eBay person I spoke to was fully aware of just how bad this was;
    they recognized the seriousness of the problem as soon as I
    demonstrated it to them. All I had to do in order to accomplish this
    was to give them the item number for the auction involved. The page
    redirected the eBay employee's browser off-site.

    I figured out how it was done; I have captured a copy of the hack, as
    a matter of fact, and can duplicate it. I will not, however, be
    publishing it.
    --
    Typoes are a feature, not a bug.
    Some gardening required to reply via email.
    Words processed in a facility that contains nuts.

  6. Werehatrack said:

    Update: the hack is via the use of a script; the script redirects the
    user's browser to an off-eBay phishing site. If you have *all*
    scripting disabled, the page will not redirect. If you have any
    scripting working, it will plop you on to a phishing site.

    What operating system/browser were youe using?

    --

    John ([email hidden])

  7. Interesting. I don't see this happening now. But I am using Mozilla on Win2K. I
    have noticed some wierd behavior on the back button over the last few days when
    navigating EBay search result pages. I wonder if this could be related?

    Werehatrack said:

    Just now, I was on a real eBay search results page, and when I clicked
    on one of the item descriptions, I was redirected to a bogus eBay
    login page on what appears to be a hacked system in Corpus Christi,
    TX.

    The redirect happened FROM AN EBAY SEARCH RESULTS PAGE.

    It is no longer safe to assume that a page reached by a link that
    *should* take you only to another spot within ebay is really going to
    do so.

    If you get plopped on to an eBay login page, LOOK CAREFULLY AT THE
    URL. If it's on any domain except ebay.com, my advice is ENTER
    NOTHING.

    EBay, in its finite wisdom, does not have a contact phone number on
    its website that I could find. I've submitted a report via the web
    interface, but it could be hours before anyone reads it, and it's not
    at all certain that the person who reads the message will be able to
    understand the issue and kick it up to where it needs to go.

    This is easily the most serious ecurity breach at eBay that I have
    ever seen.

    Given that many of the users of this group frequent eBay, I am posting
    this here because it is a marketplace *safety* issue.

    If you have direct contacts at eBay to whom you can get this info
    relayed, do it with my blessing.

  8. John Thompson said:
    Werehatrack said:

    Update: the hack is via the use of a script; the script redirects the
    user's browser to an off-eBay phishing site. If you have *all*
    scripting disabled, the page will not redirect. If you have any
    scripting working, it will plop you on to a phishing site.

    What operating system/browser were youe using?

    Several flavors of Windblows, and several different browsers including
    Firefox, Mozilla, and IE. With scripting completely turned off, the
    exploit was fully defeated; with it turned on at all, the exploit
    worked.
    --
    Typoes are a feature, not a bug.
    Some gardening required to reply via email.
    Words processed in a facility that contains nuts.

  9. "David White" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    Interesting. I don't see this happening now. But I am using Mozilla on


    Win2K. I

    Quoted message said:

    have noticed some wierd behavior on the back button over the last few days


    when

    Quoted message said:

    navigating EBay search result pages. I wonder if this could be related?

    Don't know. But regarding the exploit you wouldn't see it unless you're
    looking at an item that Werehatrack was looking at or one by the same
    seller. When that seller created his listing he threw some Javascript to
    take Ebayers to a different web site.

    Greg

    Quoted message said:
    Werehatrack said:

    Just now, I was on a real eBay search results page, and when I clicked
    on one of the item descriptions, I was redirected to a bogus eBay
    login page on what appears to be a hacked system in Corpus Christi,
    TX.

    The redirect happened FROM AN EBAY SEARCH RESULTS PAGE.

    It is no longer safe to assume that a page reached by a link that
    *should* take you only to another spot within ebay is really going to
    do so.

    If you get plopped on to an eBay login page, LOOK CAREFULLY AT THE
    URL. If it's on any domain except ebay.com, my advice is ENTER
    NOTHING.

    EBay, in its finite wisdom, does not have a contact phone number on
    its website that I could find. I've submitted a report via the web
    interface, but it could be hours before anyone reads it, and it's not
    at all certain that the person who reads the message will be able to
    understand the issue and kick it up to where it needs to go.

    This is easily the most serious ecurity breach at eBay that I have
    ever seen.

    Given that many of the users of this group frequent eBay, I am posting
    this here because it is a marketplace *safety* issue.

    If you have direct contacts at eBay to whom you can get this info
    relayed, do it with my blessing.

  10. Werehatrack said:

    Update: the hack is via the use of a script; the script redirects the
    user's browser to an off-eBay phishing site. If you have *all*
    scripting disabled, the page will not redirect. If you have any
    scripting working, it will plop you on to a phishing site.

    I have contacted eBay by phone and alerted them of the issue.

    Thanks for taking the initiative.

    Wayne

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.