WoodCentral Forums

Est. 1998 — 27 years of woodworking knowledge

Caution: Trojans on E-bay

Posts

Caution: Trojans on E-bay

#1

Caution: Trojans on E-bay

Dave Thompson


>Had a funny thing happen to me yesterday... Just before heading home from work, I did a quick check of a couple listings on the bay. I ran across a Disston #29 which had something unusual in the overview listing...probably that someone had paid extra to have it top listed. Anyway, I clicked on it, and e-bay asked me for an ebay username password, as it usually does when you add something to a watch list, or do a search. My brain on auto-pilot, I typed my info in, though I belive at the time, the username/password to something else. But then it occured to me, the URL for this page is wrong. I traced it back and found the page hosted by a free web host site. I looked at the html source of the page and saw the POSTing goes to a site in czech republic, i.e. where the username password goes when you click the button.

Not good.... it's a trojan horse account harvester. Not thinking I fell into the trap, since I believed (incorrectly) I typed in the wrong info. I attempted to notify e-bay to get it delisted. I went through their maze of issue categories and promptly filed the report.

Thought this was the end of it until tonight. I check my mail and see that e-bay has suspended my account, removed my password, stopped outgoing mail, etc. I also see they have deleted ~10 supposed listings of mine all listed within an hour of the above incident.

I get my password changed, and so no big deal right. I see a very expensive Mayo improved patented plane that I was watching has been bidded on by me, and now I'm the current winning bidder at $4800, with a cap at $4888. I can't contact the seller to delist me, as my mail privileges at e-bay have not yet been restored. I can't contact e-bay's live customer service chat because apparently e-bay's live service chat is out.

Personally, I think the whole thing is somewhat humorous. It's even funnier given my profession. I'm well aware of the exploit used by this particular trojan and have plugged it on my home systems. I've been in the web browser writing business going back 14 years, and even funnier, I actually wrote SSL client and server security libraries for web browser companies over a 7 year period and was responsible for implementing features in web browsers that would notify a user of this exact issue. Too bad I wasn't using my own product at the time.

Anyway, thought I would share while I wait for e-bay customer support live-chat to come back on line.

Moral of the story:



  1. Every time you are prompted for user name/password. Look for the little lock picture on the lower right hand corner of your browser. URL's starting with "https:" (note 's') can be spoofed in the Address line of your browser, but the lock icon validates that it truly is https. https (SSL) includes an authentication that a third party vouches for the identity of the server you are visiting. Not foolproof, but it's significantly more difficult and riskier thing for a little pudwanker script kiddie to deal with. I won't get into the specifics unless asked.

  2. Be careful if you were looking at that Mayo improved patent plow plane. My bid has currently skewed things.

  3. If you go looking for that Disston #29 saw (the trojan portal), remember #1, and don't type in your username/password. Even though I reported it immediately yesterday, my confidence is low that anything quickly will be done about it. I'm sure there are likely others hiding out in the e-bay tool lists.


enjoy,

Dave

Re: Caution: Trojans on E-bay

#2

Thanks for the Heads Up Dave.

V Parisian


>I am constantly getting e-mails from "PayPal" wanting me to update my account information. Amazing, because with PayPal I always use my wife's account and she has her own email. So far I have ignored them, but each time I do I have this niggling thought running through my mind that causes me to question if this could be a legitimate query from the real PayPal. Anybody else getting these e-mails?

Regards from hot&sticky Houston

Victor

Re: Caution: Trojans on E-bay

#3

Re: Thanks for the Heads Up Dave.

Wayne Anderson


>Neither PayPal nor ebay will ever require you to log in, (supply your ID). I've seen several types of spoof messages designed to mine IDs. If in doubt, just forward the message to spoof@ebay.com or spoof@paypal.com. They will take it from there.

Though I have never been caught in one of those scams, my friend has. First thing they do is change your profile so you no longer have control. I contacted the vendor on his behalf, and it got quickly resolved. -wayne

Re: Caution: Trojans on E-bay

#4

Let me get this straight...

VTAndy4


>.... you were ON eBay when you somehow got redirected to the scammer's site? Or you accessed it via an email that you were sent?

-Andy

Re: Caution: Trojans on E-bay

#5

Re: Caution: Trojans on E-bay

Paul Kierstead


>Very nice! I am always happy to see some of them using something more creative then just the latest IE exploit or email click this to see XXX nekkid....

As you have happily admitted to, security still remains more the realm of the user then the technology.

Great story and glad it didn't spin too out of control.

One my me leading policies is to never login to anything unless *I* pressed the login button, and even then I have a look. OTOH many years as a security geek has made me paranoid.

Re: Caution: Trojans on E-bay

#6

Re: Let me get this straight...

Dave Thompson


>Yes, I was on e-bay looking at current listings. Clicked on one of the listings, at the top of a tool list, and was directed to an e-bay looking login page which was in reality the scammer site.

This had nothing to do with e-mail. The trojan was posted within e-bay listings. In hindsite this looks like a common occurance with e-bay, as during my follow up with this issue in e-bay, I've seen many canned follow ups which are to the point for this issue. They even have available ebay internet explorer toolbar add-ons which supposedly will watch for this. Glad to see it, since the exploits that this particular trojan uses have been around for a while.

FWIW, Following links through e-mail listings is potentially inviting trouble. Spoofing e-mail has always been easy, but 20 years ago was limited to those who were familiar with SMTP protocol RFC821 (still pretty easy). We did it in college among friends for fun. These days, its trivial to do from most e-mail programs since a user has control over the from field. A couple other tricks that exploit known bugs in common software make it easier to hide. It's best to initiate ones own connection and link, rather than use a convenience e-mail link.

Dave

Re: Caution: Trojans on E-bay

#7

Re: Caution: Trojans on E-bay

Pam Niedermayer - Austin, TX


>Remember, ebay now owns Paypal. IIRC, you have to give your ebay password to Paypal (I could be really wrong here, my Paypal password in NOT the same as my ebay password.) and/or any sniping services you use. If the thief gets into other services via that ebay password, your credit cards/bank accounts may be at risk.

Pam

Re: Caution: Trojans on E-bay

#8

Re: Caution: Trojans on E-bay

Todd Hughes


>My X wife who sells a few things on ebay got a question about an auction but only thing wasn't anything she was selling but looked like it was on the standard Ebay question email. She clicked on and saw it was a car with another ebayers name. Thought it was unusual and emailed the person that asked her about it that it wasn't her auction. Didn't think to much about it but in about a week there were a bunch of car auctions using her ebay name and ebay took her off ebay till she changed her pass words. Apparently when she went into the auction and looked at it and emailed the questioner back they got into her computer and stole her ebay info. Ebay told her to only answear email questions though the "My Ebay " page....pretty amazing I thought ....Todd

Re: Caution: Trojans on E-bay

#9

Re: Caution: Trojans on E-bay

George in Lowell, Mich.


>Todd,

The same thing happened to me. By the time I was wise as to what was happening they had listed (I printed the list) 8 pages of items using my account. The listing fees if EBAY hadn't caught it was almost $1000.!!!!!

What a headache!

George, in comfortable (finally) Michigan

Re: Caution: Trojans on E-bay

#10

Re: Caution: Trojans on E-bay

Dave Thompson


>Yes, someone hoping for that would have more of an incentive. For me, parnoia has always been hightened with Paypal and on line stock trading, etc. I keep unique passwords for these, and I pretty much always check SSL authentication status. Things like ebay and amazon, I'm a little more relaxed. Risk reduction at amazon happens at the credit card level, i.e. $50 liability. The worst that could happen to me on e-bay did. I'm currently the top bidder for a $5k plane at the moment, and for about a half hour I had ten listing of some porno titles. It's just a minor annoyance, but as you point out for some others in different situations, it could be worse.

I actually never made the switch over when Paypal forced people to switch off drawing from credit cards. I haven't used Paypal in about a year. This hasn't been a problem except for the times I see things I want to buy overseas. I figure if I ever cave in, I'll just open up a separate bank account just for paypal transactions and limit my risk to paypal money.

Re: Caution: Trojans on E-bay

#11

Re: Caution: Trojans on E-bay

Pam Niedermayer - Austin, TX


>Paypal issues debit/credit cards, so what I usually do is fund that card for n dollars (they also pay 3.22% interest--stated 4.22%, but they now charge a 1% management fee) and use that card. However, the funding bank account is somewhat vulnerable, since they'll draw from that bank only when paying from Paypal for any amount greater than the debit card has on it. Geesh, this is complicated to talk about. :)

Pam

Re: Caution: Trojans on E-bay

#12

Re: Caution: Trojans on E-bay

arw01


>Now are you using IE6, IE7, or a current firefox for this Ebay trickery?

Is there a current auction that I can go look at to see what my browser tells me so I can educate my wife on any new techniques she needs?

Alan

Re: Caution: Trojans on E-bay

#13

Re: Caution: Trojans on E-bay

Ernie Miller


>I must have missed the change over frome credit cards becaust I still buy stuff using my CU issued visa card as of a month or so ago. I also don't have to use my eBay sign in when going to paypal. but with all of the increasing fees every where I turn I am about ready to quit selling. I am in the process of liquidating all of my excess inventory and not getting any more. I seems that they are about up to 25% of the gross sales when using eBay and paypal. If somthing sells for les than doubble the price I bought it for they end up making more than me. just don't add up to me.

Re: Caution: Trojans on E-bay

#14

Re: Thanks for the Heads Up Dave.

Ernie Miller


>I used to forward all of these to spoof@ but I het probably 10-15 a week and I soon got the feeling that I was being a bother to them for sending them to them. one of there security techs told me that there were just to many to keep up with and they would only be active for less than an hour befor they were taken down and moved to another site making it impossable to track and stop. I beleave there are ways that eBay could put an end to them but they have no reason to to even try and stop it. If you don't catch it you are responsable for the bill and they make money.

Re: Caution: Trojans on E-bay

#15

Re: Caution: Trojans on E-bay

Dave Thompson


>I was using IE6. There is a now well known bug in IE where the actual visited URL may be disguised from what is displayed in the Address line. Microsoft fixed this in one of their security patch upgrades more than a year ago. Ofcourse, not everyone keeps their machine up to date with the latest security patches, so they may be vulernable to this.

This only partly helps though (my machines are patched) The real solution lies in the user checking the security status of the page before typing in their user name password. As mentioned before e-bay uses a secure page for username/password. A user can verify that they are indeed at an authenticated secure site by checking for the security icon. In IE, it is a lock symbol at the bottom of the screen. If it's not there, then the username/password is sent over the internet unprotected and it has the potential of going to an unauthenticated site.

Ofcourse, I've known this for a decade and still I stumbled into the issue because my brain was on auto-pilot just trying to do some quick e-bay scanning...

good luck,

Dave

👍 This page answered my questions

Your vote helps other woodworkers quickly find the answers and techniques that actually work in the shop.