Caution: Trojans on E-bay
Dave Thompson
>Had a funny thing happen to me yesterday... Just before heading home from work, I did a quick check of a couple listings on the bay. I ran across a Disston #29 which had something unusual in the overview listing...probably that someone had paid extra to have it top listed. Anyway, I clicked on it, and e-bay asked me for an ebay username password, as it usually does when you add something to a watch list, or do a search. My brain on auto-pilot, I typed my info in, though I belive at the time, the username/password to something else. But then it occured to me, the URL for this page is wrong. I traced it back and found the page hosted by a free web host site. I looked at the html source of the page and saw the POSTing goes to a site in czech republic, i.e. where the username password goes when you click the button.
Not good.... it's a trojan horse account harvester. Not thinking I fell into the trap, since I believed (incorrectly) I typed in the wrong info. I attempted to notify e-bay to get it delisted. I went through their maze of issue categories and promptly filed the report.
Thought this was the end of it until tonight. I check my mail and see that e-bay has suspended my account, removed my password, stopped outgoing mail, etc. I also see they have deleted ~10 supposed listings of mine all listed within an hour of the above incident.
I get my password changed, and so no big deal right. I see a very expensive Mayo improved patented plane that I was watching has been bidded on by me, and now I'm the current winning bidder at $4800, with a cap at $4888. I can't contact the seller to delist me, as my mail privileges at e-bay have not yet been restored. I can't contact e-bay's live customer service chat because apparently e-bay's live service chat is out.
Personally, I think the whole thing is somewhat humorous. It's even funnier given my profession. I'm well aware of the exploit used by this particular trojan and have plugged it on my home systems. I've been in the web browser writing business going back 14 years, and even funnier, I actually wrote SSL client and server security libraries for web browser companies over a 7 year period and was responsible for implementing features in web browsers that would notify a user of this exact issue. Too bad I wasn't using my own product at the time.
Anyway, thought I would share while I wait for e-bay customer support live-chat to come back on line.
Moral of the story:
- Every time you are prompted for user name/password. Look for the little lock picture on the lower right hand corner of your browser. URL's starting with "https:" (note 's') can be spoofed in the Address line of your browser, but the lock icon validates that it truly is https. https (SSL) includes an authentication that a third party vouches for the identity of the server you are visiting. Not foolproof, but it's significantly more difficult and riskier thing for a little pudwanker script kiddie to deal with. I won't get into the specifics unless asked.
- Be careful if you were looking at that Mayo improved patent plow plane. My bid has currently skewed things.
- If you go looking for that Disston #29 saw (the trojan portal), remember #1, and don't type in your username/password. Even though I reported it immediately yesterday, my confidence is low that anything quickly will be done about it. I'm sure there are likely others hiding out in the e-bay tool lists.
enjoy,
Dave