Major eBay Security Issue - Jemsite
Vendors, Auction & Reseller Talk Not for posting JEM/UV ads. Not for posting dealer/broker ads. Not for advertising ebay auctions. This is to chat about resellers, various gear in question, odd items or the people selling them.

 
LinkBack Thread Tools Display Modes
post #1 of 13 (permalink) Old 04-11-2013, 10:19 AM Thread Starter
Vendor
 
Rich's Avatar
 
Join Date: Dec 2000
Location: South Jersey
Posts: 25,490
Major eBay Security Issue

Many of you are probably aware of this con man that has been using hacked ebay accounts for many years, easily identified by the JS20th, JSBDG, and JEM20th auctions he keeps relisting. Typically he's always used a jpg that has the Buy It Now price and the Gmail email account he wants you to write him at to finish the transaction, that jpg always hosted on a hacked website.

The issue is he has now figured out how to hack the ebay pages themselves so that when you click on the item link in the ebay search pages, you have now been redirected into another hacked site when he now controls all the links. If you click on the Report Item link you get the Buy It Now page, and all these pages are hosted on another hacked site.

This is apparently how he is collecting user ID's and passwords. An example of one of the auctions closed last night, but still hosted on this hacked URL

http://nauk2paw2.com/ws/eBayISAPl.ph...eller=bkmoores

Here is a screen shot that shows you the auction page, redirected to this hacked URL



And the familiar JS20th auction, also redirected to this nauk2paw2.com URL.



The most disturbing aspect of this is you can no longer trust the links on ebay will take you to pages ON ebay. That's scary. Shop safe.
Rich is offline  
Sponsored Links
Advertisement
 
post #2 of 13 (permalink) Old 04-11-2013, 01:36 PM
Super Moderator
 
Join Date: Dec 2000
Location: England
Posts: 6,953
Reviews: 1
Re: Major eBay Security Issue

STICKY AND BUMP!!!
jono is offline  
post #3 of 13 (permalink) Old 04-11-2013, 04:39 PM
 
Jason Stone's Avatar
 
Join Date: Dec 2000
Location: New York City
Posts: 401
Re: Major eBay Security Issue

Wow. Rich, assume you've emailed eBay itself about this?
Jason Stone is offline  
post #4 of 13 (permalink) Old 04-11-2013, 05:16 PM
 
Join Date: Jul 2001
Location: Trondheim, Norway
Posts: 3,614
Re: Major eBay Security Issue

He clicked the report item button, but ended up buying the guitar...

Moar bamps.
The Euphor is offline  
post #5 of 13 (permalink) Old 04-11-2013, 05:41 PM
 
Join Date: Dec 2012
Location: Vancouver, BC, Canadia
Posts: 1,969
Re: Major eBay Security Issue

Wow, thanks for the heads up!!!
Stealthtastic is offline  
post #6 of 13 (permalink) Old 04-11-2013, 09:29 PM Thread Starter
Vendor
 
Rich's Avatar
 
Join Date: Dec 2000
Location: South Jersey
Posts: 25,490
Re: Major eBay Security Issue

He listed these at 2:40, 20 minutes before ebay CS closes. ebay was "having updates" and by the time you could work through the voice menu to get to an agent, it would hang up, for 20 minutes straight. I spent 20 minutes on the phone this morning with somebody trying to play stupid, before finally demanding a supervisor, when he finally admitted they know they're being hacked, and they're "investigating". So they know, but they're not going to admit it.

This is only the second time he's listed this format, buy it now at $2000 auctions instead of the typical $9.99 no reserve with the jpg offer to buy off ebay. The last time I didn't notice it was not an ebay page, the report item link changed to buy it now, [[which was disturbing, and I called ebay to report that and really pressed them on HTF!! could that happen on just his auctions!! I got the stupid act that time also]] , so I had to go track down the manual way to report item, which is an easter egg hunt at best. This time when the report item went to buy it now I figured what the hey, I'll just buy it now, nobody else can get screwed on them, and I can get a kick out of whatever messages I get from him on the purchases. Ebay purges all record of them as soon as they kill all the auctions so it's nothing that can hurt your account, right?

Right, I looked at that blank login ID window, that didn't have my ID already filled in, for a about a second as odd before I filled in my ID and logged in. The only way I caught anything is the "want to save this password" IE notice bar popped up [OK, that's really strange] and when I looked close it was for nauk2paw2.com, look at the url bar, and it took a millisecond to realize I'd just given away my user ID and password to this f***!!! I immediately changed my ebay password, which means I had to do paypal also, then started calling CS trying to get through to have a good long conversation about HTf!!! this guy has been able to hack the code of his auctions to where they're mirrored off another host!

That was my good ID too. I'm actually pissed, I've been using that one as long as I've been online, it was the auto generated password from my very first ISP on my very first computer. That's a sad day. So I had to come up with a new one, and then go change ebay / PP again, and remember the other 3 sites I used my good password in.

I never did hit that buy it now to see what would happen. Next time he does this I'll try some random ID/password combination to see if he really has a mirror ebay login and it takes a correct ebay combination to log in, or if any ID will "log in" because it's not being checked by ebay.

I aint the smartest guy but I have a really good nose for the con, and I did not see that coming. If he can get me for my password, he can get most.

If this guy can do it - it'll be all over the underworld of hackers and cons and unless ebay can get a lock on it, this could get serious. You can bet that every time I go log in to buy something I'll be looking at the url before I do!!
Rich is offline  
post #7 of 13 (permalink) Old 04-11-2013, 09:39 PM
 
CosmicDebris's Avatar
 
Join Date: Aug 2007
Location: Richmond VA, USA
Posts: 3,980
Re: Major eBay Security Issue

You gotta be impressed by their ingenuity. However, I ****ing hate scammers. Never been scammed but it is the principle of the matter.
CosmicDebris is offline  
post #8 of 13 (permalink) Old 04-12-2013, 06:53 AM
 
Join Date: Feb 2010
Location: Florida
Posts: 118
Re: Major eBay Security Issue

Holy Effin' Crap. They better damn straight fix it, the theft/security implications are phenomenal. Report turns to buy it now, LOL. What a ****y bastard too.
AgentHeinz is offline  
post #9 of 13 (permalink) Old 05-15-2015, 02:29 PM
 
Join Date: Jan 2006
Location: Yorkshire,UK
Posts: 1,823
Re: Major eBay Security Issue

Unbelievable ! Did you ever find out if ebay sorted this problem out Rich ?
Zoot is offline  
post #10 of 13 (permalink) Old 05-15-2015, 02:33 PM Thread Starter
Vendor
 
Rich's Avatar
 
Join Date: Dec 2000
Location: South Jersey
Posts: 25,490
Re: Major eBay Security Issue

It didn't happen again, and I haven't seen this scammers adds in a while. Not sure exactly how long ago, but if he wasn't caught, he'll be listing again. Leopards don't change their spots.
Rich is offline  
post #11 of 13 (permalink) Old 05-15-2015, 08:40 PM
 
Join Date: Nov 2014
Location: USA
Posts: 1
Re: Major eBay Security Issue

They probably aren't hacked eBay Accounts. Companies sell them with feedback already on them. $100-$2000 per account. They can then turnaround and screw people over which is what they do with these accounts. Alot of scams on eBay and Buyer Protection only can help you so much.
Gronico is offline  
post #12 of 13 (permalink) Old 05-15-2015, 08:43 PM Thread Starter
Vendor
 
Rich's Avatar
 
Join Date: Dec 2000
Location: South Jersey
Posts: 25,490
Re: Major eBay Security Issue

He always used hacked accounts where the seller already had hundreds of legitimate listings besides the hundreds he would add.
Rich is offline  
post #13 of 13 (permalink) Old 05-16-2015, 04:17 AM
 
Join Date: Jan 2006
Location: Yorkshire,UK
Posts: 1,823
Re: Major eBay Security Issue

Ebay just isn't the place it used to be for buyer or seller. It is the biggest and quickest market though and I guess that the only reason it survives no matter what.
Zoot is offline  
Reply

Tags
ebay hack con man

Quick Reply
Message:
Options

Register Now



In order to be able to post messages on the Jemsite forums, you must first register.
Please enter your desired user name, your email address and other required details in the form below.

User Name:
Password
Please enter a password for your user account. Note that passwords are case-sensitive.

Password:


Confirm Password:
Email Address

IMPORTANT: You will be required to activate your account so please ensure that your email address is correct.

If you do not receive your activation check your spam folder before using the CONTACT US form (at the bottom right of each page).



Email Address:
OR

Log-in










Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode



Similar Threads
Thread Thread Starter Forum Replies Last Post
home security shredmaster Off-topic / Miscellaneous 5 04-23-2009 08:39 PM
Major Wiring Issue acdc51502112 Pickups & wiring 1 09-26-2008 01:00 AM
Anyone know about webcam security? kennydoe Off-topic / Miscellaneous 18 04-22-2007 06:30 AM
G-Major - JMP-1 mapping issue 9red9 Gear, Equipment, Recording & Off Topic 4 10-26-2005 05:19 AM
Major issue... Smally Off-topic / Miscellaneous 16 10-01-2005 01:40 AM

Posting Rules  
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

 
For the best viewing experience please update your browser to Google Chrome