Home  >  Community  >  The eBay Outlook  >  EBAY HACKED!!!!! IMPORTANT


<< previous topic post new topic post reply next topic >>
 CBlev65252
 
posted on September 25, 2007 12:22:31 PM
You can get the details from this thread. Scary! I've changed all my information including cc numbers. I'm taking no chances. eBay did their usual cover up.

http://forums.ebay.com/db1/thread.jspa?start=0&threadID=2000440040&anticache=1190748036430

Here's another thread:

http://forums.ebay.com/db1/thread.jspa?threadID=2000440346&tstart=0&mod=1190737403620

Here's an article:

eBay Shuts Trust & Safety Board after Credit Card Numbers Exposed
By Ina Steiner

AuctionBytes.com
September 25, 2007

eBay shut down an entire discussion board devoted to Trust & Safety issues after someone began posting confidential user information. Someone using multiple User IDs began listing information purported to be eBay users' private and financial data on the Trust & Safety discussion board. Mark, a user who says he posts regularly on the board, said he noticed the problem at 8:50 am Eastern on Tuesday and called his eBay representative about 20 minutes later after he saw the posts remained. He said it took about an hour for the posts to be removed, and minutes later, the entire board was taken down.

The person posted using several IDs that look like they had been hijacked from legitimate users. The subject line of each thread began with the letters "Wheeeeeeeeeeeeeeeeeeeee" followed by six numbers.

Mark said regular users who were posting on the board while the incident was taking place suspected that eBay may have been hacked, and he said some believed it was a scammer named Vladuz that has tormented eBay in the past. eBay has denied that Vladuz has ever hacked into its system (http://www.auctionbytes.com/cab/abn/y07/m02/i22/s03).

AuctionBytes was able to view the forum and several posts before they were removed. While most data looked like it could have been obtained through phishing campaigns, the posts also included fields labeled "Id verified" and "Store" along with a time-date stamp of the user registration. The accuracy of the information has not been verified by AuctionBytes.

NOTE: Please check back during the day as we will update this story as it develops.

Also see the AuctionBytes blog:
http://blog.auctionbytes.com/cgi-bin/blog/blog.pl?/pl/2007/9/1190743667.html

TO THOSE WHO THINK I'M TRYING TO STEAL THEIR ID'S - FEEL BETTER NOW???????????????

Cheryl
[ edited by CBlev65252 on Sep 25, 2007 06:23 PM ]
 
 CBlev65252
 
posted on September 25, 2007 12:34:51 PM
You can find a partial list of compromised ID's here. As stated in the list, if your name isn't here, it doesn't mean you are safe!

http://tinyurl.com/35n4tu


Cheryl
[ edited by CBlev65252 on Sep 25, 2007 12:51 PM ]
 
 niel35
 
posted on September 25, 2007 12:49:14 PM
it won't connect, Cheryl. Can't get through
neva

 
 fonze
 
posted on September 25, 2007 12:51:42 PM
The link is probably and scam. You shouldn't click on funny urls, they can record your keystrokes and get your passwords.

Mel

 
 CBlev65252
 
posted on September 25, 2007 12:51:47 PM
Do you mean my links? I get them okay. If you go onto Seller Central or the Jewelry boards there are discussion threads on the issue.


Cheryl
 
 CBlev65252
 
posted on September 25, 2007 12:59:22 PM
You shouldn't click on funny urls, they can record your keystrokes and get your passwords.

Mel - Let me introduce myself, I'M NOT A SCAMMER. THEY AREN'T FUNNY URLS. Tiny URL is a site that takes long URLs and makes them small. This is not a scam. You didn't read the article I posted? The news has also gotten a hold of the story.

You are exactly the kind of eBayer eBay likes. One that doesn't believe they could ever do anything to compromise you. Geesh.

Cheryl
[ edited by CBlev65252 on Sep 25, 2007 12:59 PM ]
 
 niel35
 
posted on September 25, 2007 01:19:22 PM
OK, Cheryl, I have it now. The first time it wouldn't come up but now have a list of the user ids tnx

 
 fluffythewondercat
 
posted on September 25, 2007 01:40:10 PM
Mel is correct about tinyurl and similar services. I never click on tiny urls and advise others not to as well.

All of which is independent of whether or not Cheryl is a trusted authority or whether eBay has actually been hacked.

Ina "print first, retract later" Steiner makes her living off spreading rumors to get people to visit her site.

fLufF
--


NEW free jewelry offers at clearanceclarence.com
 
 tomwiii
 
posted on September 25, 2007 02:12:08 PM
"Mel is correct about tinyurl and similar services. I never click on tiny urls and advise others not to as well."

As far as I know, TINY URL has been providing a wonderful FREE service for at least 5 years, and I've never encountered anybody warning about any kind of security issues with their very helpful service...

Perhaps you could kindly cite something somewhere to back up this rather sweeping condemnation of TINY URL?








 
 fonze
 
posted on September 25, 2007 02:13:05 PM
Hello.
I never called anyone here a scammer. But you can unknowingly click a link that will cause you grief. I've been selling on eBay over 9 years so I am no innocent newbie dope. I was told by ebay after my account password was hacked that when you click on links in fishing emails and go to a site even if you don't fill in your personal info they can record your keystrokes and get any passwords you enter and I believe it 'cause that's how it must have happend to me. I used to click on the links to see if the site the fishing emails linked to was down, to see if I sould bother reporting it to ebay. Now I just forward the funny emails to [email protected] and never click the links. I'm not familiar with tiny, never heard of it so I'm not clicking the link. Is it an online auction industry site many are familiar with? I'll go ask at the how cafe.

Mel
[ edited by fonze on Sep 25, 2007 02:21 PM ]
 
 pixiamom
 
posted on September 25, 2007 02:20:35 PM
Here is eBay's blog on the issue (for those of you who don't like tiny urls):

http://forums.ebay.com/db2/ann.jspa?annID=2000000061

Edited to add: I think it's interesting to see that eBay has chosen to address this in a blog, rather than on the General or System Announcements Board- An attempt to keep it low profile?
[ edited by pixiamom on Sep 25, 2007 02:29 PM ]
 
 tomwiii
 
posted on September 25, 2007 02:27:49 PM
US NEWS & WORLD REPORT review of TINY URL:

http://www.usnews.com/blogs/daves-download/2007/2/12/use-tinyurl-to-create-tiny-web-addresses.html#read_more

Use TinyURL to Create Tiny Web Addresses
February 12, 2007 02:15 PM ET

"We've all been frustrated by long Web addresses, like the one that will get you a recent column of mine: http://www.usnews.com/usnews/biztech/davesdownload/archive/070124/atomic
age_clocks_that_set_them.htm

Yuk. That would rarely work in an E-mail, with line breaks messing it up, as we all know from friends and relatives trying to forward Web links that just don't work. So check out www.tinyurl.com, which you may have noticed is behind a lot of the links mentioned in these columns. For example, that nasty Web link above becomes a simple: http://tinyurl.com/377xnx.

The service is free and reliable. TinyURL also offers a plug-in for your browser's toolbar. That makes it as easy as clicking on your toolbar to generate a short URL. Other services, such as www.snipurl.com, offer even more sophisticated tools, such as choosing a keyword at the end, so the link to that column becomes http://snipurl.com/atomicclocks.

The services promise to store the links permanently. Problems can arise, most often when the address of the original Web page gets changed. Also, the services could disappear, as do many Web services, leaving your shortened links in limbo. But TinyURL, for one, appears to be a survivor–with millions of hits, the site is making money for its founder, Kevin Gilbertson, who developed it while a student at the University of Minnesota. He's making enough money that he recently bought a competitor, www.makeashorterlink.com, which reportedly developed the idea even before Gilbertson. But with its shorter address, TinyURL was apparently easier for people to remember, even as it makes it unnecessary for us to remember other, long URLs."






[ edited by tomwiii on Sep 25, 2007 02:29 PM ]
 
 birgittaw
 
posted on September 25, 2007 02:31:57 PM
Tinyurls are fine; they also offer a new version (at least to me) that tells me where it is going:

http://preview.tinyurl.com/2y38np

which takes your to this message (or close enough).

 
 CBlev65252
 
posted on September 25, 2007 02:42:27 PM
The posts ALSO appeared to contain credit card information -- however, these credit cards are not associated with financial information on file for these users at eBay or PayPal. We're in the process of reaching out by phone to these members to, so that if the information is valid somehow -- regardless how this fraudster acquired the information -- these members can take the steps they need to take to protect themselves.

Like the double talk? One sentence claims the cc numbers are not associated with the financial info of members then the next sentence states "if that information is valid somehow". Typical eBay fashion.


Cheryl
 
 max40
 
posted on September 25, 2007 03:07:57 PM
As far as the tiny url is concerned, it's only as good or reliable as the person that posts it. Anyone can use it to send you anywhere.

 
 agitprop
 
posted on September 25, 2007 03:48:48 PM
No need to panic over this latest eBay snafu. It's business as usual and any resultant credit card fraud should be covered by the issuer. Ameritrade's servers were hacked earlier this year and over six months around $28 billion in assets were left exposed so nothing to worry about...

Home of the best eBay auction fee & PayPal calculators: http://auctionfeecalculator.com
 
 fluffythewondercat
 
posted on September 25, 2007 04:11:39 PM
Tom, I'm sorry to say it, but you're confused.

When the URL is masked, you have no idea where you're going by clicking on the tiny version.

For those of us who actually can read URLs and can use WHOIS and other technical information sources to figure out what's really going on, having the URL masked is a red flag.

I don't care how long the link is. I always post the thing in the clear, as it were, so people can see what they're getting into when they click it.

fLufF
--


NEW free jewelry offers at clearanceclarence.com
 
 tomwiii
 
posted on September 25, 2007 04:22:29 PM
I'm not confused, I'm just saying back up your condemnation of the TINY URL service by sumptin other than apple-dumpling pontification...

I've yet to read anyplace documented cases of problems (viruses; or spyware; or flatulating hot-airitis) caused by the use of the tiny url service...

And may the bluebird of happiness,etc,etc...



 
 OhMsLucy
 
posted on September 25, 2007 04:25:14 PM
Well, she didn't say there was anything wrong with Tiny URL, just that when the link is masked there's no way to know what it actually is.

Personally, I don't click on Tiny links. I like to check out the site first via Mywot.

Lucy

 
 fluffythewondercat
 
posted on September 25, 2007 04:34:51 PM
Here's a real life example from a few years back.

Some baddies registered the domain paypai.com all neat and legal-like. Then they put a website there that mirrored paypal.com in every respect, including a login screen.

Except it wasn't PayPal, of course.

All the baddies had to do was send out emails saying PayPal had been hacked. Login here to make sure your account is safe!

Susie Random clicks on the link in her email, logs in and sure and shootin' she's alarmed by what she sees. PayPal's been hacked indeed. It's a really really long URL, though, for the page she's looking at, so she uses a convenient URL-truncation service to post the link to all her favorite discussion groups. PAYPAL'S BEEN HACKED! OH MY GOSH! I'VE GOT PROOF! LOOKIT HERE!

And they did. 'Course, they had to log in to see it, not knowing they were kissing their PayPal password goodbye.

fLufF
--







NEW free jewelry offers at clearanceclarence.com
 
 CBlev65252
 
posted on September 25, 2007 06:07:20 PM
http://forums.ebay.com/db1/thread.jspa?threadID=2000440040&start=0

From the Trust & Safety Board:

http://forums.ebay.com/db2/thread.jspa?threadID=1000565805&tstart=0&mod=1190767746988

The "hacker" has now apparently posted the Trust & Safety page with the information on UTube.


Cheryl
[ edited by CBlev65252 on Sep 25, 2007 06:14 PM ]
 
 kozersky
 
posted on September 25, 2007 06:09:38 PM
I'm curious as to why the original URL was not posted, and has not been posted. It would seem simple enough for Cheryl to give us the original.

Bill K-
http://www.kozersky.com
 
 vintageads4u
 
posted on September 25, 2007 06:10:21 PM
And clicking on Cheryl's tiny url will take me to a paypal PAYPAI site?...

Let's tap on the brakes.
Beth
VintageAds4U

http://stores.ebay.com/vintageads4uonline?refid=store
 
 CBlev65252
 
posted on September 25, 2007 06:13:18 PM
And what the hell would you call the two links I provided above? Geeze, you people really are something.

Jewelry Board

Trust and Safety Board

They aren't all that hard to find.


Cheryl
 
 CBlev65252
 
posted on September 25, 2007 06:15:22 PM
Oh, and here. Just so you don't click on my dangerous links.

http://shenemanfamily.com/comp.html

Possibly compromised ID's
Email me
This list was compiled with the help of many people, some who wish to remain anonymous. It was pulled from many sources. Your name on this list doesn't mean your account was absolutely positively compromised. It just means it might have been. Conversely, your name *not* on this list doesn't mean anything, either. This is just a list of names that were known to have been posted on a board where some personal info was also posted.

I have to go to work (for a few hours) in a couple of hours...but will continue to monitor board & email and update page as possible. Will of course check it tonite when I get home.

Thanks to silver & all that have helped me compile the list of names. We're up to 502. If I haven't responded to your emails personally...it's only because I have set the updating of the list to top priority.

Some generic suggestions to follow if / when you feel your online information is compromised:

Change passwords.

Notify bank & credit card companies that there might be a problem, and ask them to monitor your account closely for a bit.

If really concerned, close all bank and credit card accounts, and get new accounts set up.

Apparently some discussion threads are being deleted, and some posts are being kept out due to a filter set on the conversations. Word however is spreading, news agencies and law enforcement have been notified. Hopefully no one ends up with real problems because of this incident. Hugs to all who have helped me with this list!

48871
1778696
040018
1165julie
123olbrich
151jpeterson
1755tom
1954siel
1957dudad
197bro
1alejandrita
1deadrock
1shack57
2005bim
2005branstetter
2006paulaandrea
21mercedes
3-dhunter
3015philip
30pete30
3371andrew
351stech
3bayaccount1
4ever80s
420sel1
49erdolphin
4ashtree
672roberts
754joshua
ab562
ab562
ab562
accrdcivic
adarisse
aeleafe
ags61
ags61
ahug
alabamian100
alastair1109
alcanat71
aldaros749
aldenjones
aldnjones
alec816
alex816
alexander_k1977
alobato06
alrivcamp
alrivcamp
anazingjt
anyenc
aoheaney
apeanuttoys
apeanuttoys
apsjr
asne40
atlooncall
atschirner
babyface15432
badbaby1972
bagged85
bakesman
bankbuddy
barnesk8
baseballcards5009
beathab
beep_beep_
beeson4
besthag
betterbidfast
bettrnbuck
bigant4542
biged2229
biged7779
bigmike0125
bigquess
bigskybill7
billsfossilcarsandparts
black*gts) 15
blancayyotambien
blodgett777
blue_eyed_redhead
bluebassethound
blunose2772
bluv5
bmer1828
bmf1833
boat74alfa
boatbabe36
bobbellford
bohyunseok
bri686
brianw87
brown2411
brynno1
bshophubby
bshophubby
bsmachinepump
bubjay21777
buck-rehhh
budel
budel
budmuf
bumskibum1987
calihoney02
candiaikens45011
carlinglight
carolinemaryshea
carymcc76
cassiem1210
catbic
caveman069
cds7814
cg_woodworking
cleary50
codgson
coleiro9540
const_man78
copcl
cox2000muse
cpa331
ctoudic
curve82
curve93
cworn
cyclecog
dakotacobalt1
dakotacobalt1
dalt57
debshood
deertrail98
dfd1
dfmengert
dishmie1411
distinctivejourneys
djdom111
dlanelangford
dlk953
dlparta
dmlindner
docdinky
dodgeguy2
donjtoto
donn9547
dookie892
dopey94970102
dowgint
downtoearthdental
dragonswar84
driverrobthedark
dsmitty123
dts2649
dubdlee20
dueete
duncangodfrey
dunewaters
dung_smith
e.w.pruvis007
eaglesilos
easybizman
ebee347
eddavilla
edjoan4
edsamaro
egwdoug
emak79
embrdyldy
emeraldsong
entertainyourself
equipmentjunky
ericm1980
erknight
ernieg2004
escalator66
evinrude1963
faysfinest
fishhead2842
fkada
flamingo9
flattopcody
floridaphil73
flynnut69
fordy64
foxierockwell
francescaelisa02
frankg32
franktiano
freewilly1956
frenchfreesia23
frodobaggins4
frogsbud
fsteil
fthdfrd
fttadm
funnycide
fuzylops
gamala54
garyjktrains
gasche9079
gattica777
geewhizbeav
gemz2rad
geo8rge44
george_p77
georgia2470
gg9416
gil148
gio911
giraffe59
gj3newell
glare282
glckidz
glen3295
glenoglen
glmoparman
glotfepr
gmg817
golfantick
gollipg
gollipg
goodies-online
googler69
gpb1705
greatfes
greenapples91
greensfarms
greg3ibg
grocky_fr
grp1983
gsipes1
gumptruck
gusstaff
gwitlock2308
gwmillerco
ha9362
hainesvette
happysweep
harasim2007
harat555
hardseteelandiron
harn8222
haroldehittyhat
harry200_1
hartopehtis
haybale98
healthyshoes128
heathmyster
helen6835
henburg21
henryettaknight
hesamess
heyjoe1702
high-diesel
hillsrusdog
hkatzen
hobbiesbdg
hoeycomadina
holacolombya
holierthanthou06
hop21t
hoprv
horseshoebuy
hrpete304
husspup
hyazdanparast
iabdulg
iamsore
ians4102
iblaine
idaboy1
iec33
iglidetours
ikelada
ilikeeverything2
ilive4cars7
ilivesparkysparky
imgman_200013aq
innstudio
iqman104
itchynfat
itchyrash
ivycamille
j_ferrara
j.ing
jackandruff
james-halpin
james10448
jandj9202003
jarrett518
jaspergixerboy
jaswebconsultant
jay_nuttz
jbscottdudley
jckhwr
jd260599
jdwcrna
jeffchief
jerusha85
jerusha85
jess_camb
jessalee83
jetek26
jillpallotta
jim8ujg
jimnlouise
jimpriest
jjsmudger
jk0055
jmt1011
jnmconnections
joe01655
joey0115
joface109
joface109
jonathanlocke84
jonchristoper75
josh_anderson185
joshuadam
josti
jpennstar
jptrupiano
jrtsgackerman
jrw1bulbeck
jsapp36
jtg976jtg
jxbuter
kalandr
kapenbrutzler
karamjit2004
karena6253
kareng9217
karenrig
karensky1000
karensmith786
karunafinancial
katedae
kbfis
keving82
kevinrcon
kevinselink
kilzbugz
kit124
kkeastbay
klingon_master
kromes0621
kynimo619
ladydemonsia
laser246
lazyln
ldmerriam
lee_vintagecoolstuff
libertybeads
light4less
live*life
logarithym
loriwebb777
louderthanlove3
lovemjh
lucienschallehn
lucy3182
m168yeh
madaboutyou1408
marcia9622
marcilea123
mardill2168
markaellis
markmadman11
masram3
matt81657
matto72
mavisaltin
maxlaptops
mediaman1961
metalcrafter
meuyarrow
mgshaft69
mickieboy65
mikesyz
miniemoe
misprint604
mj4900
mjhks
mmmmcn2
mobi_bristol
moheine
moht321
monica950
moseisely
moviemaster51
mrlittlemanlane
mrsacwright
msears1
musicmilligan
myron37
myttb
mytyoz
neuroticrn
nicholasbishop
nijxk99
nita50
nokarma4630
nps007jr
oakrderfn
only1jellybeanz
ornball
paalienman
padi2618
pajs60
pam3821
pam3821
partidaguy77
peachjr
pepsiman241
phyllis421
pikey408
pinkkey
pinkypunch
pizzants
pkchevyracer2
plug17
pman0516
pmi1495
poodlecracker
porchenaples
porkchop6756
postie246
powerpak
prem-recycle
prpldivr
punjabiochard
purpleronnie1969
pwarren54
pyromaniacs
qqu41p
quentin 790
ralphied
raptor597
ratautobody
rav_industries
ravenmaid3
raysel
rebos2
redflashsteve
rednismo350z
rh781218
robin37a
rodimusprimus
ropoon
ros3215
rrazor
rubylite
rudy230177
rugby-league11
runwaycollections
ryanmartin1988
sabako61
sanibel1600
sffdsaprky
shaf7886
sidlip
simplemindss
spudgunn39
sticman68
sucker4sales
sweetlime3
texaswranch
thebody55
themicks56
theperfectpick
theperfectpick
timberlandstreet
tintoyalley
tintoyc
titantelus
toddolie
tonnsracing
tracyfreeman
trocito1997
tzede619
uncledon07
virginia8232
vytotv
waitesanderson
warr2350
whatsurflavor
wilmingtonud
wonz11
wsn71
x_oarsist
x-alien
xeniphon
xrho
xtramp
y3kjon
yajitha
yarandy63
yardworks_inc
yeseron
youngest_of_4
yvonne8447
ztbhhb

Cheryl
 
 tomwiii
 
posted on September 26, 2007 03:05:25 PM
One of my HEROES is:

THE AMAZING RANDI ~ debunker of BS; slayer of non-scientific rubbish; the Anti-Uri!

http://www.randi.org/jr/2007-03/030907bomb.html

I have no qualms about clicking on his liberal use of TINY URL's throughout his site...

Since buying my first ATARI 400 in 1982 (then: Atari 800; TI; TRS-80; C64; Apple IIc; Gateway; Dell; Sony PC's), I've been connected to some kind of online service -- have never gotten a virus or any other malware...Good ole COMMON SENSE is the BEST DEFENSE...



 
 classicrock000
 
posted on September 26, 2007 03:32:49 PM
"theperfectpick"


When I read this name real quick,I thought it said something else









~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

If you look like your passport photo, you probably need the trip
 
 CBlev65252
 
posted on September 26, 2007 03:37:59 PM
Oh my, Classic! And, I know one of those. LOL! What a mind you have.

Interesting site, Tom. I've bookmarked it for further reading. I don't have time right now, but I'll get to it later.


Cheryl
 
 pixiamom
 
posted on September 26, 2007 08:31:14 PM
Tom, any site that labels Sylvia Brown a fraud is OK by me! I cannot stomach her - she is so blatantly cashing in on sorrow and the need for closure -- flippant and arrogant, riding Montel's coattails for all they're worth. Edited to add: I use tiny urls all the time, as a convenience. I do agree with Fluffy that anyone can give their link a Tiny Url name, so it doesn't signify that it is a safe site.
[ edited by pixiamom on Sep 26, 2007 08:52 PM ]
 
 tomwiii
 
posted on September 26, 2007 08:37:30 PM
Notice that she STILL has not accepted THE AMAZING RANDI'S million dollar challenge?

Gee? Wonder why?

As my roomie always opines: "A fool and his kibble are soon parted..."





 
 
<< previous topic post new topic post reply next topic >>

Jump to

All content © 1998-2026  Vendio all rights reserved. Vendio Services, Inc.™, Simply Powerful eCommerce, Smart Services for Smart Sellers, Buy Anywhere. Sell Anywhere. Start Here.™ and The Complete Auction Management Solution™ are trademarks of Vendio. Auction slogans and artwork are copyrights © of their respective owners. Vendio accepts no liability for the views or information presented here.

The Vendio free online store builder is easy to use and includes a free shopping cart to help you can get started in minutes!