Hackers attack eBay accounts

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Someone other than Gloria Geary had access to the artist's eBay account last week. Using Geary's user ID, the person set up an auction for an Intel Pentium computer chip. Not only that, but the person changed Geary's password so she could no longer access her own account -- or cancel the bogus auction. Geary, who discovered the auction on Friday, was able to convince eBay to pull down the auction over the weekend, but not before suffering through a stressful day of worrying about how the auction would affect her legitimate listings. "I felt totally violated. I was shaking," Geary said. "It's appalling the ease at which they totally took over my account." Geary is only the latest victim of an increasingly popular scam on eBay. Since January, the company has received a growing number of complaints from people such as Geary who say their accounts have been taken over and used to set up fraudulent auctions. The scam artists make a quick buck, then leave the legitimate eBay users to deal with the furor from bilked bidders. Although the company has thus far seen only a relatively small number of cases -- numbering in the "low triple digits" -- the new scam is a "concern" for eBay, company spokesman Kevin Pursglove said. "Even if it happened to just one user, that user had a fairly bad user experience," Pursglove said. "We need to find ways of preventing it." Security experts say eBay needs to work fast to find a fix, because this combination of hacking and identity theft are the wave of the future. "We work with the people at eBay. They know they have a real problem," said Lee Curtis, managing director of high-tech investigations at Kroll, which specialises in security. "If they lose the confidence of their customer base, they're out of business." The percentage of auctions that end in a confirmed case of fraud on eBay is less than one one-hundredth of 1 percent, the company said. But the problem has been a persistent thorn in the side of the company and of the online auction industry as a whole. Last year, consumers reported some 20,000 fraud complaints concerning online auctions to the Federal Trade Commission, second only to complaints about identity theft. Some complaints involved sellers who simply never sent the goods they auctioned. Other complaints have involved more elaborate schemes, such as the sale of a fake Richard Diebenkorn painting on eBay in 2000. But the latest attempts to defraud bidders seem to be using more sophisticated methods. Instead of establishing their own accounts on eBay, many scam artists are using a so-called dictionary attack to break into reputable sellers' accounts. A time-tested technique, a dictionary attack involves an automated program, or "bot," that tries to find a password for a known user ID by drawing on a list of common passwords and a dictionary of words. Once they have access to the seller's account, the scam artists use the legitimate seller's reputation to draw bids on their fraudulent auctions. Kevin Jarrett had his account broken into last week. The person who broke into it listed four auctions for digital cameras and changed the password for Jarrett's account on Billpoint, eBay's proprietary payment service. Jarrett, who found out about the auctions when he received an email from a bidder on one of the bogus auctions, was able to minimise the damage by getting eBay to shut down the auctions before they ended. But as a result, he's since cancelled a bank account and credit card that were linked to his Billpoint account. Jarrett said it was likely his status as a trusted eBay seller that attracted hackers to his account. "It never occurred to me that 142 feedback points on eBay is a very valuable item," he said. "It means that you're trusted." Feedback points allow members to judge the trustworthiness of other members. In addition to providing written comments about members, eBay assigns a feedback rating based on the number of positive comments a member has received minus the number of negative comments. Password patrol
The usual way of preventing a dictionary attack is for a Web site to lock an account after there have been several incorrect password entries. Typically, Web sites require customers whose accounts are locked to call their customer service departments and verify their right to access the account by giving information such as their social security number or mother's maiden name. While eBay is exploring the possibility of locking accounts after repeated failed log-in attempts, it doesn't do so currently, Pursglove said. EBay is worried that unscrupulous bidders might try to sabotage their competitors by locking out their accounts or that legitimate users may find themselves unable to log in after an attempted dictionary attack, he said. "It's one of the proposals that we're considering," he said. "We're trying to figure out a way that we can adopt it without disclosing how the process works." In the meantime, the company is recommending that customers check their accounts frequently and change their passwords to ones that are more difficult to guess. The company is also recommending that bidders check sellers' selling history to look for anything anomalous such as a sudden upswing in listings. Jarrett, an information technology consultant, said he was probably too lax about his passwords, using ones that were too easy to guess. But he said that eBay needs to do a better job of protecting accounts. "I find this vulnerability to be unacceptable," he said. "As a paying customer, I have the expectation that my information will be held securely." EBay's reluctance to put in place a lockout system may have more to do with it wanting to save money on customer service than anything else, said Rosalinda Baldwin, editor of The Auction Guild, a newsletter covering the online auction industry. If the company put in place a lockout system, it would have to provide people with instant customer support over the telephone so they could unlock their accounts. Currently, eBay doesn't list a customer support phone number on its site, instead directing all inquiries to email or to lists of frequently asked questions. Locking out accounts "would make sense," Baldwin said. "But they would have to hire some people to man a phone 24-7. That's not what they want to use our dollars for." That eBay is not taking a more active role in protecting customer accounts by implementing a lockout system indicates that the company is putting business concerns ahead of security concerns, said Richard Power, editorial director of the Computer Security Institute. The problem is that e-commerce has never fully dealt with security issues, and those issues are likely to become more acute in the near future, Power said. Criminal gangs and organised crime, for instance, are only now getting up to speed on the Internet and could prove a tough challenge to vulnerable e-commerce sites, he said. "I think eBay's foolish," Power said. "The thing that holds back people from buying on the Internet more than anything is insecurity."
For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section. Have your say instantly, and see what others have said. Go to the Security forum. Let the editors know what you think in the Mailroom.

Talkback

Hey,

I was suckered into a laptop deal for $1250 through what appeared to be a reputable ebay account. He posted the auction, it was then canceled. I contacted him outside of it and agreed to a price. I sent him the money through western union under my name as the receiver so he couldn't touch the money until I got the package and changed the receivers name. He got a fake id under my name and stole the money. The thing is, the ebay name he posed under is extremely reputable and I believe it was hacked into like this article describes. I have no where to turn to. I am only 18 and have lost what I worked for the entire summer. ($1250). Please let me know if you know of anyone I can contact for a lawsuit or anyway I can get my money back. Waiting eagerly,
Jason

via Facebook 10 August, 2003 05:44
Reply

Mr. Pursglove has simply mastered the art of deception. In my personal experience and others I have found that about 5% of all auctions end in some sort of fraud, whether it comes to getting stiffed completely, or getting defrauded by misleading ads, or counterfeit goods. Mr Pursglove is just confirming that ebay does not INVESTIGATE but 1/100 of 1% of their fraud reports. He speaks the truth, while conveying a LIE. I was recently banned from ebay for contacting bidders on fraudulent auctions, and posting facts on my ebay "about me" page which ebay censored. Ebay simply does not investigate fraud, then reports this fact. Too bad ebay has such a monopoly on online auctions. I think the government should make ebay answer up. The big fraud seems to be this cover up Mr Purseglove.

via Facebook 11 November, 2003 09:39
Reply

You can go to the following address and file a report:

http://www.ifccfbi.gov/complaint/

via Facebook 26 February, 2004 01:04
Reply

I was a victim yesterday when I learned someone has listed a laptop for sale ($950.00)
using my account information. My ebay account was suspended, between yesterday and today, I am still trying to regain my account.

via Facebook 14 September, 2004 17:39
Reply

I've just been suspended from ebay because someone unauthorized has tried to use my account. It's good that ebay recognizes this, and close the account for the hacker. But what I don't understand is, why can't ebay let me get back into my account, change my password and continue with my business? I am losing lots of money from sales! If a hacker can get in to my account, how come they wont let ME get back in to my account faster, I mean, I can PROVE to them that I am ME!

via Facebook 3 December, 2004 21:09
Reply

She isn't the only one. It just happened to my family and I.The hackers sent a fraudulent email from eBay, and now they have my SSN, Bank numbers and so much more. It is becoming dangerous to even put anything online these days. It's horrible how people can take over someone's life just by a single email. If you would like more of this story please feel free to email me. I would be glad to tell you.

via Facebook 3 January, 2005 03:11
Reply

HAHA FUNNY

via Facebook 8 November, 2005 04:39
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

51 minutes ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 hour ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 hour ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

3 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

4 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

10 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

12 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

12 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

14 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

14 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

15 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

16 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

16 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

16 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

17 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

17 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

17 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

17 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

20 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

21 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs