<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: eBay was not hacked this weekend</title>
	<atom:link href="http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html/feed" rel="self" type="application/rss+xml" />
	<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html</link>
	<description>eBay &#38; ecommerce made easy</description>
	<lastBuildDate>Fri, 19 Mar 2010 23:12:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sue Bailey</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-27691</link>
		<dc:creator>Sue Bailey</dc:creator>
		<pubDate>Fri, 22 Feb 2008 10:12:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-27691</guid>
		<description>Thanks for your comments, Alex. I should just say that neither Chris nor myself work for eBay, eBay have no control over what we write here, and we write as we find. If that&#039;s too pro-eBay for some, well, so be it :-)</description>
		<content:encoded><![CDATA[<p>Thanks for your comments, Alex. I should just say that neither Chris nor myself work for eBay, eBay have no control over what we write here, and we write as we find. If that&#8217;s too pro-eBay for some, well, so be it <img src='http://tamebay.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Illner</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-27683</link>
		<dc:creator>Alex Illner</dc:creator>
		<pubDate>Fri, 22 Feb 2008 05:10:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-27683</guid>
		<description>It is refreshing to finally read some comments by people that seem to critically evaluate information from and about ebay rather than to just take it at face value. 

It does much to legitimize tamebay as a blog with a voice for all, rather than make it appear as an ebay mouth-piece to spread and affirm ebay corporate spin.</description>
		<content:encoded><![CDATA[<p>It is refreshing to finally read some comments by people that seem to critically evaluate information from and about ebay rather than to just take it at face value. </p>
<p>It does much to legitimize tamebay as a blog with a voice for all, rather than make it appear as an ebay mouth-piece to spread and affirm ebay corporate spin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firemeg</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-390</link>
		<dc:creator>Firemeg</dc:creator>
		<pubDate>Sun, 25 Feb 2007 14:58:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-390</guid>
		<description>Several hundred?  That number is up a bit.  The largest amount of listing that I&#039;ve seen this week from one scammer is 3500+ simultaneous auctions.  eBay eventually got around to removing them after several hours, but they stayed in search for much longer.
http://firemeg.blogspot.com</description>
		<content:encoded><![CDATA[<p>Several hundred?  That number is up a bit.  The largest amount of listing that I&#8217;ve seen this week from one scammer is 3500+ simultaneous auctions.  eBay eventually got around to removing them after several hours, but they stayed in search for much longer.<br />
<a href="http://firemeg.blogspot.com" rel="nofollow">http://firemeg.blogspot.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TameBay : Hacking, taunting and eBay security</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-388</link>
		<dc:creator>TameBay : Hacking, taunting and eBay security</dc:creator>
		<pubDate>Sat, 24 Feb 2007 13:22:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-388</guid>
		<description>[...] It&#8217;s been a fairly hectic week for eBay with stories flying around re security on the site. A few of them are on auctionbytes (twice), The Register (twice) and pretty much every other eBay related news site going. So it&#8217;s time to look at the facts. [...]</description>
		<content:encoded><![CDATA[<p>[...] It&#8217;s been a fairly hectic week for eBay with stories flying around re security on the site. A few of them are on auctionbytes (twice), The Register (twice) and pretty much every other eBay related news site going. So it&#8217;s time to look at the facts. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Helen</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-383</link>
		<dc:creator>Helen</dc:creator>
		<pubDate>Fri, 23 Feb 2007 11:04:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-383</guid>
		<description>After Durzy&#039;s admission yesterday that Vladuz HAS accessed eBay staff systems I assume we can all agree that the eBay statement you quoted in the original post â€œthat the eBay site has not been hacked or compromised in any wayâ€ was not entirely truthfull?

Now we can all rest easy since the eBay statement yesterday saying, in effect, &quot;the successful hack that happened ages ago that we were denying completely until now wasn&#039;t that bad really and nobody needs to worry.&quot;

Yea I trust &#039;em!</description>
		<content:encoded><![CDATA[<p>After Durzy&#8217;s admission yesterday that Vladuz HAS accessed eBay staff systems I assume we can all agree that the eBay statement you quoted in the original post â€œthat the eBay site has not been hacked or compromised in any wayâ€ was not entirely truthfull?</p>
<p>Now we can all rest easy since the eBay statement yesterday saying, in effect, &#8220;the successful hack that happened ages ago that we were denying completely until now wasn&#8217;t that bad really and nobody needs to worry.&#8221;</p>
<p>Yea I trust &#8216;em!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abby</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-368</link>
		<dc:creator>Abby</dc:creator>
		<pubDate>Wed, 21 Feb 2007 23:16:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-368</guid>
		<description>Someone is playing a game with ebay.

A conservative estimate would be that 600 unique sellers account were hi-jacked by this person and have been used so far.

Around 300 unique selling account were discovered hi-jacked on Sunday (18th Feb). Around 100 on Tuesday (20th Feb). Around 200 on Wed (19th Feb, today).

It is clear that the hi-jacker wanted to be caught, he made it simple and made sure that each new &#039;wave&#039; of hi-jacks were linked to previous ones.

I&#039;d assume there is a lot of profit to be made in hi-jacked accounts. Why &#039;waste&#039; (for want of a better word) this many accounts?

Because he is proving a point and playing a game.

How many more accounts does he have?

What will he do with the ones he does not want discovered?

Clearly large-scale. And ebay have been slow to respond.</description>
		<content:encoded><![CDATA[<p>Someone is playing a game with ebay.</p>
<p>A conservative estimate would be that 600 unique sellers account were hi-jacked by this person and have been used so far.</p>
<p>Around 300 unique selling account were discovered hi-jacked on Sunday (18th Feb). Around 100 on Tuesday (20th Feb). Around 200 on Wed (19th Feb, today).</p>
<p>It is clear that the hi-jacker wanted to be caught, he made it simple and made sure that each new &#8216;wave&#8217; of hi-jacks were linked to previous ones.</p>
<p>I&#8217;d assume there is a lot of profit to be made in hi-jacked accounts. Why &#8216;waste&#8217; (for want of a better word) this many accounts?</p>
<p>Because he is proving a point and playing a game.</p>
<p>How many more accounts does he have?</p>
<p>What will he do with the ones he does not want discovered?</p>
<p>Clearly large-scale. And ebay have been slow to respond.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TameBay : Britney Spears&#8217; hair not for sale on eBay</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-361</link>
		<dc:creator>TameBay : Britney Spears&#8217; hair not for sale on eBay</dc:creator>
		<pubDate>Wed, 21 Feb 2007 01:29:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-361</guid>
		<description>[...] Rumours have been flying around that eBay themselves spread the &#8220;Britney&#8217;s hair on eBay&#8221; story, to deflect interest in the news concerning compromised accounts over the weekend. We&#8217;re happy to confirm that the Britney hype did not originate from eBay&#8217;s PR team. [...]</description>
		<content:encoded><![CDATA[<p>[...] Rumours have been flying around that eBay themselves spread the &#8220;Britney&#8217;s hair on eBay&#8221; story, to deflect interest in the news concerning compromised accounts over the weekend. We&#8217;re happy to confirm that the Britney hype did not originate from eBay&#8217;s PR team. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DOC</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-357</link>
		<dc:creator>DOC</dc:creator>
		<pubDate>Tue, 20 Feb 2007 20:38:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-357</guid>
		<description>Yep.. Internal Redirects are a big problem on eBay! 

What eBay is not telling us is, There are a lot of internal redirects leading new and inexperienced site visitors off to look alike sites where &quot;no scam warnings are posted&quot; A newbie will fall into this cleverly baited trap in a new york minute! 

Review these articles on how it is being done.
http://www.ebaymotorssucks.com/iiwasp-com-2.htm
http://www.ebaymotorssucks.com/asrcs-com.htm

There are fake sign in links in eBay ME Pages as well. I have seen plenty of them! 

When the physhing is Internal On eBay&#039;s Site it&#039;s hard to blame it on the users opening emails and clicking on links! 

Another favorite is to list a car with a pornographic photo, clicking on the listing brings up a phony sign in page! 

This one had the link code messed up so who ever looked at it got mooned but good!
http://www.ebaymotorssucks.com/danield418.htm

eBay is making $$$ hand over fist.. They need to spend some of it policing and cleaning up their site!

BTW: Appologies for the Sensord Comment. Guess my previous posting was delayed because of the links.</description>
		<content:encoded><![CDATA[<p>Yep.. Internal Redirects are a big problem on eBay! </p>
<p>What eBay is not telling us is, There are a lot of internal redirects leading new and inexperienced site visitors off to look alike sites where &#8220;no scam warnings are posted&#8221; A newbie will fall into this cleverly baited trap in a new york minute! </p>
<p>Review these articles on how it is being done.<br />
<a href="http://www.ebaymotorssucks.com/iiwasp-com-2.htm" rel="nofollow">http://www.ebaymotorssucks.com/iiwasp-com-2.htm</a><br />
<a href="http://www.ebaymotorssucks.com/asrcs-com.htm" rel="nofollow">http://www.ebaymotorssucks.com/asrcs-com.htm</a></p>
<p>There are fake sign in links in eBay ME Pages as well. I have seen plenty of them! </p>
<p>When the physhing is Internal On eBay&#8217;s Site it&#8217;s hard to blame it on the users opening emails and clicking on links! </p>
<p>Another favorite is to list a car with a pornographic photo, clicking on the listing brings up a phony sign in page! </p>
<p>This one had the link code messed up so who ever looked at it got mooned but good!<br />
<a href="http://www.ebaymotorssucks.com/danield418.htm" rel="nofollow">http://www.ebaymotorssucks.com/danield418.htm</a></p>
<p>eBay is making $$$ hand over fist.. They need to spend some of it policing and cleaning up their site!</p>
<p>BTW: Appologies for the Sensord Comment. Guess my previous posting was delayed because of the links.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dimes</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-356</link>
		<dc:creator>dimes</dc:creator>
		<pubDate>Tue, 20 Feb 2007 19:40:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-356</guid>
		<description>eBay uses semantics to hide its site security problems.

However it defines the word &quot;hacked&quot;, it is apparently excluding the social engineering scams that use embedded javascript within eBay item listings to steal personal data from eBay customers.  

1.  Users already logged in to eBay are asked to login again when they land on poisoned eBay listings.

2.  These users did not respond to phishing emails, and may never have received a single spoof email.

3.  The users dutifully login again on what appears to them to be a legitimate eBay login screen. 

4.  The login screen isn&#039;t eBay&#039;s at all, despite the fact that it was presented to the user from a listing screen within eBay.  

5.  Because the users are returned to the real eBay site after giving away their ID/passwords, they are unaware they&#039;ve just been robbed.

6.  The users later find out, to their dismay, that their eBay accounts (and possibly credit card data and/or paypal accounts) have been hijacked by criminals who got their info while the users were browsing on eBay.


Since this method of identity theft does not depend on eBay being &quot;hacked&quot;, perhaps a new word is needed to define the problem - maybe &quot;scamBayed&quot;?</description>
		<content:encoded><![CDATA[<p>eBay uses semantics to hide its site security problems.</p>
<p>However it defines the word &#8220;hacked&#8221;, it is apparently excluding the social engineering scams that use embedded javascript within eBay item listings to steal personal data from eBay customers.  </p>
<p>1.  Users already logged in to eBay are asked to login again when they land on poisoned eBay listings.</p>
<p>2.  These users did not respond to phishing emails, and may never have received a single spoof email.</p>
<p>3.  The users dutifully login again on what appears to them to be a legitimate eBay login screen. </p>
<p>4.  The login screen isn&#8217;t eBay&#8217;s at all, despite the fact that it was presented to the user from a listing screen within eBay.  </p>
<p>5.  Because the users are returned to the real eBay site after giving away their ID/passwords, they are unaware they&#8217;ve just been robbed.</p>
<p>6.  The users later find out, to their dismay, that their eBay accounts (and possibly credit card data and/or paypal accounts) have been hijacked by criminals who got their info while the users were browsing on eBay.</p>
<p>Since this method of identity theft does not depend on eBay being &#8220;hacked&#8221;, perhaps a new word is needed to define the problem &#8211; maybe &#8220;scamBayed&#8221;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firemeg</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-347</link>
		<dc:creator>Firemeg</dc:creator>
		<pubDate>Tue, 20 Feb 2007 06:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-347</guid>
		<description>This may have been an instance of a well orchestrated scam that got user info from phishing...or not.  We will never know.  Taking eBay&#039;s word for it is beyond ridiculous.  An eBay spokesperson said that the Prosperpoint breach was a result of phishing which was a blatant lie.  Why should we trust them in this case?</description>
		<content:encoded><![CDATA[<p>This may have been an instance of a well orchestrated scam that got user info from phishing&#8230;or not.  We will never know.  Taking eBay&#8217;s word for it is beyond ridiculous.  An eBay spokesperson said that the Prosperpoint breach was a result of phishing which was a blatant lie.  Why should we trust them in this case?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DOC</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-345</link>
		<dc:creator>DOC</dc:creator>
		<pubDate>Tue, 20 Feb 2007 02:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-345</guid>
		<description>Nice Sensored Blog You Have Here..  That&#039;s OK..  eBay will have it&#039;s day sooner or later.. It&#039;s only a matter of time!

DOC</description>
		<content:encoded><![CDATA[<p>Nice Sensored Blog You Have Here..  That&#8217;s OK..  eBay will have it&#8217;s day sooner or later.. It&#8217;s only a matter of time!</p>
<p>DOC</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sunny martin</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-344</link>
		<dc:creator>sunny martin</dc:creator>
		<pubDate>Tue, 20 Feb 2007 01:05:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-344</guid>
		<description>I agree with the poster above. It sounds to me that it was a phishing exercise. It wouldnt be that difficult to achieve hundreds of hits through eBay because of the high numbers of users.

I am not a huge fan of eBay as I stopped seller their a while back but I think if people bothered to visit their help pages they would find loads of info on how to minimise the chances of being caught out like this.

A lot of people dont protect their pcs from attack but they wouldnt leave their front doors open would they? We should be as concerned about pc security as we are about our household possessions.</description>
		<content:encoded><![CDATA[<p>I agree with the poster above. It sounds to me that it was a phishing exercise. It wouldnt be that difficult to achieve hundreds of hits through eBay because of the high numbers of users.</p>
<p>I am not a huge fan of eBay as I stopped seller their a while back but I think if people bothered to visit their help pages they would find loads of info on how to minimise the chances of being caught out like this.</p>
<p>A lot of people dont protect their pcs from attack but they wouldnt leave their front doors open would they? We should be as concerned about pc security as we are about our household possessions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Huddersfield_lass</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-343</link>
		<dc:creator>Huddersfield_lass</dc:creator>
		<pubDate>Tue, 20 Feb 2007 00:30:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-343</guid>
		<description>I was one of the people involved in trying to warn sellers about this yesterday.  In response to Eddie - these were very high value items and most sellers only had at most a  couple of items listed.  Even those who did only had a few of their listings compromised, not all of them.   The number of listings in this case therefore is, in effect much the same thing as the number of accounts - nearly all the ones I saw were one  listing to one account.

In my opinion this was a phishing exercise, but quite a sophisticated one, which did not involve clicking on, or responding to anything in emails.

I think the most sensible thing anyone who is worried about this, and who has listed a high value item recently (even or especially if it has finished and you are not regularly checking ebay) is to check your pc is free from keystroke loggers and change all your ebay and paypal passwords.</description>
		<content:encoded><![CDATA[<p>I was one of the people involved in trying to warn sellers about this yesterday.  In response to Eddie &#8211; these were very high value items and most sellers only had at most a  couple of items listed.  Even those who did only had a few of their listings compromised, not all of them.   The number of listings in this case therefore is, in effect much the same thing as the number of accounts &#8211; nearly all the ones I saw were one  listing to one account.</p>
<p>In my opinion this was a phishing exercise, but quite a sophisticated one, which did not involve clicking on, or responding to anything in emails.</p>
<p>I think the most sensible thing anyone who is worried about this, and who has listed a high value item recently (even or especially if it has finished and you are not regularly checking ebay) is to check your pc is free from keystroke loggers and change all your ebay and paypal passwords.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DOC</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-342</link>
		<dc:creator>DOC</dc:creator>
		<pubDate>Mon, 19 Feb 2007 22:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-342</guid>
		<description>Uh Huh..

Sure they were not hacked.. Like you expect a sleazy bunch like eBay to tell you the truth??

Look over the recent hacked pages we have captured, and the severity of it.  Then tell us it ain&#039;t so..

http://www.ebaymotorssucks.com
http://www.ebaymotorssucks.com/rflello.htm</description>
		<content:encoded><![CDATA[<p>Uh Huh..</p>
<p>Sure they were not hacked.. Like you expect a sleazy bunch like eBay to tell you the truth??</p>
<p>Look over the recent hacked pages we have captured, and the severity of it.  Then tell us it ain&#8217;t so..</p>
<p><a href="http://www.ebaymotorssucks.com" rel="nofollow">http://www.ebaymotorssucks.com</a><br />
<a href="http://www.ebaymotorssucks.com/rflello.htm" rel="nofollow">http://www.ebaymotorssucks.com/rflello.htm</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eddie</title>
		<link>http://tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-340</link>
		<dc:creator>Eddie</dc:creator>
		<pubDate>Mon, 19 Feb 2007 20:49:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.tamebay.com/2007/02/ebay-was-not-hacked-this-weekend.html#comment-340</guid>
		<description>Was it several hundred accounts though, or did Chinese Whispers take place ?

I &#039;watched&#039; the events unfold, and at its peak there were reports of several hundred auctions (not accounts), some members were frustrated at the ability to only report 10 auctions at a time.

Several hundred accounts would indicate many more than several hundred auctions, this was not the case.</description>
		<content:encoded><![CDATA[<p>Was it several hundred accounts though, or did Chinese Whispers take place ?</p>
<p>I &#8216;watched&#8217; the events unfold, and at its peak there were reports of several hundred auctions (not accounts), some members were frustrated at the ability to only report 10 auctions at a time.</p>
<p>Several hundred accounts would indicate many more than several hundred auctions, this was not the case.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
