![]()
My friend called me last night and explained he recently had two security problems — some malware on his computer and a stolen eBay account. I figured the two were connected, but it’s interesting to understand how.
His eBay account had been compromised and someone loaded some fraudulent auctions under his account — just in time for the holidays. Obviously the malware found on the machine had compromised his password. The question was, how did the malware get there?
The attacker had used an interesting way to deliver the malware onto the target machine and thereby compromise that specific eBay account:
- Find an eBay account to target, preferably an eBay account with good standing.
- Send the "mark" account a question using the built-in eBay messaging system.
Hello ,
Please confirm if your item is the same like this:
http: //www.evilwebsite.com/item.html
i want to BUY your item ! i am very interested !
Tell me the Final Price with all the taxes.
Let me know asap ,
thank you
- The message includes a URL to a hostile website. The website contains a 0-day attack for IE. The payload is a keylogger.
- The attacker obtains the eBay password from the mark account and uses that account (and it’s good eBay standing) to create fraudulent auction items.
My friend found the fraudulent items quickly, removed them, and changed his eBay password (from a known clean system). At this point, he thinks he has resolved the problem and will be wary of any new messages coming into his account — especially if they contain URLs.

i just recieved the ebay attacker today..i havent responded to him yet…i thought it was weird that he put the url.code in the message…thanks for your heads up..i might have checked the url..
shay
The hacking / phishing continues.
My account was crapped on last week.
It is now “inactive” – a result of ebay
shutting it down.
ebay needs to find and fix this security hole.
THIS SUCKS BIG TIME.
jeffrey
I personally use Kaspersky Anti-virus 6.0.
I vote kaspersky .
the info is useful but you will have to tel indetail hte usage and controlling of ant-spam as like we do in the program control
http://pornoneskimo.info x
I was trying to reach website but I found another one almost the name is just like you so please take care as this my misguide your customers & business
I would liake to know why Z A sends me the following nessage:
instalation off update package failed:
“0-updating D#70.1.3.11.0