Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

ACK!!! What virus is this?!? Ebay wants an ATM PIN?!?
Ebay Motors ^ | Saturday, March 6, 2010

Posted on 03/06/2010 1:02:42 PM PST by Special Agent Anthony DiNozzo

I am trying to log into my ebay account, and I am being asked for all sorts of personal information, to include an ATM PIN.
 
I am going to the correct URL [the browser shows it as living at "ebay.com"], so this isn't "phishing".
 
Ergo one of the following must be true:

1) Either Ebay has been hacked, or
 
2) I have a very sophisticated virus on my machine which is capable of altering my TCP/IP stack and redirecting my DNS lookups.


TOPICS: Crime/Corruption; Miscellaneous; News/Current Events; Technical
KEYWORDS: chat; vanity
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 121-134 next last
To: webschooner

That part is or can be. eBay allows HTTPS login.


21 posted on 03/06/2010 1:07:52 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: webschooner

https I believe means the site is secure.


22 posted on 03/06/2010 1:07:57 PM PST by fatnotlazy
[ Post Reply | Private Reply | To 11 | View Replies]

To: Special Agent Anthony DiNozzo

I'd rather take my chances with the 'Free Candy' van than put my info. on that form.

23 posted on 03/06/2010 1:08:02 PM PST by BookmanTheJanitor
[ Post Reply | Private Reply | To 1 | View Replies]

To: Special Agent Anthony DiNozzo

I’m sure that I have seen this before for other vendors, such as Chase. ALL financial institutions will tell you that they will NOT ask you to enter private information like this.


24 posted on 03/06/2010 1:08:29 PM PST by DallasDeb (USAFA '06 Mom)
[ Post Reply | Private Reply | To 1 | View Replies]

To: DallasDeb

Bad news, chances are that they all will. This isn’t phishing, this is a hijack.


25 posted on 03/06/2010 1:08:30 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Special Agent Anthony DiNozzo

You have malware that redirecting your DNS lookups. Go to http://66.211.160.87 and see if you get the same thing.


26 posted on 03/06/2010 1:08:42 PM PST by Smogger
[ Post Reply | Private Reply | To 1 | View Replies]

To: Special Agent Anthony DiNozzo

The URL is long, have you tried just going to ebay.com and logging in if possible, before you go to ebaymotors?


27 posted on 03/06/2010 1:08:46 PM PST by wita
[ Post Reply | Private Reply | To 2 | View Replies]

To: webschooner
Also, I notice there is an “s” after http in the url. That isn’t normal is it?
 
The "s" is for "secure", as in "Secure Sockets Layer" - it means the interaction is supposed to be encrypted.
 
What worries me is that my browser thinks that I am at "ebay.com", so this isn't phishing.
 
One other possibility is that my ISP's DNS servers have been hacked, and I am being re-directed to this page as a resulte.
 
Maybe I will give my ISP a call.
28 posted on 03/06/2010 1:09:11 PM PST by Special Agent Anthony DiNozzo (SCORE!!! And in Paris, no less. MOO HA HA HA HA HA HA!!!!!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Special Agent Anthony DiNozzo

No one should ask for your social security number or your ATM pin.


29 posted on 03/06/2010 1:09:49 PM PST by fatnotlazy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Special Agent Anthony DiNozzo

Also, why are you still using Internet Exploiter? There are so many security holes in that some major sites are beginning to refuse service to IE users for fear of security breach. Suggest you use Firefox or Chrome or any of the other browsers.


30 posted on 03/06/2010 1:09:51 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Special Agent Anthony DiNozzo

Just reading the paragraph at the top should tell you it is a scam. It is not phrased right.


31 posted on 03/06/2010 1:10:19 PM PST by Red_Devil 232 (VietVet - USMC All Ready On The Right? All Ready On The Left? All Ready On The Firing Line!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Special Agent Anthony DiNozzo

This is not an ISP problem. This is a problem with YOUR computer.


32 posted on 03/06/2010 1:10:43 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 28 | View Replies]

To: webschooner

The “s” in the https indicates it is supposed to be an SSL (secure socket layer) site. However, it’s easy to create a webpage that never actually gets published to the real web. Phishers will create a web page and then send you the link to their private webpages. Check out the email address that you received. Betcha it looks nothin’ like an ebay address.


33 posted on 03/06/2010 1:11:04 PM PST by DallasDeb (USAFA '06 Mom)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Special Agent Anthony DiNozzo

Just reading the paragraph at the top should tell you it is a scam. It is not phrased right.


34 posted on 03/06/2010 1:11:10 PM PST by Red_Devil 232 (VietVet - USMC All Ready On The Right? All Ready On The Left? All Ready On The Firing Line!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Smogger

That will just redirect you, and since his computer’s DNS files have been essentially hijacked, it’ll take him back to the fake site.


35 posted on 03/06/2010 1:11:57 PM PST by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: Spktyr

If it’s his DNS lookups that are being hijacked then the ip address should still work.


36 posted on 03/06/2010 1:12:56 PM PST by Smogger
[ Post Reply | Private Reply | To 35 | View Replies]

To: Special Agent Anthony DiNozzo
I am going to the correct URL [the browser shows it as living at "ebay.com"], so this isn't "phishing".

Are you sure there is not a "hidden window", that is one with no browser around it, overlaying the apparent ebay window.

I can see no reason why Ebay would need your ATM pin. Giving them the CVV2 ensures them that you actually have the card, and not just the card number.

Depending on your browser you might try placing the cursor somewhere on the questionable page, right clicking and selecting "properties". in IE you can look at certificates, in Firefox you right click and select "view page info", which also allows you to look at the security info and other stuff.

37 posted on 03/06/2010 1:13:13 PM PST by El Gato ("The second amendment is the reset button of the US constitution"-Doug McKay)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Special Agent Anthony DiNozzo

That’s weird. The web address shows https:// but no padlock or anything else to show it is a secure website. Some kind of browser hijack perhaps.

Download hijack this! from Trend Micro and see what it tells you.


38 posted on 03/06/2010 1:13:55 PM PST by smokingfrog (You can't ignore your boss and expect to keep your job... WWW.filipthishouse2010.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Disturbin

note more instead of much—this is foreign.


39 posted on 03/06/2010 1:14:22 PM PST by richardtavor
[ Post Reply | Private Reply | To 6 | View Replies]

To: 2nd amendment mama

Ping!


40 posted on 03/06/2010 1:14:26 PM PST by basil (It's time to rid the country of "Gun Free Zones" aka "Killing Fields")
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 121-134 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson