Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-27-2004 11:43 AM
Dear eBay user,
During our regular update and verification of the accounts we could not verify your current information. Either your information has changed or it is incomplete.
As a result your access to your eBay account will be restricted.
According to our site policy you will have to confirm that you are the real owner of the eBay account by completing the following form within 24h or else your account will be suspended without the right to register again with eBay.
Please use the link below to complete this verification:
http://scgi.ebay.com/saw-cgi/ebayISAPI.dll?ConfirmRegisterInformation
Thank you!
eBay Customer Support
- « Previous
-
- 1
- 2
- Next »
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-29-2004 06:39 PM
So what happens when I click on the SSL(as I just did)?....When I was on the secure login page it had the https, but once logged in, it goes back to http. I would think that clearly it is now insecure, but does it matter, since I am not using my password on those pages?
I would really like to understand all this better.
Jaqui
Gem Am I
The spiritual journey is individual, highly personal. It can't be organized or regulated. It isn't true that everyone should follow one path. Listen to your own truth. -Ram Dass
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-29-2004 07:05 PM
We had someone trying to access our server, rentlentlessly for about 6-days earlier this year and when we traced it back to the source it was one of eBay's servers in San Jose.
While we knew that it wasnt eBay trying to gain access to our server, it was someone that had gotten into eBay's system and was using it as one of their cloaks for what-ever they wanted to use it for, from spamming to obtaining secure information on members etc.
We immediately emailed eBay at PS Customer support and spoof@ebay and followed up several more times however we NEVER rec'd any response so we felt we were on our own to disway this guy from getting at us.
I have learned directly from eBay that none of my, perhaps 10 emails sent eBay from February through April were ever recd and there are others on this board who complained of the same problem when reporting things that seemed to fall on deaf ears.
Given what you have told us, it appears that part of eBay's system itself may have been hijacked from December through ...? a problem more serious than what you suspected from your incident.
When I consider that my emails to them were through the PS link on one of the preceeding pages before getting into this forum and your belief that the people got your userid and password by way of signing onto this forum, it seems very likely that the problem may in fact center around someone hacking into the eBay system and having some control over it for several months unknown to eBay.
I have spoken to an eBay rep on a couple of recent ocassions and was assured that their technical people were looking into the problems about my emails not reaching them by checking the links however I have not heard back and I suspect the reason may be to protect themselves from a massive loss of members, both buyers and sellers from lack of confidence should the truth be that outside people had control of their system.
I hope that isnt the case but given our experience and yours, it seems highly possible.
Malcolm
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-29-2004 07:28 PM
Jaqui
Gem Am I
The spiritual journey is individual, highly personal. It can't be organized or regulated. It isn't true that everyone should follow one path. Listen to your own truth. -Ram Dass
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 12:38 AM
Actually, the 'leakiest' part of these boards is the login itself...because Canadian PowerSellers have two choices (unlike the Americans who appear to have only the one, fully secured). If you're logging in via the top left link you're secure; if you're logging in via the icon link beneath the U.S. board you will be unsecured. And although I'm not absolutely sure about this, I believe that this unsecured PowerSeller login is a static page (consistently same address) on eBay's server(s). So forgetting about the possibility of a more elaborate personal hack for a moment (presumably logging in unsecurely leaves an unencrypted 'cookie' on your hard drive), it would be very easy for even a 'lite' (read-only) hack of eBay's unsecure servers to identify the unsecured login file. To be on the safe side, always login via the left link, not the right.
Malcom, although I'm now rather paranoid about the security issue here, I'm not that paranoid...at least not yet. However, it may interest you to know that after one of the Security pros had analyzed my system and not discovered any keyloggers or trojan redirects, his first thought was that somehow the unsecured servers of eBay had been hacked, and that this was how the miscreants retrieved the unencrypted file of unsecured PowerSeller logins. We'll never know for sure because eBay would never admit this, but it's at least as plausible as a local system hack.
Let's put it this way...before any of this happened, I experenced no security 'events'--none whatsoever--whistle clean system(s) and 'Net-based work for years--and since I've begun rigorously avoiding unsecure logins throughout eBay's site and these boards, as well as jettisoning the toolbar...well...once again...nothing...nada...nyet.
Entirely circumstantial evidence, but I truly believe that if you watch out for the first 3 potential hazards mentioned in my previous post (Defualt unsecure, PowerSeller unsecure, and Toolbar), you will have nothing to fear* here.
* ...except of course, those random, mysterious, somewhat dopey policy and interface changes.
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 12:21 PM
I log on via a bookmark that I placed on my desktop eons ago because I couldn't find the url link to the Canadian Powersellers board via any descriptive web page, etc.
Maybe you could post the url that you log in securely from for the benefit of others.
Thanks
Jeff
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 01:01 PM
To access the Power Seller Portal, you click the link at the top titled "Site Map". Under the main caption "SERVICES" you will see the sub title "Power Sellers" and that link will take you to the Power Seller Portal where you can access the discussion boards, Power Seller support phone number and links and other related topics.
Malcolm
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 03:22 PM
To the left is the secure "PowerSeller Discussion Board" link. To the right, underneath the "U.S. PowerSeller Discussion Boards" icon & link, there is a "Discuss With Canadian PowerSellers" icon & link, which directs you to an unsecure 'http' page, not a secure 'https' page.
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 05:01 PM
I had noticed that there was not "https://" when I signed in to the Canadian board and I was concerned about it. Thanks doc_scribe for the heads-up on how to sign in to this board securely!
Glenda
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 05:30 PM
take care,
Jaqui
Gem Am I
The spiritual journey is individual, highly personal. It can't be organized or regulated. It isn't true that everyone should follow one path. Listen to your own truth. -Ram Dass
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 05:36 PM
When I click on doc's url above the only thing I see to the left is a register button.
Jeff
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 05:46 PM
Try this link...from this page about 2/3 up the screen on the left it says
"Looking to find out more about our PowerSellers Program? Click on any of these links.
PowerSeller Discussion Board"
Here is the link:
http://cgi1.ebay.ca/aw-cgi/eBayISAPI.dll?PowerSellerSignin&pass=9szpAvIu/3b5w4TRtaAqr1&userid=gem-n-i-gemstonz
I believe that is the secure link he is referring to(unless I am also mistaken).
Jaqui
Gem Am I
The spiritual journey is individual, highly personal. It can't be organized or regulated. It isn't true that everyone should follow one path. Listen to your own truth. -Ram Dass
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 06:38 PM
http://servlet.ebay.ca/ForumLoginPage?from-page=http%3A%2F%2Fforums.ebay.ca%2Fentry.jsp%3Fredirect%3D%252Fforum.jsp%253Fforum%253D44
If you logging in via that screen, you're not doing so securely. Check the Note: "By signing in, you'll get a temporary "cookie" which will remember your User ID while your browser is open. If you close your browser, then the cookie will expire." That alone gives it away...cookies are text-based files saved on your hard drive and not encrypted.
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 08:23 PM
Jeff
Re: Another fake notice
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-30-2004 11:28 PM
BTW, this appears to be true for My eBay as well. Even after logging in securely, you still end up on an unsecured webpage.
* From a routine practical standpoint, no big deal, although theoretically anyone logged into eBay given the URL for this page could read it whether or not they are actually a PowerSeller. I have never tested this, so there may be some other stop mechanism in place that I am unaware of, but given the ease with which we post links to other areas of this site, including boards across *.com, *.ca, and *.uk etc., I rather doubt it.

- « Previous
-
- 1
- 2
- Next »
- « Previous
-
- 1
- 2
- Next »