FYI - ebay hacked again ... not good for business

copied article from BBC News (business news)

 

17 September 2014 Last updated at 14:32

eBay redirect attack puts buyers' credentials at risk

 

EBay has been compromised so that people who clicked on some of its links were automatically diverted to a site designed to steal their credentials. The spoof site had been set up to look like the online marketplace's welcome page.

The US firm was alerted to the hack on Wednesday night but removed the listings only after a follow-up call from the BBC more than 12 hours later. One security expert said he was surprised by the length of time taken.

"EBay is a large company and it should have a 24/7 response team to deal with this - and this case is unambiguously bad," said Dr Steven Murdoch from University College London's Information Security Research Group.

The security researcher was able to analyse the listing involved before eBay removed it.

He said that the technique used was known as a cross-site scripting (XSS) attack.

It involved the attackers placing malicious Javascript code within product listing pages. This code in turn automatically redirected affected users through a series of other websites, so that they ended up at the page asking for their eBay log-in and password.

Users only had to click the original listing to have their browser hijacked.

"The websites the user is being redirected to are almost certainly compromised by the attacker to hide his or her traces," Dr Murdoch explained. (read fully story at BBC)

Message 1 of 9
Latest reply
8 REPLIES 8

FYI - ebay hacked again ... not good for business

Great.Smiley Sad

Message 2 of 9
Latest reply

FYI - ebay hacked again ... not good for business

From Wikipedia - "Reportedly, eBay was simply a side hobby for Omidyar until his Internet service provider informed him he would need to upgrade to a business account due to the high volume of traffic to his website."

 

It's been upgraded ever since.

 

Why any legitimate business would let users embed any sort of scripting code into their own pages is just the dumbest thing ever, especially in this day and age.

Message 3 of 9
Latest reply

FYI - ebay hacked again ... not good for business

Lol no surprise it was a weak ago how some ebay CS explained me how the data are secure on ebay .... Lol same like in may when someone hack 157 milions of account and downloaded all personal datat of all buyer and seller. Perfect security like in India ... 😄

Message 4 of 9
Latest reply

FYI - ebay hacked again ... not good for business

When I tried to log back into the forums about 10 minutes ago, instead of the page just refreshing and logging me in, it took me to an unsecured eBay home page. It had the https crossed out. I clicked back and tried to log in again and was successful. I haven't searched any listings this afternoon, so hopefully it's nothing.

 

Were you the one asking earlier about getting a message wanting you to link your already linked accounts? Hopefully that's coincidence......

Message 5 of 9
Latest reply

FYI - ebay hacked again ... not good for business

Thanks so much for the info.
Nice of eBay to let us know . . . . . . again !
Message 6 of 9
Latest reply

FYI - ebay hacked again ... not good for business

yes, when I went to relist an item this afternoon I was told I was unable to sell any items until I had linked my ebay and paypal accounts, I messaged customer service however I could not wait for the reply to relist and so I simply followed the prompts to link my accounts which took me to paypal to confirm, then my husband alerted me to the recent hacking and so I quickly changed my paypal password just to be on the safe side, after all paypal is where the money is

 

also has anyone noticed an extreme downturn in sales ???

Message 7 of 9
Latest reply

FYI - ebay hacked again ... not good for business

Yes.. I agree. An EXTREME downturn in sales alright. !!!!!!

 

That is JUST why I just came onto the discussion boards to see if there was any other 'chatter' about it.

 

Very ODD at this time of the month....You can always expect a downturn in sales at the end of the month when many have their bills to pay etc....but not in the middle.

 

Must hope for better I guess !

 

 

Message 8 of 9
Latest reply

FYI - ebay hacked again ... not good for business

Yes, II have noticed a downturn in sales but i thought it was due to the items i sell (pre-loved clothes) and everyones wardrobe was full or my listings were badly worded and not being found :):) Who knows? Dunno, still bit new to this selling caper, hardly making a fortune but least my wardrobe is slowly thinning out 🙂

Message 9 of 9
Latest reply