« Listd offers one page eBay listing tool | Main | Cross Promotion on Sold eBay Items »

Aug18
New eBay Fraud Tactic

eBay Strategies has posted some information about a new scam tactic surfacing on eBay:




A new tactic (which we have dubbed VPTH) has hit eBay hard the last couple of days.  Unfortunately it's a really clever way to get lots of eBay uids/passwords AND it's very viral so it appears to be growing at an exponential rate.   

Here's how the bad guys do it:

1. They use normal Phishing techniques to get an ebayer's uid/pwd (preferably a seller with some good feedback).

2. They post toins of malicious listing to popular categories.  In the listings they:

  • Use something like porn imagery to draw heavy click-through to the listing
  • Turn on every eBay bonus feature you can imagine: bold, highlight, gallery plus, featured plus, etc. (hey they aren't paying so why not?!)
  • Lots of timese these are 1 day auctions so they are indexed quick and TnS doesn't have much time to a) find and b) react.
  • Now here's the trick - they put in the listing some malicious javascript that redirects anyone that clicks on the listing to a page at badguy.com that is 100% identical to an eBay login page and it says: "To view this item you must login".

3. Now the bad guys have tons of BUYER userid's and logins, which they then use to get into paypal accounts, launch more auctions and cause general mayhem.

4. Some of these are so clever you can't find which listing is doing it.  They'll post a porn listing and then 10 regular ones all with the javascript in there.  A seller saw one yesterday that seemed to infect every listing in the category - it somehow was changing the search results pages around.


1 Comments/Trackbacks




I always take extra precaution with comes dealing with ebay.

submit a trackback

TrackBack URL for this entry:

post a comment

Name, Email Address, and URL are not required fields.





Comment Preview

« Listd offers one page eBay listing tool | Main | Cross Promotion on Sold eBay Items »

Advertise

sponsored ads



subscribe


Prefer Email?
Subscribe below-

Enter your Email:


Powered by FeedBlitz What's this?

Current News

Support This Blog

blogroll


 


Know More Media - Internet / Ecommerce / Online Business

know more media network

View Network Map

Network Feed List (OPML)

Know More Media Network
Feed


we support unitus

PRWeb

Influencer



PowerSellerKing is a member of the Know More Media network of business related blogs.

Here are some current headlines from some of our business publications:

ProductivityGoal

CallCenterScript

AdHurl

TheBizofKnowledge


Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 619

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 620

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 621

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 622

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 737

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 738

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 739

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 740


Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 619

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 620

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 621

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 622

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 737

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 738

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 739

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 740

HealthCareVox

BrainBasedBusiness


Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 619

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 620

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 621

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 622

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 737

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 738

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 739

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 740


Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 619

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 620

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 621

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 622

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 737

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 738

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 739

Warning: date() expects parameter 2 to be long, string given in /usr/www/users/chrisycm/kmm-network/includes/rss2html/rss2html.php on line 740