Powersellersunite
Go to the homepageHome
Index of the forum.Forum
nav_searchSearch Forum
Store_explainUsers Storefronts
Register
Log in
         
Site Navigation
Go to the homepageHome
Index of the forum.Forum
Online auction industry related acronymsAuction Acronyms
Topics that are top rated by forum usersLatest Ratings
Store_explainUsers Storefronts
Frequently Asked Questions.FAQ
Help spread the word about us.Link To Us
Search through forums.Search Forums
Joomla VirtueMart Google Checkout ModuleJoomla VirtueMart Google Checkout Module


Ecommerce Hosting
Sign up for Web HostingSign up for Hosting
ecommerce shopping cartEcommerce Details

Go to the homepageWebMail Login
Go to the homepageControl Panel
SupportSupport

Please consider a small donation to help me keep this site running.

Free Auction Tools
Number of listings on auction sitesAuction Site Count
Ebay Fee ChartEbay Fee Chart
Track PackagesTrack Packages
TinyURLTinyURL
WYSIWYG HTML EditorHTML Editor
Create your own dynamic custom imageSmartSignature
Create custom PayPal payment buttonsPayPal Button Factory

Search
Forum
PowerSellersUnite.com
MOAAS

Advance Forum Search

User Info
Username:

Password:

 Remember me



I forgot my password

Don't have an account yet?
You can register for FREE


Recent Topics
» Ex-eBay CEO Whitman to run for California governor
by Daikon on Tue Jan 06, 2009 10:56 am

» New Google Auction Site?
by sciencefare on Tue Jan 06, 2009 10:48 am

» I don't want to be a "bad" buyer but...
by sciencefare on Tue Jan 06, 2009 10:20 am

» So I've worked my way around Best Match, sales are great....
by sciencefare on Tue Jan 06, 2009 10:15 am

» Must Read - Product Safety Act Legislation
by suburbantreasure on Tue Jan 06, 2009 9:56 am

» Introduce Yourself
by PA-Antiques on Tue Jan 06, 2009 9:47 am

» Importing items from a CSV or Turbolister
by PA-Antiques on Tue Jan 06, 2009 9:35 am

» EBay Watch 2008: The Year in Review
by ploughman on Tue Jan 06, 2009 9:17 am

» Toyota to suspend production for 11 days in Japan
by USA license plates on Tue Jan 06, 2009 9:14 am

» eBay's Big Post Holiday Promotion
by ploughman on Tue Jan 06, 2009 9:07 am




EBay Motors Scam
 
View previous topic View printer-friendly version Search Display number of posts for each poster in this topic Export topic thread to a text file View next topic
Author Message
dticorp
Total posts: 1245

USA US Florida
PostPosted: Wed Mar 07, 2007 1:30 am   Post subject:  EBay Motors Scam #1  Back to top 

http://www.symantec.com/enterprise/security_response/weblog/2007/03/ebay_motors_scam.html

We have recently received a new threat that targets users of the eBay auction site and, more specifically, motor auctions. The threat, named Trojan.Bayrob, is quite advanced and tries to implement a man in the middle style attack. While we have previously seen Infostealers that try to steal your username and password, a threat attempting a man in the middle attack on eBay is very unusual.

Man in the middle attacks are very powerful, but are also difficult to code correctly. Trojan.Bayrob takes the approach of implementing a local proxy server and directing traffic bound for eBay through this local proxy server. The proxy server listens on localhost port 80.

To send traffic through its proxy server, Trojan.Bayrob changes the etc/hosts files to force traffic bound for the following sites through the local proxy server:
My.ebay.com
Cgi.ebay.com
Offer.ebay.com
Feedback.ebay.com
Motors.search.ebay.com
Search.ebay.com

Trojan.Bayrob then connects to the following servers to download configuration data (the Trojan can also download an updated list of these control servers):
Superdigitalprices.com
Wai-k-mart.com
Wal-stop-mart.com
Onemoreshoot.com
Jdo24nrojseklehfn.com

These servers are duplicates of each other and the Trojan regularly pings them to check that they are still active (using the isup.php script). Each of these servers contains the following scripts:
Var.php
Cfp.php
Hst.php
Var-user.php
Ping.php
Isup.php
Ban.php
Setvar.php
Getip.php
Hostname.php
Hst-user.php
Exe.php
Contact.php

The most interesting of these scripts is var.php; this script returns many different variables, which will be used in the attack. The downloaded variables include tokenised versions of legitimate eBay pages. An example is shown below:



When the user requests a real “ask a question” page, they will be presented with this fake page instead. The page has been tokenised to allow the Trojan to easily replace important strings with its own. In the example above, the %seller_name%, %item_number% etc will be replaced with variables that the Trojan will download.

In total, the Trojan downloads 10 fake pages–although this is also variable:
%ask_page% - Fake Ask a Question Page
%bin_page% - Fake Buy it Now Page
%ended_page% - Fake Auction eneded Page
%commit_page% - Fake Review and Commit to Buy Page
%feedback_page% - Fake Feedback page
%payment_page% -
%insert_won% -
%insert_paid% -
%trust_and_safety% -
%item_specifics% -

The fake feedback page is interesting and is shown below, it shows a high feedback rating so that the user will be confident to continue and finish the auction:



The exact motive behind the Trojan is still a mystery since at the time of writing the servers are not sending down the %item_number% and %seller_name% variables that may show which auction the user should be redirected to, and without which, the Trojan will not start to show fake pages.

Further analysis is on going, and we will update this blog as soon as we have any further information. Symantec detects this threat as Trojan.Bayrob. Another way to prevent the attack is to block the domains shown above at the firewall; however, these domains will no doubt change since the Trojan is capable of updating the list.


http://www.DtiCorp.com



HONEYWELL Thermostats and HVAC Controls


http://www.cxNewYork.com



Looking for Sport shoes? Make yourself at home.



.

Download Post  No rating  
dticorp
Total posts: 1245

USA US Florida
PostPosted: Wed Mar 07, 2007 1:33 am   Post subject:  Re: EBay Motors Scam #2  Back to top 

New Ebay Motors Scam Revealed

http://www.shortnews.com/shownews.cfm?id=60716

Symantec have warned of a malicious Trojan called 'Bayrob' which enables scammers to obtain Ebay Motors customers' IDs and passwords.


Ebay's latest security scare is known as a 'middleman' attack. Trojan.Bayrob does this by exploiting a weakness in Ebay's proxy server.


Ebay users are warned (by Symantec) to be wary of attacks from Ebay's internal messages as well ME pages. The risk of being attacked is reduced by refraining from clicking on any links. There is no word from Ebay regarding this latest security scare.

Download Post  No rating  
Display posts from previous:      
 


 Jump to:   



  View previous topic View printer-friendly version Search Display number of posts for each poster in this topic Export topic thread to a text file View next topic

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
   Lo-Fi version