Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Database

    Whats Bugging eBay?

    Written by

    Lisa Vaas
    Published March 6, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The eBay villagers are whispering that he can creep through eBays internal databases and suck the lifeblood of customer accounts—log-ins and passwords—right out of their pulsing, 222 million-plus customer heart. Hes putting up bogus listings as fast as eBay can take them down, and that proves hes walked through a security hole as big as a barn door.

      No, eBay insists, this hacker, this Romanian wiseguy who goes by the handle Vladuz, is “nothing new.” Hes just another phisher, says eBay spokeswoman Catherine England, one of hundreds the huge auction site has to deal with constantly.

      He may be getting loads of publicity from posting onto eBay forums as a service rep and taunting eBay—”Durzy is full OF sh*t,” he wrote about eBay spokesperson Hani Durzy in a February posting after Durzy said that Vladuz had not accessed internal systems. But that just means he got lucky once and hit upon an internal e-mail that had a screenshot containing customer service reps e-mail account information, eBay maintains.

      Some eBay watchers attribute eBays recent crackdown on cross-border sales to the recent spike in hijacked accounts. The spike in traffic might not be wholly attributable to Vladuzs work, but he or she is being credited for most of it. The multitalented hacker is leaving a calling card behind with his or her name, spelled backwards, attached to malicious code injected in live auctions. Hes taunting eBay by posting to its forums as a customer service rep. His name is associated with a company name that is in turn associated with eBay hacking tools being found for sale online.

      Hijacked accounts occur after phishers weasel log-in names and passwords out of legitimate eBay account holders and then use them to run auctions that look like theyre taking place in a country with a reputation for legitimate sales, such as the United States or Canada.

      /zimages/1/167279.jpg

      This is nothing new, but eBay watchers say the number of hijacked accounts and their changed behavior makes it begin to look as if somebody had set up tools to automatically skim customer accounts from eBays internal accounts—and such are Vladuzs reputation and braggadocio, at this point, that experts believe he or she could be responsible.

      eBay watchers say the trigger for the spike was eBays recent crackdown on counterfeit goods being sold from countries notorious for it, such as China. Like rats leaving a sinking ship, the thinking goes, crooks such as Vladuz are turning to hijacked accounts because the counterfeit e-business has gone belly-up.

      /zimages/1/28571.gifeBay retools its technology platform to scale for rapid growth. Click here to read more.

      “In the last few months, eBay has really taken a look at the trust and safety of our marketplace and our Web site,” England told eWEEK. “Weve been incorporating a lot of new measures. My understanding is its been a little frustrating for this fellow. Hes spent some quality time poking around our site and trying to find a way in. He did find access to a small amount of customer service rep e-mail accounts. He used those to go on discussion forums, as a pink—when an employee posts, its highlighted in pink. He did that in an attempt basically to say, Ha ha, look what I did.”

      Lies, lies, lies, says online auction activist Rosalinda Baldwin, who runs an auction watchdog group called The Auction Guild (TAG).

      “Theres always been phishing [attempts to get account information and second-chance offers made to bidders who didnt win] and other fraud going on,” she said. “It became huge mid-December [when eBay began to prevent Chinese sellers from selling to eBay U.S., eBay Canada, etc.]. It seems to have been the trigger: [The collection of phishing attempts and hijacked accounts] went from one without pattern to one” that definitely showed a pattern, she said.

      “I know eBay pretty well,” Baldwin said. “They can use all the excuses and lies they want, but they have yet to explain how what is happening on this site could be happening if what Im saying is not true: that somebody has access to the back end.”

      Quantifying the hijacking of accounts is another eBay watcher, Genie Livingstone. Livingstone is a PHP programmer and runs the Internet host and domain name registration site Dotyou.Com.

      Heres an example (check out the five links at the bottom) of the Web monitors, based on RSS eBay tools, that Dotyou.com is using to track eBay scam auctions in real time. Livingstone is also tracking eBay listing totals on MedVed.net.

      What shes found for the past few weeks is that the daily count of eBay listings has been “a series of sharp spikes of 1 [million] to 3 million items, instead of the usual gradual curve that reflects items being listed and sold,” she said.

      The seesawing appears, she said, “as if someone is flooding the site with hacked listings that eBay is pulling down, only to have them immediately relisted, only to have them pulled down, etc., etc.”

      /zimages/1/28571.gifeBay adds 10 terabytes of new storage every week. Click here to find out how it manages all that storage.

      This is MedVeds graph for eBay listings in February 2007, compared with February 2006. Notice the seesawing that begins on Feb. 22, 2007, with sharp increases and decreases that are of equal value, as if the same number of listings are being posted, delisted and posted again, in multiple daily cycles.

      eBays England said that she looked into site activity over the past six months and found “absolutely no significant movement in number of account takeovers.” However, she has not yet looked into the flux of listings numbers, she said.

      Still, she insists, theres nothing new to see here, even if Livingstone credits eBay with having perfected automated tools to remove the bogus listings, which recently have been coming down after only 30 seconds.

      “Weve had a variety of automated tools in place for a long time,” said England, in San Jose, Calif. “This is nothing new. I wish I could say its some big, exciting thing. Its your standard, typical phishing scam thats been happening a long, long time. I think this person, because [he or she] went on discussion boards and posed as an employee, it got more attention. The reality is these scams have been around years and years. As [we] shut these guys down, they adapt. Theyre obviously intelligent people. But as they evolve, so do we.”

      Next Page: Vladuz gets Dotyou.coms attention.

      Page 2


      Vladuz first came to Dotyou.coms attention a few weeks ago—Valentines Day, as a matter of fact.

      Dotyou had written some RSS tools to track scam auctions. First, they manually identified the improper English typically used by non-native English-speaking scam artists. The listings with bad English had another consistent feature: They tried to lure buyers into contacting them outside of eBay, through an e-mail address at Yahoo or Hotmail, for example, and then asked that the buyers pay them through Western Union.

      Using the bad-English phrases in one RSS stream and cross-referencing the non-eBay e-mail addresses in another RSS feed keeps the list of bogus sites current, Livingstone said. Using this list, they kept track of hijacked seller accounts and were tracking some 30 to 70 accounts per day. Each account, however, would typically post from 70 to 200 expensive items, to make as much use of the hijacked account as possible before eBay would shut it down.

      But in 2007, Dotyou noticed that the hijacked accounts were only running one auction per hijacked seller; the frugality had disappeared. “It appeared as though something [had] changed,” Livingstone said in an e-mail exchange. “As if there is [a] larger and larger pool of available phished eBay IDs so the scammers do not need to be frugal with them any longer.”

      The trend culminated with Vladuz temporarily unveiling his auctions to the public, she said. Instead of putting up fake auctions, he began to inject legitimate auctions created by real sellers, updating the auction with big “EMAIL ME” statements. The typical hijacked auction on Feb. 14 looked like this listing, with a “Buy It Now” message luring buyers to a Gmail address.

      /zimages/1/28571.gifPhishers cast bait for bigger catch. Click here to read more.

      Whats alarming about the new trend, Livingstone said, was that it went beyond fake listings—a “regular Romanian modus operandi”—that were the result of successfully phished legitimate accounts and, through a security hole or a tool, entered a new level of sophistication, picking up on real auctions and modifying them.

      As of Feb. 5, Dotyou.com was in the process of updating an archive of what Livingstone said are live Vladuz auctions, identifiable by his signature toward the bottom: his handle spelled backward, as zudalv.

      TAGs Baldwin said that Vladuz first came to her attention through his sale of eBay hacking tools. She saw that somebody on a chat board posted a tale of having been offered the chance to buy a tool called Second Chance Offer. The modus operandi of the tool was to contact an auction bidder who came in second and therefore hadnt won whatever he had bid on. Second Chance offers to sell the bidder a similar item, but in this case, Vladuz appeared to have created a tool that allowed the user to look as though the e-mail was coming from eBays e-mail system. Actually, the tool creates fake offers, a way to coax a buyer into making a payment and receiving nothing in return.

      Baldwin searched for any reference of the Second Chance Offer tool and came up with a company called SGI Enterprises—a name to which the handle vladuz was connected. She started tracking postings of vladuz back to 2002, finding postings on Chinese hacker sites.

      Then Vladuz e-mailed her, offering a look at his or her new tool. It was posted as a Firefox plug-in, Baldwin said, that would automatically decipher and type in the text encoded in a garbled image file.

      eBay denies that Vladuz has anything but old screenshots of the back ends of tools eBay created and used. “He didnt have access—he pulled screenshots,” England said.

      At this point, Vladuz is shrouded in an aura of invincibility. eBay watchers, almost superstitiously, point to his ability to “cherrypick accounts” according to a certain pattern—usually those with a medium amount of feedback that are fairly inactive. News accounts have referenced his ability to offer up hijacked accounts in sequential order as proof that he has access to eBays internal databases.

      Thats taking it a bit far, said Dave Jevans, chairman of the Anti Phishing Working Group.

      “There are of course automated phishing kits, and they are becoming both more sophisticated and widely available,” he said. “However, they typically mine eBay auctions and find user names, and then send e-mails or Second Chance rebid opportunities to those people. Thats the only way I can see that automated harvesting would work.”

      /zimages/1/28571.gifClick here to read about the role of the “money mule” in phishing.

      The sequential order of hijacked accounts is typical, he said, when phishers batch-process information and offer it for sale.

      Still, given the range of brazen hacks to which the name is attached, Vladuz is scary, and eBay is hot on the Romanian spammer/phisher/hackers trail.

      England said that eBay has spent the past few months tracking the crook, working with Romanian law enforcement. But although Vladuz is known as a “career criminal” in Romania, she said, theres no guarantee he or she will be found and prosecuted soon. Thats due to differences in laws surrounding IP tracking, for example, but also due to a lack of resources in a country such as Romania.

      In an impoverished country such as Romania, money talks, Livingstone said. On that point, England agrees. Back in 2002 when eBay was dealing with a separate hacker issue in Romania, the police knew where the criminal was, she said. Unfortunately, he was some 30 to 40 miles away from the station, and they couldnt afford the gas to go get him.

      eBay was more than happy to lend a helping hand.

      Editors Note: This story was updated to include more information on Vladuzs reported activities.

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Lisa Vaas
      Lisa Vaas
      Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.