Skip to main content

Found on the eBay UK discussion board (click here):

quote:
Hi,

Recently, I received the following message (with this return address: "Helen Doe 9019" ):

'Hello, auctionstealer.com customer. I'm gladly informing you, that www.auctionstealer.com was hacked a week ago by us. We contacted with managers of www.auctionstealer.com from our email web_tiburon@yahoo.es., but we didn't get an answer. They do not care about security and privacy of their customers. We wanted to help 'em to improve their network security, but they do not need it. They have too much holes in their security, and I think they are only care about the money they get from you. So, the only thing you pay for being their customer is to possibility of share your private information worldwide =) Now all your info was sold yesterday on hacker's underground auction, and now all your info (private info, eBay account info) is available for another people. Maybe they will use your info for selling of buying of stolen property or else. And you'll be in charge as account holder. You can save this letter as evidence for future lawsuit against www.auctionstealer.com. Also you better contact with your bank about your credit card if you use one with www.auctionstealer.com. As we wrote, now all your personal info is available over the internet, so you can call to www.auctionstealer.com to ask, why they allowed it. El Tiburon P.S. We are sending this letter to first 10.000 of more than 110.000 customers of www.auctionstealer.com. You can download the piece of base with your details from http://xxxxxxxxxxxxxxxxxxxxxx. You'll find there alot of interesting things about yourself and another poor customers of www.auctionstealer.com... Be hurry, because www.auctionstealer.com will delete this file ASAP =) Rest In Peace'

Have any other AuctionStealer.com users received this message. The link doesn't go anywhere, but I have changed my eBay password just in case. AuctionStealer.com offers a great service, but I'm not sure that I'll be using it again.

Thanks,
Joe



Must admit that I did try them in the early days but have since been a faithful and much happier ASniper customer ... think I'm even happier now ... so long as ASniper doesn't get hacked too!

[moderator removed URL to an Excel spreadsheet on likely hacker site that could run an exploit on your computer. If you're smart you wont ever click on these sorts of things! Anything that sounds sketchy is better to avoid than to be sorry later]

[This message was edited by Sniper Sara B. on May 24, 2003 at 12:23 AM.]
Last edited {1}
Original Post

Replies sorted oldest to newest

Methinks it's much easier for a disgruntled Auctionstealer.com customer who also has a bit of computer knowledge to send such a letter out to selected persons than it is for that same customer to hack into Auctionstealer.com and obtain personal information.

As for AS security -- I've had my eBay userid stolen, but I've never had any security problems with my AS account. Knock on wood. Eek
I would think that it's more likely that your ebay password would be hacked on ebay. It seems that's where it happens. The hacker has your ID, and they can apparently take as many tries at the password as they like (at least that use to be the case - I think ebay was concerned about restricting a user after a certain # of failed signon's for fear that buyers would try to temporarily suspend their competition, unless that's changed?).

Not being a hacker I could be completely wrong on this, but even if someone were to get my password thru ebay, what could they do? They could run up a bunch of BIN's or place bids, but I'd be getting email on that. Some buyers might get upset, but couldn't that be explained? As long as I have a different password for Paypal, they can't send money to themselves. I guess they could leave negs for any open feedbacks, but can't that be resolved?

And remembering when Steve's ID was stolen, the hacker put some items for sale under Steve's ID. Was that the most damage the hacker could do? Had to be stressful, but it sounded like Steve was able to resolve this (don't mean to minimize it). Steve changed his password which, as he suggested, is a good idea to do from time-to-time.

Considering Steve's experience, is that the worst that can happen? If not, what other things could someone do if they got your password.

If, I mean "IF", someone could actually hack AS' site, what's the chance they would only go after one of us? And IF they did, what's the chance it would be me? Isn't it more likely they would go after several people? If they did, this forum would be flooded with complaints. After all, remember "the worm". I think Dan Rather even reported it, but people were still coming on here to accuse AS.
I agree with both of you, really. That's why I suggested that it was someone trying to discredit the sniping service, not one who had actually stolen someone's identity and spread it all over the internet. The real sniper would've started getting all kinds of indications that something was terribly wrong immediately if his id, etc. had really been put out on the Net.

The language was similar to the guy you're reminded of, star_trkr, but there are some subtle differences that make me think it's somebody with English as a first language who didn't pay much attention to grammar in grade school. Roll Eyes
I received the subject email and immediately copied it to auctionstealer.com's contact us email and received no reply. I then searched their site and attempted to contact them through their privacy questions email and still no reply. I then did a little web research and obtained a phone number for SeeFusion Technologies, Inc. I called and they confirmed their site had apparantly been hacked. They think it was hacked from Spain. Although they claim no bank or credit info is stored on their servers, they did confirm some Ebay id's and passwords may have been obtained. They recommended changing Ebay & PayPal passwords. They will be releasing info soon.
quote:
Originally posted by rwwcarguy:
I hope they are not next.


Considering that Steve, Chatter163, fordfalcons, Rickdogg, star_trkr, Robert, granitz (hope I didn't miss anyone) have been here since the beginning of time and none of them have had a problem with AS' security; I'd say that counts for something. Smile

[This message was edited by Rick on May 21, 2003 at 08:16 PM.]
Last edited {1}
quote:
Originally posted by Rick:
quote:
Originally posted by rwwcarguy:
I hope they are not next.


Considering that Steve, Chatter163, fordfalcons, Rickdogg, star_trkr, Robert, granitz (hope I didn't miss anyone) have been here since the beginning of time and none of them have had a problem with AS' security; I'd say that counts for something. Smile

[This message was edited by Rick on May 21, 2003 at 08:16 PM.]


Heh. From what I have read from the boards recently over the past 2 days, they make dirt look young. Just Kidding.

Steven R.
aka Darkchilde

------
Tell me and I may forget
Show me and I may remember
Involve me and I will understand.

- Old Chinese Proverb

Add Reply

Post
×
×
×
×
Link copied to your clipboard.
×