CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

PayPal HTW?

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
fetuz

Cadet
Cadet


Joined: Jun 12, 2008
Posts: 2
Location: USA

PostPosted: Thu Jun 12, 2008 10:23 pm    Post subject: PayPal HTW?
Reply with quote

So it seems that someone got my PayPal password. I'm asking for your guys' advice because I'm actually pretty stumped on how it was stolen. I'd never fall for a phishing site or email and even If I would, I simply haven't gotten any phishing emails so I've ruled that out. The only thing I know is, I bought something with "Buy It Now" on ebay last night around 11pm. I payed it with PayPal and went to bed. This morning I found that someone had sent themselves a nice amount of money from my PayPal account. The last time I used PayPal before that was a couple weeks ago so I can only assume that this is related to last night's purchase...somehow. I thought maybe I had a trojan or something - which seems unlikely since I use Firefox and I never really download any apps or appZ Wink But I did a full scan with Mcafee and AVG and they found nothing. I NOW have Sunbelt Firewall running and its not detecting any weird outgoing connections. Lastly, my PayPal password was unique and impossible to be guessed and pretty hard to brute-force. I checked if my local DNS had been modified - it doesn't seem to be and I can ping paypal at their real IP.

Any ideas? I'm pretty perplexed! Unless it's that guy with the binoculars across the street....

Back to top
View users profile Send private message
moike

PIRT Handler
Premium Member

Joined: May 26, 2006
Posts: 1873

Phishing Squad Premium

PostPosted: Fri Jun 13, 2008 1:29 am    Post subject:
Reply with quote

One possibility is local malware acting as a keylogger, etc. I'm guessing that this is unlikely because of FireFox and AVG, and not downloading anything.

One possibility is that the "Buy it Now" button was corrupted via Javascript in the listing. EBay still has cases where malicious users can embed Javascript in their listings to manipulate end users in various ways - generally nothing as serious as this. What is the listing #? If the listing contained malicious Javacript, it may still be present in the listing.

(Or you may PM the listing # to me if you don't want to post it publicly).

Back to top
View users profile Send private message
moike

PIRT Handler
Premium Member

Joined: May 26, 2006
Posts: 1873

Phishing Squad Premium

PostPosted: Fri Jun 13, 2008 3:49 am    Post subject:
Reply with quote

Thanks for the listing #s - the one with the high number of feedback was straightforward and had no Javascript.

The one with 128 feedback had Javascript for 2 auction helper sites : auctiva.com and sellathon.com. Everything appeared OK - the script was concerned only with trying to track the auction on the helper sites, and did not try to manipulate the Buy It Now button. I checked his other listing and the Buy It Now button took me to eBay with no hidden redirect.

There's only the wonderment that a guy with 2 active listings and 128 sales in 5 years need all this auction help - all the fluff only detracts from his listing. But otherwise, that seller and listing pass the legitimate feel test.

So, I have no answer here.

Back to top
View users profile Send private message
fetuz

Cadet
Cadet


Joined: Jun 12, 2008
Posts: 2
Location: USA

PostPosted: Fri Jun 13, 2008 4:19 am    Post subject:
Reply with quote

Thank you for taking the time - it's much appreciated. This is quite a puzzler - I've been thinking about it all day! Yes, the Ebay listings look pretty sanitary. Spybot, AVG, Mcafee, and Sunbelt Firewall suspect nothing on my PC. Have you heard a trojan that removes itself after it gets what it wants? Not me, usually they are pretty greedy Smile
Even if it was a home-grown (no common signature) key logger, Sunbelt should still pick it up when it phones home. Pretty weird!

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer