Unconfigured Ad Widget

Collapse

Unconfigured Ad Widget

Collapse

Announcement

Collapse
No announcement yet.

password/ID hijack

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • password/ID hijack

    While I was away, I received what appeared to be a spoof or phishing email from eBay. I get them so often, I just deleted it because I was only using my PDA.

    When I returned home, I noticed my SpySweeper picked up a ldpinch Trojan during a scan and quarantined it.

    Infostealer.Ldpinch is a password-stealing Trojan horse that attempts to steal information from an infected computer and send it to the author of the Trojan. Troj/LdPinch-FC is a password-stealing Trojan with backdoor functionality.

    Troj/LdPinch-FC attempts to steal confidential information and send it to a remote location via HTTP or email.

    The information that Troj/LdPinch-FC attempts to gather includes:

    - keypresses (with the aid of a dropped keylogger DLL)
    - computer details
    - drive and volume information
    - hostname and IP address
    - information (including passwords and usernames) relating to selected applications installed on the computer, including: Miranda ICQ, mirabilis ICQ, The Bat!, Trillian, Windows Commander and Total Commander
    - passwords and confidential information stored by the system in 'Protected Storage'
    - POP3 and IMAP server information, usernames and passwords
    - FTP usernames and passwords
    - RAS dial-up settings


    I went to log into Ebay this morning and it stated my account was no longer valid. I did a live chat to find out what happened and they told me they put a hold on my account, and I had to change my password. Below is a portion of the email I had deleted while away on vacation thinking it was a spoof

    Here is a portion of the email: (this appears in my message center of eBay)

    "It appears your account was accessed by an unauthorized third party and used to send unsolicited emails to other community members, including email offers to sell items outside of eBay. It does not appear that your account was used to list or bid on any items. Additionally, the email address on your account may have been tampered with, which is why you may not have received any emails about this activity.
    At this time we have taken several steps to secure your eBay account. Rest assured that your credit card is safe".

    They advised me to change all my passwords, log off all websites and close the browsers when not in use, also advised me not to leave the computer on at night.

    What bothers me is that I have firewalls, internet security/spysweeper and up to date virus protection; never did I think this could ever happen..

    I left my laptop home and my mom, who doesn't understand much about computers may have clicked on something that she shouldn't have...or ignored one of the warnings on one of my programs, I don't know...but I have learned a lesson. Shut the computer off at night!!!

    I am also thrilled that ebay acted quickly on the matter!

  • #2
    About a year ago they had gotten into my ebay account. I was lucky I was on line watching the new auctions that I was not submitting going up for bid. Ebay as soon as I contacted then move super fast. But believe it or not even after changing the password 3 time they were still logged in. See the system allowed them to stay logged in under the old password for 12 hours more. They had tried to change everything in my account. The first thing they do is disable the email notification then put there email in. What really got me was even after everything was cleared up. When ever I had to set up a new auction it would have a link to the crooks. I could not remove it. Ebay had to figure out how to disable it.
    Timeshareforums Shirts and Mugs on sale now! http://www.cafepress.com/ts4ms

    Comment


    • #3
      You have to be careful using other people computers and networks that are not your own because people can spy on you even if you go to a site that is encrypted.

      1. If there is a person that set up the site and you are using it for like banking or ebay they can watch your key strokes (watch what you are typing) and get your pin that way.

      2. If you have a wireless router with out encryption someone can do the same thing again.


      To avoid these problems try not to use public internet for banking or sites that need a password and if you use a wireless router put a encryption on it. If you use Bank Of America you can set it up to have them text message you a 6 digit password number to your cell phone that is good I think for 10 minutes or one use for times like this.

      The reason I found out about this a coworker had his passwords taken that away.

      I hope this helps.

      Comment


      • #4
        this is disturbing...
        Connie

        Comment


        • #5
          This same thing happened to me with e-bay a couple of months ago. I wonder if it's a problem specifically with e-bay security and not just a general phisher?

          Comment


          • #6
            I don't know, but I'm generally pretty good when it comes to phishing emails because I get quite a few. I just wish I knew how I exactly picked up the trojan and why it only went after ebay...nothing else, but all passwords were changed to be safe.

            Comment

            Working...
            X