Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Product Tips & Reviews
Security & Privacy
Daily Downloads
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Auction SitesHackersOnline SecurityCybercrime

Botnet Steals eBay Accounts

Gregg Keizer, Computerworld

Tuesday, September 04, 2007 9:00 AM PDT
Recommend this story?

Online auction site eBay has been targeted by identity thieves, who are wielding a botnet that uses brute force to uncover valid account log-in information, a Tel Aviv-based security company said Monday.

The attacks against eBay Inc. may have started as long ago as early August, said Ofer Elzam. He said that he and other researchers at Aladdin Knowledge Systems Ltd. have not been successful in notifying eBay of their weekend findings.

According to Elzam, the product manager of Aladdin's eSafe threat-protection line, the brute-force attacks are launched by a large botnet that the identity thieves have built using a sophisticated, multistage campaign that begins with compromised legitimate Web sites.

"My best estimate is that there are at least 300 compromised sites," said Elzam, who noted that they are spread worldwide and in several languages. Two sites are based in Israel, he said, including a price-comparison Web site and another operated by one of the country's largest unions. Other sites identified in a search run with information provided by Elzam included scores of real estate Web sites in Florida and Massachusetts, and a Microsoft security message forum in Italian.

Seeding genuine Web sites with malware is nothing new, but the practice has been gathering steam this year. In June, for example, hackers launched a massive bot-building attack from more than 10,000 hijacked Web sites, most of them hosted in Italy.

"These sites are compromised by SQL injection vulnerabilities, and then IFrame attack code is inserted," said Elzam, describing a common method of hacking legitimate Web sites and infecting their visitors. "The IFrame code redirects visitors to other sites which host a Trojan," he added. The Trojan horse hijacks the PC and turns it into a zombie, or bot.

"This is a very sophisticated, very complex attack," Elzam claimed, ticking off obfuscation techniques, multipart malware downloads and encryption among the tactics used by the thieves.

The resulting botnet is being used to call an eBay application programming interface (API) with pairs of possible usernames and passwords, said Elzam. The API allows the Trojan horse-infected PC -- the bot -- to communicate directly with the eBay database using XML-formatted code. If the database contains the username-password pair, it responds, which the Trojan horse notes, then later transmits to a hacker controlled server.

With enough username-password combinations -- the brute-force part of the attack -- the criminals can uncovering a limited number of real credentials.

"Each bot may be using as few as six pairs of usernames and passwords" in an attempt to come in under the security radar of eBay, said Elzam. "I don't think that eBay is even aware of the attack. The distributed nature of the attack may make it look like a merchant sending confirmations to buyers," he said.

Although Aladdin pieced together the evidence only Tuesday, Elzam said that clues indicate it might have started in early August.

It's unknown what the identity thieves have done with stolen eBay log-ons. One eBay user, however, may have offered up a possibility Tuesday in a blog post.

"I woke up this morning to a nightmare," wrote a Texas-based book collector identified on his blog only as Sam Houston. "Someone in England hacked into my personal eBay data and changed it to reflect a completely fraudulent identity with an English mailing address. That person than proceeded to send out at least 25 e-mails to individuals in the U.K. who are trying to sell Sony laptop computers on the site. He offered them more than they are asking for the laptops and wanted them mailed to him as soon as possible."

According to the blogger, the attacker has also compromised his PayPal account and tried to pay for the 25 notebooks using funds from the checking account linked to PayPal.

EBay did not reply to a request for comment Monday night.


Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.


Recommend this story?
Related Searches: ebay identity theft security botnet

Comments
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
Longtime iPod developer, Griffin Technology, unveiled on Wednesday its newest accessory, the iTrip AutoPilot. The good news is... 22-May-2008
HP wants printer buyers to pay more attention to the environmental impact of its printers, and is introducing a new labeling... 22-May-2008
Aero Quartet has released version 3.7 of SimpleMovieX, software the company describes as a "lightweight Mac OS X movie editor... 22-May-2008
Screen recording application Screenflick has been updated adding over 30 enhancements, the company said on Thursday. 22-May-2008
Toontrack has updated all six of its expansion packs for its EZdrummer drum sampler. The updates fix some issues and copy... 22-May-2008
Here's a little Spotlight timesaver for those running 10.5. As you're probably aware, when you invoke a search in the 10.5... 22-May-2008
Other World Computing (OWC) on Thursday began shipping its new line of internal CD- and DVD-burning SuperDrives. The new... 22-May-2008
As you may have read, Mac clone maker Psystar is now distributing Apple's own software updates. That's right--you can now... 22-May-2008
Hothead Games has released Penny Arcade Adventures Volume One: On the Rain-Slicked Precipice of Darkness. The new game is... 22-May-2008
Elgato Systems has updated the software for its turbo.264 video encoder USB stick. The  1.3 update now lets users convert and... 22-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)