Feeds

Hacked eBay accounts give rise to conspiracy theories

Roswell, the Kennedys and a hacker named Vladuz

Reducing the cost and complexity of web vulnerability management

Eagle-eyed conspiracy buffs have pounced on a recent rash of compromised eBay user accounts as proof of a mile-wide hole in the auctioneer's front lines, giving new life to a theory that could one day rival the intrigue surrounding Roswell UFO crashing and Kennedy assassinations.

Details remained sketchy, and of course, eBay managers have assembled the requisite wall of plausible deniability, but here's what we've pieced together so far: Over the past few days, several dozen eBay auctions - many selling pricey items such as Cartier Tank watches - have been hijacked by crooks who append legitimate auctions with notes suggesting would-be buyers contact a Gmail account for a special, "buy-it-now" discount. (Our initial Google search, trolling for tell-tale signs of the scam, returned 73 results; those numbers thinned over the next several hours, presumably, as the tired souls in eBay's security group pulled down offending pages.)

An eBay spokesman says all indications suggest that the accounts were compromised through plain-vanilla phishing techniques, in which unwitting users fall prey to spoofed emails and give passwords to their attackers. End of story, right?

Not quite. While the more timid among us would be tempted to agree with the company's party line, a chorus of eBay critics say there is something much more nefarious going on. They argue the episode is the latest proof of the existence of back door that has been built into the company's corporate network, allowing an attacker or a cadre of attackers to siphon login credentials and other confidential information from the site's users.

Who's in the Hoody?

Suspicions of a cover-up date back at least to December, when according to a post on The Auction Guild, a reader named Jack reported that his eBay account had been hijacked by crooks who were using it to sell BAPE Hoody shirts. On at least two occasions - once from a work PC, the other from his fire-walled home network - Jack retook control of his account and changed the passwords and other settings. Each time, the attacker was able to regain access.

"In trying to analyze what was going on, it appeared that the hijacker or hijackers had to have access to accounts independent of passwords, and have the ability to set account parameters so the legit account holder would not know what was going on," the Auction Guild posting theorizes. "If this is so, it either points to someone working inside eBay, or to a security hole so big, you can drive a tractor trailer through it."

A month later, Auction Guild was back, this time with evidence that a Romanian hacker going by the name Vladuz had developed and was circulating a sophisticated tool that reads confidential information residing on eBay's internal network, allowing attackers free reign of virtually any account and a trove of information that could be used in phishing attacks. A screen shot on another blog known to be hostile to eBay also purports to show Vladuz having gained the credentials of an eBay customer service representative on a public forum. "How about you start arguing in English?" the hacker taunts the crowd. "So I can laugh at you."

eBay spokesman Hani Durzy acknowledges that the hacker was able to gain access to a "single-digit number" of email accounts reserved for customer service employees, but he insists those accounts were maintained by servers that are entirely separate from the network where customer databases and confidential corporate information are stored. eBay officials know the identity of Vladuz and have alerted US and Romanian officials of his deeds, Durzy says.

But like any plausible denial, Durzy's is accompanied by a cloak of secrecy that officials say is necessary to maintain security, but that conspiracy theorists insist is designed to keep the lie alive. One such detail being kept under wraps is how Vladuz managed to gain the credentials of an eBay employee in the first place, or how officials can be sure the intruder never gained access to more sensitive parts of eBay's network.

Even more suspicious, according to AuctionBytes, is the recent removal of a link from an eBay forum that exposed account holders' names, addresses, and user names and passwords. Indeed, eBay officials appeared to have purged an entire forum thread where conspiracy theorists were discussing the vast cover up. (A capture of a more recent thread can be found here.

Not quite as compelling a plot as The X-files or Oliver Stone's JFK. But with all the round and round, we get the feeling this one may have more staying power. ®

The next step in data security

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Driving with an Apple Watch could land you with a £100 FINE
Bad news for tech-addicted fanbois behind the wheel
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Sony says year's losses will be FOUR TIMES DEEPER than thought
Losses of more than $2 BILLION loom over troubled Japanese corp
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Big Content Australia just blew a big hole in its credibility
AHEDA's research on average content prices did not expose methodology, so appears less than rigourous
Special pleading against mass surveillance won't help anyone
Protecting journalists alone won't protect their sources
Bono: Apple will sort out monetising music where the labels failed
Remastered so hard it would be difficult or impossible to master it again
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.