Feeds

eBay goes hacker hunting in Romania

Fraud rising at internet speed

Next gen security for virtualised datacentres

Exclusive More than two months after breaching eBay's employee servers, a hacker who calls himself Vladuz remains at large, despite the best efforts of the online auctioneer's security team and officials with law enforcement agencies in the US and eastern Europe.

So far, little public information is known for sure about Vladuz, who on at least two occasions has logged into eBay forums as an official customer service representative and then mocked the company's security. But the net is covered with bread crumbs left by a hacker who goes by that name, brazenly advertises cracking software and talks up his programming prowess. "This scam is perfect in many ways," he wrote on one site about a file he said steals eBay passwords.

eBay officials say they are aggressively pursuing Vladuz with the help of the FBI and law enforcement authorities. And the online auctioneer insists his unauthorized access has been limited to servers used for employee email accounts, which are completely separate from the network where crucial customer data is kept.

The last time Vladuz is known to have breached eBay's servers, the person, who posted under a pink banner reserved for official eBay representatives, said he was Romanian but not currently living in that country. An eBay spokesman said the company believes the hacker is Romanian.

Vladuz's break-ins may be limited, but his work has been accompanied by what critics say is a sudden spike in the number of fraudulent auctions on the site. As evidence, they point to the sharply increased volatility in the number of auctions being offered, and then removed, from hour to hour since the end of January.

On Jan. 31, for example, the number of listings swung from about 13.95m at 3 AM New York time to about 12.2m an hour and a half later, according to this chart from MedVed, which continuously tracks these figures. Over the next 13 hours, listings fluctuated between those extremes three times, making the graph (immediately below this paragraph) appear like a roller coaster, with each slope representing about 1.75m auctions. Many daily charts since then show a similar pattern.

eBay listings on Jan. 31, shortly after Vladuz emerged

It wasn't always this way. On Jan. 29, 2006 (MedVed didn't supply figures for Jan. 31 of that year), the graph maps a single downward slope that moves from about 14.5 auctions to 14.05, a difference of about 450,000, or about one-fourth of the heaviest recent activity. (The latter chart, below, is typical of account volume prior to Jan. 31.) To critics, the recent volatility is proof of an increase in the cat-and-mouse game playing out between fraudsters and eBay's security team. Many suspect Vladuz and his clients are responsible for the supposed increase in fraudulent postings.

eBay listings on Jan. 29, 2006

What goes down must come up

"As quick as eBay is removing them, they're putting them right back up," says Ed Koon, whose outspoken criticism of eBay extends to his creation of a site titled eBayMotorsSucks.com. Also on the rise, according to Koon and others, are the number of fraudulent sales being posted by users with highly favorable feedback ratings from previous buyers. (The positive approval scores are valuable in gaining the trust of potential victims.)

Typical of this latter trend, Koon says, is a sale on Monday for a rare Scotty Cameron Del Mar 3 golf putter by a user with the handle kennecl. The seller had a 100 per cent favorable score from 77 users, and yet the person asked prospective buyers to send bids to a CompuServe email address, a violation of eBay terms that require sales to go through official eBay channels. Circumventing eBay is a common technique employed by fraudsters, who then try to convince the buyer to send a money transfer or volunteer bank account information. (We sent inquiries to kennecl's address and received a response instructing us to send a payment through Western Union to a person in Italy named Stanley Jones.)

An eBay spokeswoman says the MedVed numbers "far exceed our real activity in this area." She also said the swings are caused by many variables, including batch processes and the timing of new code roll-outs.

"My team looked at the data and there just isn't enough information there to tie the swings in listings that they show to any one cause," she writes in an email. She declines to disclose how many accounts are removed due to fraud.

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?