Feeds

Bot-wielding hackers crash eBay holiday giveaway

eBay cares not

SANS - Survey on application security programs

eBay users are howling in protest after discovering hackers are using automated scripts to win hundreds of steeply discounted auctions as part of a holiday season contest designed to draw visitors to the site.

Auctions for pricey items including a Green Life electric scooter and an Oscar de la Renta evening gown, which had been marked down to just $1, were scooped up even as the counter for their pages registered 0000 visitors. The Grinch stealing this year's Christmas booty were bot-armed hackers who were able to sniff out the promo pages before they went live to the public.

"This should have been advertised as a programming contest because those are the only people who can win," one eBay user complained to MSNBC's Red Tape Chronicles, which reported the story. "eBay can stop this if they want to by requiring a verification screen or something, they just don't care."

Perhaps. But that would require eBay to have an established set of contest rules, which it apparently doesn't.

An eBay spokesman first told MSNBC's Bob Sullivan the rules didn't prohibit the use of scripts to find items included in the "Holiday Doorbusters" promotion. Later, he changed that to say they might bar automated tools. Finally, the company issued a mealy-fingered email that said only that employees were "doing everything in our power to ensure that all eBay users have an equal opportunity to search for and win these hot holiday items."

So our advice to eBayers intent on winning this year is to hire a freelance programmer to scoop up the hot items before someone else gets there first. It may not be the most ethical thing you've ever done, but the deals are amazing. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.