‘Fiendish’ Trojan pickpockets eBay users

Miscreants have unleashed a new strain of a sophisticated Trojan that targets eBay users by feeding them spoofed web pages containing fraudulent information about high-ticket purchases, The Register has learned. It has already contributed to an $8,600 loss by one eBay member.

The Trojan installs a scaled-down webserver on an infected machine that masquerades as eBay and several third-party destinations frequently used to sniff out fraudulent offerings, including Carfax.com, Autocheck.com and Escrow.com.

When a victim browses to one of these sites, the webserver creates a parallel universe of sorts, in which the victim sees counterfeit pages designed to counter fraud protection mechanisms offered by eBay and third-party sites.

“To think that somehow they got software on their system that managed to spoof all the validation sites – that’s a shit-scary story,” said Roger Thompson, a researcher at Exploit Prevention Labs who specializes in web-based attacks. “It’s fiendishly clever.”

The malware was found on the machine of one eBay Motors user who recently lost $8,650 after trying to buy a 2005 Jeep Liberty advertised for 10 days on the site. Customer representatives have refused to cover the theft because, they said, the transaction was made outside of eBay.

Shortly after making the offer, the victim received a notification in the My Messages section of her eBay account telling her she had won the auction. eBay has long cautioned users not to rely on notifications unless they appear in this official section.

The malware installed on the victim’s machine caused her browser to display a counterfeit version of just such a message. Had she used a non-infected computer to access her account, no such message would have appeared.

“There’s no reason to suspect it’s fraud until its too late,” said the Ohio-based user, who agreed to tell her story on the condition her identity was not revealed. The Register was able to verify the scam by confirming details with eBay and by reviewing screenshots, emails and files pulled from her machine.

The malware appears to be a reworking of Trojan.Bayrob, which first came to light in early March when researchers from Symantec wrote reports about it.

It arrives in an attachment to an email responding to a bid and installs a local proxy server that redirects traffic bound for eBay. The proxy, according to Symantec, spoofs sensitive pages on eBay, including online auction’s “ask a question” messaging feature. The Trojan also inflates the user feedback score of the purported buyer, according to Symantec.

In the intervening seven months, the Trojan has been updated so that, among other things, traffic bound for sites such as Carfax and nine other addresses maintained by third-party companies will also be redirected. This helps thwart victims who try to independently confirm details fed on the falsified eBay pages.

eBay spokeswoman Nichola Sharpe says the company’s security team has forwarded samples of the new strain to anti-virus companies so they can add it to the updates they send to customers.

Read the rest of this entry »

Posted in eCommerce, Security | 1 Comment »

UK PCs have least malware

An online malware measuring tool has unexpectedly rated U.K. PCs as having the lowest level of infection in Europe.

The Nanoscan tool, which can be downloaded as a plug-in from the site of owner Panda Software, put the U.K. in bottom spot last week, with only 8.1 percent of those scanned showing active malware. By a separate measure, that of ‘latent’ or inactive malware, however, the U.K. fared less well, reaching 20.7 percent.

Top of the infection list for active malware was France (28.2 percent), Mexico (23.1 percent), Brazil (18 percent), the U.S. (17.8 percent), and Argentina (17.4 percent).

The figures appear to show very high levels of infection, but the results only rate those who visited the site and asked to be scanned. These individuals would be expected to show a bias towards having infected PCs. The company has created its own global malware map from the data, which is collected from thousands of mostly consumer PCs every 15 minutes.

Interestingly, almost 8 percent of those scanned and who showed active threats also had anti-virus software installed, which appears to support the company’s controversial view that conventional signature-based malware detection is no longer enough to protect PCs.

“These figures prove that it must be complemented with online tools such as Nanoscan and Totalscan, which are capable of detecting more malicious codes than the solutions installed on users’ computers” said Luis Corrons of Panda Software.

Nobody knows for sure how many PCs are infected with malware at any one time, though last year Microsoft came up with the more optimistic figure of one in 300 Windows PCs in its own research.

Critics might point out that, flawed though anti-virus systems might be, they are no worse than online scanning tools, which are often promoted as marketing tools for paid-for products. This is the case with Nanoscan. Anyone passing the malware test with Nanoscan is invited to try the more advanced but paid-for Totalscan software.

Read the rest of this entry »

Posted in General, Hardware, Security | No Comments »

Mystery eBay ‘hack’ exposes 1,200 accounts

eBay is one of the most successful Internet-only ventures of all time, so it’s not surprising that it has come under near-constant attack by fraudsters and hackers. In the latest attempt, a hacker logged on to the eBay Trust and Security forums and pretended to post as 1,200 separate users, making it appear as if he had actually logged in with each user’s account. The posts contained the users’ names, contact information, and credit card numbers.

That done, the hacker posted a video of his exploits on YouTube to celebrate his “achievement” (the video has subsequently been taken down). In response, eBay and LiveWorld—the third-party software firm that operates eBay’s web-based forums—took the entire Trust and Security forum offline while they looked into the problem. The forum was taken down 90 minutes after the posts first hit the Web and was put back online later that day.

eBay issued an official statement on its eBay Chatter forum, stating that while the posts appeared to contain credit card information, the posted numbers did not correspond to credit card information that eBay had on file for those users. Nevertheless, the user names and contact information were accurate, and eBay claims they are attempting to get in contact by phone with each of the 1,200 users to ensure that they can protect themselves from any attempts at hijacking their accounts. At this time, eBay is unclear as to whether or not the accounts have been fully compromised. It is also not certain that only these 1,200 accounts are affected.

While the original posts and the YouTube video showing the list of names have been removed from the Web, an eBay member has grabbed as many of the account names as possible and posted them on a personal web site so that people can easily check to see if their account was one of the original 1,200. So far, the operator of this list has not been asked by eBay to take it down.

While this particular attack may not have revealed customers’ credit card information, there are plenty of fraudsters about who are trying their hardest to scam people out of their money: a helpful eBay forum member even posted a list of an astonishing 36 common scams currently being perpetrated against eBay users. Most of these involve social manipulation and phishing scams rather than direct attack, but clearly they are effective: videos of hacked accounts posting over 60,000 items for bid show what the bad guys are likely to do once they have your account information. It’s always a good idea to practice skeptical computing, but eBay users should take even greater care to ensure that they are not taken in by any of these scams.

An eBay representative did not return our request for a comment in time for publication.

Read the rest of this entry »

Posted in Internet, Security | No Comments »


Copyright © 2009 Red Canyon Ltd. All rights reserved.

Company Registration No. 6688868



Find us on Facebook! Find us on twitter! Read our blog! Bookmark us on delicious! Bookmark us on Stumbleupon!

We are listed on the FreeIndex.co.uk Web Designers directory