728_header.jpg (23748 bytes)
Google  Web AuctionBytes  

Home
Subscribe
Blog
Letters to Editor
EcommerceBytes
Podcasts
Forums
Merchant Directory
PR Service  
AuctionBytes TV
ABU Back Issues

Sponsor

COOL TOOLS

Calendar
eBay Fee Calculator
Collectors' Links
eBay Promo History
Bookshelf
Fraud Resources
Auction Site Fees
Auction Management
Payment Services
Storefronts Chart
Sniping Chart
Email List Hosting
Consignment Services
Drop-Off Store Laws
Ecommerce Resources
Photo Tips
Marketing Inserts
Yellow Pages
Classifieds

AUCTIONBYTES

Our Writers
Write For Us
Partners
Press
Advertising
About Us
Link To Us

150ab1.jpg 150ab2.jpg 150ab3.jpg

Auctionbytes-NewsFlash, Number 1638 - October 09, 2007 - ISSN 1539-5065      Previous Story | | Next Story

eBay Explains Security Hole Used by Hacker
By Ina Steiner
AuctionBytes.com
October 09, 2007
Reading AuctionBytes: eBay Explains Security Hole Used by Hacker

An eBay moderater apologized to users on a Trust & Safety discussion board over an incident that took place on Friday in which a hacker was able to suspend some member accounts. He explained, "This fraudster found very old administrative functions that had not been deactivated several years ago when we changed the security of our internal systems. These functions were still accessible on public servers, while the rest of our functionality is now behind multiple layers of security. We immediately identified the functions that he accessed and deactivated, and we are undergoing an audit to ensure obsolete code that may still exist for other reasons is secure."

Friday's incident was detailed on the AuctionBytes blog on Saturday and was believed by users to have been committed by a fraudster called Vladuz (http://blog.auctionbytes.com/cgi-bin/blog/blog.pl?/pl/2007/10/1191718840.html). The story was picked up on Monday by IDG News Service reporter Juan Carlos Perez (http://www.pcworld.com/article/id,138193-c,hackers/article.html).

The eBay moderator, posting on Monday evening, said no financial information had been accessed ("that is because credit card data is protected at a much higher level than contact information") and called the number of affected accounts a "handful."

He told affected users to write him at john_security@ebay.com if they had not received a phone call from eBay.

http://forums.ebay.com/db2/thread.jspa?threadID=2000445800

Email this story to a friend.


AddThis Social Bookmark Button
Previous Story | | Next Story

Related Stories
  • eBay Addresses Vladuz Hacking Incident - February 22, 2007, Issue #1480
  • He's Baaack - Vladuz 'Hacker' Taunts eBay - February 23, 2007, Issue #1481
  • Vladuz 'Captcha Populator' Tool Doesn't Worry eBay, Mozilla - March 06, 2007, Issue #1488
  • eBay Auction Listing Swings Remain a Mystery - March 12, 2007, Issue #1492
  • Romanian Hacker Vladuz Makes Another eBay Housecall - March 14, 2007, Issue #1494
  • eBay Shuts Trust & Safety Board after Credit Card Numbers Exposed - September 25, 2007, Issue #1628
  • eBay Denies Security Breach after User Information Exposed - September 26, 2007, Issue #1630
  • Hacker Email Address Used in Previous eBay Scams? - October 09, 2007, Issue #1638
  • eBay Hacker 'Vladuz' Arrested in Romania - April 18, 2008, Issue #1772



  • Discuss this story in our forums.

    Site Index
    Copyright 1999-2009. Steiner Associates LLC. All rights reserved. Privacy Policy.