Home U.S. Coin Forum

Looks like another e-bay scam

nederveitnederveit Posts: 1,038 ✭✭✭
Sorry if this has already been posted recently, but I got this e-mail today, looks bogus, so beware:


Five password bruteforcing attems were performed on your eBay account.

You must register and ID Verify certificate in order to remain in the eBay Community.


Dear eBay Community Member,
You (or someone else) has attempted to log in with your eBay ID and 5 diffrent wrong passwords.

According to our site policy you will have to confirm that you are the real owner of the eBay account by completing the following form or else your account will be suspended within 24 hours for investigations.

Establish your proof of identity with ID Verify (free of charge) - an easy way to help others trust you as their trading partner. The process takes about 5 minutes to complete and involves updating your eBay information. When you're successfully verified, you will receive an ID Verify icon in your feedback profile. Currently, the service is only available to residents of the United States and U.S. territories (Puerto Rico, US Virgin Islands and Guam.)

Confirm my account information and continue beeing a member of the eBay Online Auction Community.

Never share your eBay password to anyone!


Comments

  • MyqqyMyqqy Posts: 9,777
    5 diffrent wrong passwords.

    I'm really surprised that computer geek scumbags who try these scams seem to frequently forget to use a spell checker........ image
    My style is impetuous, my defense is impregnable !
  • got this one today.
    forward to spoof@ebay.com
    its BS
    image
  • Fake, I would say:

    C:Documents and SettingsNutty McSh*thead>tracert ebay.scgi8-update.com

    Tracing route to premium2.geo.yahoo.akadns.net [66.218.79.159]


    as compaired to:

    C:Documents and SettingsNutty McSh*thead>tracert www.ebay.com

    Tracing route to pages.ebay.com [66.135.192.88]
  • lordmarcovanlordmarcovan Posts: 43,940 ✭✭✭✭✭
    What is a "bruteforcing attem" ? image

    Explore collections of lordmarcovan on CollecOnline, management, safe-keeping, sharing and valuation solution for art piece and collectibles.
  • CoppernicusCoppernicus Posts: 1,764
    SCAM!! - So far, I've never been hit by one of these - I get them all the time but so far (knock on wood), I sense they're bogus immediately so I am unscathed. I'm very skeptical in all things.

    One of my favorite sayings: "My pessimism extends to the point of suspecting the sincerity of other pessimists."

    Mike
    Coppernicus

    Lincoln Wheats (1909 - 1958) Basic Set - Always Interested in Upgrading!
  • Scam is right, and I get them all the time too. I copy the address and send it to e-bay, if they do anything or not I don't know.

    Definiately Never give out your info!!! E-bay wont ask for your info like that!!

    Katrina
  • nederveitnederveit Posts: 1,038 ✭✭✭
    There are different ways to "crack" or discover passwords, and brute force refers to a type of attack that tries all combinations of a given range. It is a sort of trial of the strength of your computer processing power due to all the possible keys.

    Many computer users use simple and/or flawed passwords, thus making Brute Force successful. If a password consists of 4 numbers, then there are 10*10*10*10 possible combinations, so that is 10,000 total combinations. In that case the BF attack is very simple, testing all possible combinations. When the key is long and complicated using Brute Force is pointless, your computing power will not suffice, and you have to look for other weak links in the system if you want to force your way in.

    Brute force cracking programs will attempt to crack the password using every combination of numeric, alphabetic and special characters available no matter how long it takes. In other words, given enough time, brute force cracking will eventually determine the password, IF DONE OFF-LINE or if done online on a system where no account policies have been set, e.g. lock account after 3 bad attempts. Many times a Brute Force attack finds ways to eliminate a lot of possible combinations and then do the actual attack on the remaining few combinations.

    If an intruder simply tries every combination against the system whilst online, MOST good (a relative term here!) systems will eventually lock out the account. However, if the attacker manages to get a copy of the passwords in encrypted format, for example the SAM file in Windows NT, the attacker can then copy the file to another location on his/her own system and then take as much time as needed to crack the password using Brute Force off-line.

    A good PC can manage 1,000,000 combinations per second. An IBM mainframe can manage 12,300,000,000,000 combinations/second.

  • HEY WARNING Two years ago I received something along those lines and we ignored it. Well, the next day we were locked out of our account by eBay for our own protection. And, it took a bit to get it all straightened out. Well, one way to see if it's legit is to have someone try signing into their own eBay account with 5 phony passwords, and see if they get a e-mail from eBay. It sounds bogus though.


    Jerry
  • Conder101Conder101 Posts: 10,536
    Dear eBay Community Member, <------- First clue it is a fake. A real ebay email will address you by name.

    Confirm my account information and continue beeing a member of the eBay Online Auction Community. <----Second clue. Ebay will not provide a clickable link for you to follow and enter sensitive information.

    Third clue is if you follow the link the "ebay sign in" is NOT a secure web site address.
  • CoppernicusCoppernicus Posts: 1,764
    Nice points condor - the http versus the https is one I always look for. That and the URL in the link - once you know what the real ebay/paypal address is, the fakes will jump out at you. It pays to pay attention!

    Mike
    Coppernicus

    Lincoln Wheats (1909 - 1958) Basic Set - Always Interested in Upgrading!

Leave a Comment

BoldItalicStrikethroughOrdered listUnordered list
Emoji
Image
Align leftAlign centerAlign rightToggle HTML viewToggle full pageToggle lights
Drop image/file