Anyone see the newly listed items on eBay this morning?

I decided to surf- and the first 5 items were PORN. I tried to get to the auctions to report them, but they redirect you to a phishing site login. I've never seen this kind of phishing redirect on eBay before, and this could be VERY dangerous...what's the best way to report it?
--Christian
--Christian
You Suck! Awarded 6/2008- 1901-O Micro O Morgan, 8/2008- 1878 VAM-123 Morgan, 9/2022 1888-O VAM-1B3 H8 Morgan | Senior Regional Representative- ANACS Coin Grading. Posted opinions on coins are my own, and are not an official ANACS opinion.
0
Comments
<< <i>Link to the porn, please >>
The porn didn't bother me, but I know others would find it offensive, and it's definitely not what you would want your YN to stumble on. My main concern is that someone has figured out how to redirect to a phishing site when you click an eBay item to view it.
--Christian
Domain name: rosstravis.com
Registrant Contact:
Travis Ross (nin_antichrist@hotmail.com)
+1.9058477686
Fax:
1292 Fairmeadow Trail
oakville, ON l6m 2m2
CA
Administrative Contact:
Travis Ross (nin_antichrist@hotmail.com)
+1.9058477686
Fax:
1292 Fairmeadow Trail
oakville, ON l6m 2m2
CA
Technical Contact:
Travis Ross (nin_antichrist@hotmail.com)
+1.9058477686
Fax:
1292 Fairmeadow Trail
oakville, ON l6m 2m2
CA
Status: Active
Name Servers:
ns3.tektonic.net
ns4.tektonic.net
Creation date: 13 Sep 2007 18:08:13
Expiration date: 13 Sep 2008 18:08:13
NSDR - Life Member
SSDC - Life Member
ANA - Pay As I Go Member
<< <i>To me, the implications of this could be staggering. If they can redirect to a phishing site, they can also redirect to a real-looking item view page that takes you to a login screen when you click the bid button or 'My bBay'.... >>
If you keep your IE updated it catches it. --Jerry
NSDR - Life Member
SSDC - Life Member
ANA - Pay As I Go Member
NSDR - Life Member
SSDC - Life Member
ANA - Pay As I Go Member
I am a bit concerned over this since how in the world did they get a re-direct on the main EBay search results pages???
The name is LEE!
Great thread
``https://ebay.us/m/KxolR5
<< <i>I saw if under seller id jetta6799 but that appears to have been cleaned up.
I am a bit concerned over this since how in the world did they get a re-direct on the main EBay search results pages??? >>
Yes, that was the account. The redirect was not formt he search results page. Any of the porn lots did redirect. It was accomplished through an embed src tag to a tinyurl redirect in the eBay description section.
NSDR - Life Member
SSDC - Life Member
ANA - Pay As I Go Member
--Christian
In honor of the memory of Cpl. Michael E. Thompson
<< <i>If they can redirect to a phishing site, they can also redirect to a real-looking item view page that takes you to a login screen when you click the bid button or 'My bBay'.... >>
They already do that... that's the number one way that people have their EBay password stolen.
You click the auction, then you're asked to log in... but... you have to look at the URL!
IE7 does a pretty good job stopping that crap though. I had it twice last week and reported both auctions.
It's so common, you click a link in EBay and you're asked to log in, if it wasn't for IE7, a sharp eye, or some other tool... my password would have been a goner!
Hoard the keys.
domain or IP address your browser is surfing too. i always watch
the address bar for that crap.
otherwise, does ebay.com/ somehow magically stay in the address
bar during this exploit/phishing attempt/cross site scripting crap?
something tells me one can obfuscate it but one would need another
exploit of the browser to make is say one thing but do another...
fancy hack that.
<< <i>To me, the implications of this could be staggering. If they can redirect to a phishing site, they can also redirect to a real-looking item view page that takes you to a login screen when you click the bid button or 'My bBay'.... >>
That had already been done long ago. I have seen it before.
San Diego, CA
<< <i>
<< <i>I saw if under seller id jetta6799 but that appears to have been cleaned up.
I am a bit concerned over this since how in the world did they get a re-direct on the main EBay search results pages??? >>
Yes, that was the account. The redirect was not formt he search results page. Any of the porn lots did redirect. It was accomplished through an embed src tag to a tinyurl redirect in the eBay description section. >>
The redirected to site could also be a victim, who knows.
San Diego, CA
The other thing is that people often have the status bar at the bottom and rely on it. Can that ever be made to say whatever you want it to say for IE.
NSDR - Life Member
SSDC - Life Member
ANA - Pay As I Go Member
<< <i>
<< <i>
<< <i>I saw if under seller id jetta6799 but that appears to have been cleaned up.
I am a bit concerned over this since how in the world did they get a re-direct on the main EBay search results pages??? >>
Yes, that was the account. The redirect was not formt he search results page. Any of the porn lots did redirect. It was accomplished through an embed src tag to a tinyurl redirect in the eBay description section. >>
The redirected to site could also be a victim, who knows. >>
Yes, that is possible, since it was a new domain and a fresh install of a known vulnerable apache server version.
NSDR - Life Member
SSDC - Life Member
ANA - Pay As I Go Member
<< <i>I've seen this before. I just wish the pictures were bigger. ;-) >>
You are sooooo BAD!
The name is LEE!