eBay security issue — eBay Trust and Safety Department
The following is an email I received the 10 of Marsh 2005. As you can see it includes an address in .nl which has nothing to do with ebay. And I won't mention that I'm not a member so it couldn't really affect me, could it?!
Since the person was connected at the time I checked the email, I got a trace route:
traceroute to 209.174.122.21 (209.174.122.21), 30 hops max, 38 byte packets
1 cayman (192.168.1.254) 0.468 ms 0.391 ms 0.369 ms
2 adsl-64-166-38-37.dsl.scrm01.pacbell.net (64.166.38.37) 8.089 ms 7.153 ms 7.408 ms
3 dist1-vlan60.scrm01.pbi.net (64.171.152.130) 7.859 ms 7.243 ms 7.524 ms
4 bb2-g8-3-0.scrm01.pbi.net (64.171.152.248) 7.611 ms 7.446 ms 7.913 ms
5 bb1-p12-0.scrm01.sbcglobal.net (151.164.188.125) 8.057 ms 7.909 ms 7.598 ms
6 bb1-p10-3.crscca.sbcglobal.net (151.164.188.121) 11.649 ms 13.327 ms 11.301 ms
7 ex2-p14-0.eqsjca.sbcglobal.net (151.164.242.230) 12.494 ms 13.526 ms 12.377 ms
8 ex1-p10-0.eqsjca.sbcglobal.net (151.164.191.66) 215.758 ms 139.392 ms 213.456 ms
9 sl-st20-sj-0-0.sprintlink.net (144.223.242.81) 12.069 ms 12.942 ms 12.657 ms
10 sl-bb21-sj-9-0.sprintlink.net (144.232.9.59) 104.169 ms 14.369 ms 30.610 ms
11 sl-bb24-chi-3-0.sprintlink.net (144.232.20.160) 59.922 ms 60.763 ms 60.629 ms
12 sl-bb23-chi-14-0.sprintlink.net (144.232.26.102) 60.435 ms 60.982 ms 60.320 ms
13 sl-gw36-chi-15-0.sprintlink.net (144.232.26.66) 60.543 ms 59.331 ms 59.183 ms
14 sl-nufx-6-0.sprintlink.net (144.223.21.18) 59.826 ms 60.902 ms 60.124 ms
15 pos-6-0-nap-sob2-nap-sob1.chicago.lincon.net (206.166.9.121) 65.105 ms 65.320 ms 65.295 ms
16 POS-1-0-6-PeoriaCore-PEO-P1-1-NapSOB1-CHI-P1.lincon.net (206.166.5.66) 65.824 ms 65.371 ms 65.298 ms
17 POS-4-0-6-NewPeoCore-PEO-P2-6-PeoriaCore-PEO-P1.lincon.net (206.166.9.134) 64.562 ms 65.615 ms 64.873 ms
18 atm2-0-sub03-peoria-core-wiu-core.macomb.lincon.net (206.166.9.198) 65.011 ms 65.816 ms 66.240 ms
19 atm-1-0-0-4-wiu-core-wiu-dist.macomb.lincon.net (206.166.9.130) 65.279 ms 123.672 ms 79.265 ms
20 s1-wiu-ii-union.macomb.lincon.net (206.166.85.46) 75.213 ms 68.839 ms 79.473 ms
21 linuxuhs.union.115.k12.il.us (209.174.122.21) 81.830 ms 68.362 ms 68.297 ms
The "home" page at 209.174.122.21 was the default Fedora Core Test Page.
The directory listing wasn't turn off so the place were the PHP scripts replacing the ebay regular scripts was visible:
Index of /.signin.ebay.com/ws
Name Last modified Size Description
Parent Directory -
eBayISAPIdllPlaceCCInfo.php 30-Nov-2004 13:21 44K
eBayISAPIdllPlaceCCInfoError.php 30-Nov-2004 13:21 18K
eBayISAPIdllSignIn.php 30-Nov-2004 13:21 22K
eBayISAPIdllSignInError.php 30-Nov-2004 13:21 22K
eBayISAPIdllThankYou.php 10-Mar-2005 04:01 19K
pic/ 06-Jul-2004 03:23 -
Apache/2.0.52 (Fedora) Server at 209.174.122.21 Port 80
These "scripts" are actually HTML pages for most.
At least the script "eBayISAPIdllThankYou.php" includes a virus which attacks MS-Windows using a buffer overun in visual basic.
I made a package that you can download here: ebay-trust.zip (use wget if your browser wants to load this file as an HTML page). My package doesn't include the images.
Of course, all of this is illegal and it looks like someone has been hacked in the US (the hackers rarelly do this sort of a thing on their own computers.)
The table below includes style sheets from Yahoo! which may change with time and this it may not look right in a while. Sorry!
Update Your Account Information Within 24 Hours