Someone stole my Hotmail and Ebay accounts

Miscellaneous Forums/General Discussion/Someone stole my Hotmail and Ebay accounts

It may be coincidence but after the recent security breach here on the Blitz forum, I'm not so sure.

Basically today someone got into my Hotmail account and changed the password and security details. Subsequently they did the same with my eBay account and hijacked the item I'm selling, changing the seller id (a 6 grand car btw!) Obviously I've contacted Microsoft and Ebay, but I'm just twiddling my thumbs till they get back to me. Fortunately there aren't any links to my Paypal or bank accounts from Hotmail.

While this may have nothing to do with my Blitz account, I did register here with my hotmail account and my Blitz password was the same as my Hotmail password. Stupid, I know. Obviously I changed it after the announcement, but by then it would have been too late.

So, like I say, it may be a coincidence, but for peace of mind make sure you update your email passwords, especially if it matches your Blitz password.

Well, as I said before - I believe at least one person was actively trying to gain password information - theoretically, I think they can also access an eBay cookie or any other one - not just the BRL one. The BRL one certainly had the password in it.

I'm not sure what action BRL took, other than banning them.

However, if eBay or Microsoft, etc query anything then mention the incident that happened here.

Having said that - you were probably more likely to have been taken over from the eBay side of things. eBay accounts can be hacked from especially if you use hotmail email accounts.

EDIT:
Having said that to - I've only seen evidence of gmail accounts and eBay being hacked.

Stupid question, but did you at any point in time receive one of those noticed 'from ebay' telling that you needed to log in to verify your account information, or telling you to change your password?

If you ever filled one of those things out, then that's probably how they stole your ebay account. There's a lot of scammers stealing login info that way, and all they need to do is sit back and wait for a big ticket item to come by and swoop in to hijack the auction.

They could have had your login for years, just never bothered to abuse it until it got interesting just now.

This is the first I've heard of a security breach. Do we have any idea how many passwords were potentially compromised? All of them?

Well, to give you the info on what happened... Long time no see you posty by the way. :)

There was a Russian Guy who posted on the forum selling a Blitz3D wrapper. He wrapped Blitz3D and made it possible to use it with other languages.

The community reacted defensively as it was a bold face cheek to sel a wrapped blitz3d to BRL customers.

He was told to cease and desist. Which I think he did.

Then, the Blitz3D SDK was released and it made him angry to the point where he was calling Mark a theif.

He then put a java script in his sig that had the capability of reading people's passwords from the BRL cookie stored on their systems.

As far as I'm aware this hack only affected IE6.

So, if you haven't changed your password yet, best change it now.

Worklog entry about security breach below.

http://www.blitzbasic.com/logs/userlog.php?user=1&log=1043


:)

Thanks for the info, Amon. That's good to know that it only affected IE6.

Long time no see you posty by the way. :)
I've been getting into Palm development among other things, but I still lurk from time to time. Glad to see you're still here being helpful :)

Also the exploit did not work as it used the wrong syntax. Had it had the correct syntax members would of been directed off bb.com and transferred to his site (due to the nature of how it worked).

I don't know if his method worked in pre IE6 (any IE5 users?) but it definitely didn't work in IE6. Even if he had written out the exploit correctly it didn't work in any other browser but IE6.


I think they can also access an eBay cookie or any other one - not just the BRL one


The exploit could only read the site cookie it was on and not others. Plus most sites don't store a plain text password in a cookie.

Overall I'd not worry about the attempted exploit - It didn't work :P

(1) How do you know it used the wrong syntax?
(2) Internet Explorer has never been very good with javascript, the hack might have affected Netscape users...
Not sure about anything, just throwing ideas around...

@xlsior: I'm wise to Phishing sites so there's no way I would have fallen for that.

I use Firefox 99% of the time. I don't know how secure that would have been against the hack. Like I say, it may be unconnected with Blitz but my hotmail address was in my profile and my pw was the same as the Blitz one. From there I'm guessing they could have reset my Ebay account.

BTW, Ebay got back to me within a couple of hours having taking action to secure the account. I'm still waiting for MS. :rolls_eyes:

eikon: This text has appeared at the top of the forum screens for the last two months now:

Important: Please read this note concerning site security.
-> with a hyperlink to: http://www.blitzmax.com/logs/userlog.php?user=1&log=1043


The exploit could only read the site cookie it was on and not others. Plus most sites don't store a plain text password in a cookie.


Just looked at my blitzmax.com cookie, and it definitely stores the password in plain text. :-?

Anyway, this kind of shows again how important it is to have unique passwords for different sites, so if one gets compromised they don't immediately have full access to your other accounts. Siread: if you happen to use the same password anywhere else ((especially if there is online banking involved) make sure to change it right away.

Even if you want to limit the # of passwords for convenience sake, at the very least use a different password for 'important' / financial sites as you do for 'fun' sites.


(1) How do you know it used the wrong syntax?


Because I tested it to see if it did work. I wanted to know if my password for BB had been stolen.

(2) Internet Explorer has never been very good with javascript, the hack might have affected Netscape users...
No. Even Internet Explorer 6 prevents cross-site scripting.

I use Firefox 99% of the time. I don't know how secure that would have been against the hack.
Perfectly.

If brl could prove someone was hacking their accounts they should have given the details to the police.

And STILL waiting for Microsoft. Ebay is sorted though.