Results 1 to 13 of 13

Thread: Someone trying to hack my eBay account

  1. #1
    Registered+
    Join Date
    Jan 2014
    Posts
    44
    Thanks
    1
    Thanked
    0 times in 0 posts
    • Dan the bloke's system
      • Motherboard:
      • Sabertooth 990fx
      • CPU:
      • Phenom II 1055t
      • Memory:
      • Corsair 8GB
      • Storage:
      • Crucial M500 120GB
      • Graphics card(s):
      • VTX3D 7870XT
      • PSU:
      • Enermax 700W Triathlor-FC
      • Case:
      • Coolermaster Elite 430
      • Operating System:
      • Windows 7

    Someone trying to hack my eBay account

    I'm not sure if this is the right forum for this, but someone seems to be trying to get into my ebay account.
    Ive got an email saying about how ive forgotten my password for ebay, and the origin of this was from 174.20.82.33 which appears to be from somewhere in Minnesota.
    Should I be worrying about this?
    And is there anything I should do?

  2. #2
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Someone trying to hack my eBay account

    Usually with those "forgotten password" emails, you can safely ignore them and the reset token will expire after 24 hours or so. If you have a simple or guessable password for eBay, change it to something that's hard to guess/crack and that you don't use elsewhere as soon as possible. Change your PayPal password to something different.

    It could also be that the password reset email itself is a scam, with malicious links, so make sure to go to eBay manually to change your password and not via any links in the email.

  3. #3
    Registered User
    Join Date
    Jan 2014
    Location
    Northumberland
    Posts
    12
    Thanks
    0
    Thanked
    2 times in 2 posts

    Re: Someone trying to hack my eBay account

    Change your password to something around 10 characters that incorporates both uppercase and lowercase letters and substitute letters for numbers.

    For Example
    H3xu5F0rum5

    hard to crack

  4. #4
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,025
    Thanks
    1,871
    Thanked
    3,383 times in 2,720 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Someone trying to hack my eBay account

    Quote Originally Posted by Lister View Post
    Change your password to something around 10 characters that incorporates both uppercase and lowercase letters and substitute letters for numbers.
    It's a bad idea to substitute letters for numbers and think that it gives you any extra security - for starters this is really obvious, and additional numbers don't add that many extra combinations to try for brute force approaches. Better to use unrelated combinations of words.

    Something like "H3xu5F0rum5" would be a bad password as it suffers from both of those problems (simple number substitution and related words).

  5. #5
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Someone trying to hack my eBay account

    Quote Originally Posted by kalniel View Post
    It's a bad idea to substitute letters for numbers and think that it gives you any extra security - for starters this is really obvious, and additional numbers don't add that many extra combinations to try for brute force approaches. Better to use unrelated combinations of words.

    Something like "H3xu5F0rum5" would be a bad password as it suffers from both of those problems (simple number substitution and related words).
    +1 This is particularly true if the 'attacker' is specifically targeting you, as they'll have some information on you already. A base wordlist can fizz through millions of iterations and substitutions in a very short amount of time.

    It's also good practice to use non alpha-numerics in your password ($£!%&_ etc.), a lot of word lists and brute force patterns will stick to alphanumeric characters to cut down on time - especially for impatient chancers with low resources.

    I'd think (hope) that eBay have a good system to prevent brute-force attacks.

  6. #6
    jim
    jim is offline
    HEXUS.clueless jim's Avatar
    Join Date
    Sep 2008
    Location
    Location: Location:
    Posts
    11,457
    Thanks
    613
    Thanked
    1,645 times in 1,307 posts
    • jim's system
      • Motherboard:
      • Asus Maximus IV Gene-Z
      • CPU:
      • i5 2500K @ 4.5GHz
      • Memory:
      • 8GB Corsair Vengeance LP
      • Storage:
      • 1TB Sandisk SSD
      • Graphics card(s):
      • ASUS GTX 970
      • PSU:
      • Corsair AX650
      • Case:
      • Silverstone Fortress FT03
      • Operating System:
      • 8.1 Pro
      • Monitor(s):
      • Dell S2716DG
      • Internet:
      • 10 Mbps ADSL

    Re: Someone trying to hack my eBay account


  7. #7
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,025
    Thanks
    1,871
    Thanked
    3,383 times in 2,720 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Someone trying to hack my eBay account

    Precisely. It still pees me off when accounts insist on using numbers in a password.

  8. #8
    Registered User
    Join Date
    Jan 2014
    Location
    Northumberland
    Posts
    12
    Thanks
    0
    Thanked
    2 times in 2 posts

    Re: Someone trying to hack my eBay account

    Quote Originally Posted by virtuo View Post
    +1 This is particularly true if the 'attacker' is specifically targeting you, as they'll have some information on you already. A base wordlist can fizz through millions of iterations and substitutions in a very short amount of time.

    It's also good practice to use non alpha-numerics in your password ($£!%&_ etc.), a lot of word lists and brute force patterns will stick to alphanumeric characters to cut down on time - especially for impatient chancers with low resources.

    I'd think (hope) that eBay have a good system to prevent brute-force attacks.
    You wouldn't believe the amount of people I come across that have their password set to 'password' or their name or date of birth. Picking a random word that has some meaning to you and using numbers etc is at the very least a hell of a lot better and the average user will be able to remember it.

    Yes you could go down the route of 20 character randomly generated passwords, there are free websites that will do this.

  9. #9
    Registered+
    Join Date
    Jan 2014
    Posts
    44
    Thanks
    1
    Thanked
    0 times in 0 posts
    • Dan the bloke's system
      • Motherboard:
      • Sabertooth 990fx
      • CPU:
      • Phenom II 1055t
      • Memory:
      • Corsair 8GB
      • Storage:
      • Crucial M500 120GB
      • Graphics card(s):
      • VTX3D 7870XT
      • PSU:
      • Enermax 700W Triathlor-FC
      • Case:
      • Coolermaster Elite 430
      • Operating System:
      • Windows 7

    Re: Someone trying to hack my eBay account

    Right, well id like to think my password is a pretty secure one, and this is a one off attack
    Ill probably just leave it because i dont keep any bank details on my account or anything. In fact Ive only used it once, and Im tempted to delete it now, haha

    Thanks for the insight guys!

  10. #10
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Someone trying to hack my eBay account

    Quote Originally Posted by Lister View Post
    You wouldn't believe the amount of people I come across that have their password set to 'password' or their name or date of birth. Picking a random word that has some meaning to you and using numbers etc is at the very least a hell of a lot better and the average user will be able to remember it.

    Yes you could go down the route of 20 character randomly generated passwords, there are free websites that will do this.
    Agreed. Kalniel is dead right that "H3xu5F0rum5" is far from strong, but it's at least better than "ebaypassword", or indeed "password".

    And, by the way, I would believe how many you come across using "password", or other similar phrases. During some security testing, I came across a number of wifi routers run by businesses that still used the default router password and username. Encryption was enabled, though.

    As for Dan's concerns, I'd endorse virtuo's answer.

  11. #11
    Senior Member
    Join Date
    Jun 2008
    Posts
    1,495
    Thanks
    2
    Thanked
    143 times in 119 posts
    • BobF64's system
      • Motherboard:
      • Asus P8Z77-V Pro
      • CPU:
      • Intel Core i7-3770K
      • Memory:
      • 16GB Corsair XMS3 PC3-12800
      • Storage:
      • Multiple HDD and SSD drives
      • Graphics card(s):
      • ASUS DUAL-GTX1060-06G
      • PSU:
      • 750W Silverstone Strider Gold Evolution
      • Case:
      • Silverstone Fortress FT02
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • HP ZR24w

    Re: Someone trying to hack my eBay account

    Don't forget, it might also be a mistake.

    Sometimes people mistype their email addresses, obviously if you have your own domain thats unlikely, and if you're on one of the free providers this could be why.

  12. #12
    Registered+
    Join Date
    Sep 2008
    Posts
    26
    Thanks
    0
    Thanked
    1 time in 1 post

    Re: Someone trying to hack my eBay account

    This can also happen if you have inadvertently used a VPN or proxy. Some corporate networks also route all of their traffic through the US so that can be a issue if you've tried to login from work.

  13. #13
    Registered+
    Join Date
    Dec 2012
    Posts
    42
    Thanks
    0
    Thanked
    1 time in 1 post
    • Aftermath's system
      • Motherboard:
      • Gigabyte Z77X-D3H
      • CPU:
      • Intel i5 3570K
      • Memory:
      • Corsair Vengeance LP
      • Storage:
      • 2 x Samsung 840, 2 x Seagate Barracuda
      • Graphics card(s):
      • EVGA GTX 780
      • PSU:
      • Corsair AX750
      • Case:
      • Corsair Air 540
      • Operating System:
      • Windows 8
      • Monitor(s):
      • Asus PB278Q 27" 2560x1440p + BenQ 2420HD 1920x1080
      • Internet:
      • Virgin Media

    Re: Someone trying to hack my eBay account

    Quote Originally Posted by virtuo View Post
    +1 This is particularly true if the 'attacker' is specifically targeting you, as they'll have some information on you already. A base wordlist can fizz through millions of iterations and substitutions in a very short amount of time.

    It's also good practice to use non alpha-numerics in your password ($£!%&_ etc.), a lot of word lists and brute force patterns will stick to alphanumeric characters to cut down on time - especially for impatient chancers with low resources.

    I'd think (hope) that eBay have a good system to prevent brute-force attacks.
    I wouldn't say it's a very short amount of time. Checking through millions of lines is going to take a good 6+ hours. Either way, agreed on the rest.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •