Announcement

Collapse
No announcement yet.

Theory on how I got ID Thefted

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Theory on how I got ID Thefted

    I think I know how and where my ID was hijacked a while back:

    Someone here posted a link to an Ebay auction, and when I clicked the link to view it, I was greeted with the EBay Sign In page. I was already signed in (or so I thought) and it didn't really dawn on me until recently that I've never ever had to sign in to view a listing, but I entered my Ebay ID and password anyway.
    I can't remember who posted the link, when it was posted, or what it was about [img]/images/graemlins/frown.gif[/img]

    I know there's an HTML line that you put in a page to email you the information that is typed into a text box on a web page, or to post it in a Guestbook, but I can't remember what it is.

    If I can find a way to stick this HTML function into an Ebay listing, I'm pretty sure it will throw up a Sign In page. Of course this will immediately be reported to Ebay as a security risk once I test it (using fake ID and passwords, obviously - just to see if it will mail the info to me and still proceed to the listing)

    I've seen it done with CGI and such, but I'm more interested in the HTML version, as a CGI version would most likely require the use of Ebay's CGI-BIN, unless you can specify an outside URL for a cgi or java script?

    The lines for the Ebay Sign In function (edited to not screw up here) are:


    eBay User ID<br><input type="text" name="userid" maxlength="64" tabindex="1" value="" size="27"><br>Password<br><input type="password" name="pass" maxlength="64" value="" tabindex="2" size="27"><br>
    <input type="submit" tabindex="3" value="Sign In Securely >">

    Anyone know how to rig this to email you the submitted info?
    I want to depart this world the same way I arrived; screaming and covered in someone else's blood

    The most human thing we can do is comfort the afflicted and afflict the comfortable.

    My Blog: http://newcenstein.com

  • #2
    Re: Theory on how I got ID Thefted

    45 views and no replies - looks like there's gonna be a rash of ID thefting on Ebay [img]/images/graemlins/poke.gif[/img] [img]/images/graemlins/laugh.gif[/img]
    I want to depart this world the same way I arrived; screaming and covered in someone else's blood

    The most human thing we can do is comfort the afflicted and afflict the comfortable.

    My Blog: http://newcenstein.com

    Comment


    • #3
      Re: Theory on how I got ID Thefted

      I'm pretty sure that is not possible. If the link is sent to ebay.com and not no where else you can't really do that.

      Unless he made a link look like ebay.com, but in reality its something like ebayy.com or something then ya they can get your info.

      Comment


      • #4
        Re: Theory on how I got ID Thefted

        When did your identity get stolen?

        Comment


        • #5
          Re: Theory on how I got ID Thefted

          You can't do that with HTML alone, sadly. You'll have to use a server side script language like CGI or PHP.

          However what you could do is this; fake an E-bay page. Make an HTML document look exactly like the ebay login page and run it off your server. You could actually make it so that somebody could log in to ebay and email you the name and password. If you want to know how to send the information off to ebay, look above the tags that you posted. You'll see a tag that says <form action="where the information goes"> The action attribute will be in there somewhere. There will probably be other attributes in that tag.

          How would you disguise the link? Well, you don't need to post the url. You could post something like this:
          This is not google's front page.

          Good luck with your little scam!

          Comment

          Working...
          X