eBay Hacked – 128 Million Users To Reset Passwords

Keep on Guard!


The big news this week is that the massive online auction site eBay has been hacked, the compromise appears to have taken place a few months around February/March but has only come to light recently when employee login credentials were used.

eBay Hacked

This is 3 times bigger than the massive 42 Million passwords leaked by Cupid Media last November. But as least they are hashed this time, in the case of Cupid Media – the passwords were in plain text.

eBay‬ has told people to change their passwords for the online tat bazaar after its customer database was compromised.

Names, dates of birth, phone numbers, physical addresses, email addresses, and “encrypted” passwords, were copied from servers by attackers, we’re told. Credit card numbers and other financial records were not touched, and are stored separately, eBay claims. The website has hundreds of millions of user accounts.

Hackers accessed the database between late February and early March after obtaining a few employees’ login credentials, and then infiltrated the corporate network.

The digital break-in of staff accounts was detected about two weeks ago, and sparked a computer-forensics probe that is still ongoing. The website’s investigators today revealed a database containing customer information was accessed by the hackers.

eBay reckons everyone should change their passwords as a precaution – but it hasn’t uncovered any evidence of fraud linked to the breach, it claims. One assumes eBay’s techies have closed the hole the attackers exploited to infiltrate its systems, and has cleared its systems of the miscreants.


The passwords should be reasonably secure as they are hashed and apparently salted too, but the encryption algorithm used is currently unknown. If the passwords do go public, perhaps we can use something like HashTag to identify the hash type and see how secure it is.

And the salting, whilst it doesn’t make a single password much more secure, it does make cracking sets of passwords with Rainbow Tables much harder.

eBay’s handling of the breach notification has already created a fair bit of confusion: eBay-owned PayPal published then deleted an alert instructing users to change up their passwords this morning.

The brief item on PayPal’s site, which included the line “place holder text”, was pulled before the security breach was confirmed soon after in a press release. The warning was eventually restored, although PayPal is not affected by the eBay hack.

The exposure of encrypted passwords is bad news because it’s now easy to create convincing phishing emails urging people to change their eBay passwords – although said scam emails will instead take victims to a site masquerading as eBay.com to swipe their details.

Weak passwords could also be easily cracked if the website’s hashing algorithm isn’t up to scratch, and woe betide anyone using the same crap password across multiple sites with the same email address. The habit of many users of using the same password on multiple sites makes this type of attack all too possible.

You can read the official release on the corporate site here:

eBay Inc. To Ask eBay Users To Change Passwords

I hope more technical details are released as everything seems a bit wishy-washy right now, like how exactly did they get compromised? The biggest danger right now is probably Phishing, someone could capitilize on the list of confirmed eBay users and e-mail them all to reset their passwords on a bogus site.

It’s early days though, I’m sure more info will be released as time goes by (or not, as corporates to tend to like to keep a lid on such incidents).

Source: The Register

Posted in: Exploits/Vulnerabilities, Password Cracking, Web Hacking

, ,


Latest Posts:


OSSIM Download - Open Source SIEM Tools & Software OSSIM Download – Open Source SIEM Tools & Software
OSSIM is a popular Open Source SIEM or Security Information and Event Management (SIEM) product, providing event collection, normalization and correlation.
What You Need To Know About KRACK WPA2 Wi-Fi Attack What You Need To Know About KRACK WPA2 Wi-Fi Attack
The Internet has been blowing up in the past week about the KRACK WPA2 attack that is extremely widespread and is a flaw in the Wi-Fi standard itself.
Spaghetti Download - Web Application Security Scanner Spaghetti Download – Web Application Security Scanner
Spaghetti is an Open-source Web Application Security Scanner, it is designed to find various default and insecure files, configurations etc.
Taringa Hack - 27 Million User Records Leaked Taringa Hack – 27 Million User Records Leaked
The Taringa hack is actually one of the biggest leaks of the year with 27 million weakly hashed passwords breached, but it's not often covered in the West.
A2SV - Auto Scanning SSL Vulnerability Tool For Poodle & Heartbleed A2SV – Auto Scanning SSL Vulnerability Tool For Poodle & Heartbleed
A2SV is a Python-based SSL Vulnerability focused tool that allows for auto-scanning and detection of the common and well-known SSL Vulnerabilities.
VHostScan - Virtual Host Scanner With Alias & Catch-All Detection VHostScan – Virtual Host Scanner With Alias & Catch-All Detection
VHostScan is a Python-based virtual host scanner that can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.


Comments are closed.