eBay Hacked – 128 Million Users To Reset Passwords

Use Netsparker


The big news this week is that the massive online auction site eBay has been hacked, the compromise appears to have taken place a few months around February/March but has only come to light recently when employee login credentials were used.

eBay Hacked

This is 3 times bigger than the massive 42 Million passwords leaked by Cupid Media last November. But as least they are hashed this time, in the case of Cupid Media – the passwords were in plain text.

eBay‬ has told people to change their passwords for the online tat bazaar after its customer database was compromised.

Names, dates of birth, phone numbers, physical addresses, email addresses, and “encrypted” passwords, were copied from servers by attackers, we’re told. Credit card numbers and other financial records were not touched, and are stored separately, eBay claims. The website has hundreds of millions of user accounts.

Hackers accessed the database between late February and early March after obtaining a few employees’ login credentials, and then infiltrated the corporate network.

The digital break-in of staff accounts was detected about two weeks ago, and sparked a computer-forensics probe that is still ongoing. The website’s investigators today revealed a database containing customer information was accessed by the hackers.

eBay reckons everyone should change their passwords as a precaution – but it hasn’t uncovered any evidence of fraud linked to the breach, it claims. One assumes eBay’s techies have closed the hole the attackers exploited to infiltrate its systems, and has cleared its systems of the miscreants.


The passwords should be reasonably secure as they are hashed and apparently salted too, but the encryption algorithm used is currently unknown. If the passwords do go public, perhaps we can use something like HashTag to identify the hash type and see how secure it is.

And the salting, whilst it doesn’t make a single password much more secure, it does make cracking sets of passwords with Rainbow Tables much harder.

eBay’s handling of the breach notification has already created a fair bit of confusion: eBay-owned PayPal published then deleted an alert instructing users to change up their passwords this morning.

The brief item on PayPal’s site, which included the line “place holder text”, was pulled before the security breach was confirmed soon after in a press release. The warning was eventually restored, although PayPal is not affected by the eBay hack.

The exposure of encrypted passwords is bad news because it’s now easy to create convincing phishing emails urging people to change their eBay passwords – although said scam emails will instead take victims to a site masquerading as eBay.com to swipe their details.

Weak passwords could also be easily cracked if the website’s hashing algorithm isn’t up to scratch, and woe betide anyone using the same crap password across multiple sites with the same email address. The habit of many users of using the same password on multiple sites makes this type of attack all too possible.

You can read the official release on the corporate site here:

eBay Inc. To Ask eBay Users To Change Passwords

I hope more technical details are released as everything seems a bit wishy-washy right now, like how exactly did they get compromised? The biggest danger right now is probably Phishing, someone could capitilize on the list of confirmed eBay users and e-mail them all to reset their passwords on a bogus site.

It’s early days though, I’m sure more info will be released as time goes by (or not, as corporates to tend to like to keep a lid on such incidents).

Source: The Register

Posted in: Exploits/Vulnerabilities, Password Cracking, Web Hacking

, ,


Latest Posts:


StaCoAn - Mobile App Static Analysis Tool StaCoAn – Mobile App Static Analysis Tool
StaCoAn is a cross-platform tool which aids developers, bug bounty hunters and ethical hackers performing mobile app static analysis on the code of the application for both native Android and iOS applications.
snallygaster - Scan For Secret Files On HTTP Servers snallygaster – Scan For Secret Files On HTTP Servers
snallygaster is a Python-based tool that can help you to scan for secret files on HTTP servers, files that are accessible that shouldn't be public and can pose a s
Portspoof - Spoof All Ports Open & Emulate Valid Services Portspoof – Spoof All Ports Open & Emulate Valid Services
The primary goal of the Portspoof program is to enhance your system security through a set of new camouflage techniques which spoof all ports open and also emulate valid services on every port.
Cambridge Analytica Facebook Data Scandal Cambridge Analytica Facebook Data Scandal
One of the biggest stories of the year so far has been the scandal surrounding Cambridge Analytica that came out after a Channel 4 expose that demonstrated the depths they are willing to go to profile voters, manipulate elections and much more.
GetAltName - Discover Sub-Domains From SSL Certificates GetAltName – Discover Sub-Domains From SSL Certificates
GetAltName it's a little script to discover sub-domains that can extract Subject Alt Names for SSL Certificates directly from HTTPS websites which can provide you with DNS names or virtual servers.
Memcrashed - Memcached DDoS Exploit Tool Memcrashed – Memcached DDoS Exploit Tool
Memcrashed is a Memcached DDoS exploit tool written in Python that allows you to send forged UDP packets to a list of Memcached servers obtained from Shodan.


Comments are closed.