<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-10483427</id><updated>2011-12-06T01:26:20.506-08:00</updated><title type='text'>About Me</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://toshogucentral.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10483427/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://toshogucentral.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-10483427.post-3722894344492227960</id><published>2009-04-19T13:31:00.000-07:00</published><updated>2009-04-19T13:32:00.006-07:00</updated><title type='text'>The Little Black Book of Security</title><content type='html'>&lt;span class="postbody" style="font-family: verdana;"&gt;When I found &lt;a href="http://www.scmagazineus.com/More-than-5000-pirated-eBay-credentials-found-on-web/article/119453/"&gt;this pile of EBay logins&lt;/a&gt; circulating around the Net, I did whatever any security person does in such a situation - ask around for "contacts at company x", so I could get them the data. However, this was going to take a good few hours so in the meantime, I could indulge in one of my favourite past-times.&lt;br /&gt;&lt;br /&gt;See, I do have lots of security connections at different companies and people who can GET me the contacts I need, but I always make a point of going through "standard" channels first, just to remind myself what its actually like for a regular web-user who finds something that shouldn't be out there.&lt;br /&gt;&lt;br /&gt;More often than not, it just reminds me that most methods of reporting illegal activity are fundamentally broken.&lt;br /&gt;&lt;br /&gt;What's alarming is that if it &lt;span style="font-style: italic;"&gt;hadn't&lt;/span&gt; been me - or some &lt;span style="font-style: italic;"&gt;other&lt;/span&gt; security person who'd found this data...if it was some regular web-user who didn't have that support structure to fall back on...this data would probably still be lying around online for people to use and abuse as they see fit.&lt;br /&gt;&lt;br /&gt;I won't bore you with &lt;span style="font-style: italic;"&gt;all&lt;/span&gt; the details, but I started off by calling the Paypal phone number. This predictably ended in disaster, because you have to login to Paypal and be assigned a unique reference number. The operator at the other end couldn't understand that the problem had nothing to do with my &lt;span style="font-style: italic;"&gt;own&lt;/span&gt; account (though he did spend about five minutes telling me all the security procedures he was going to deploy on my account to prevent any further fraud, which is nice of him if somewhat misplaced).&lt;br /&gt;&lt;br /&gt;Later that day, I went through a procession of vaguely hopeless "support staff" on EBay Live Chat. I demanded some kind of dedicated support team EMail address due to the severity of the problem - I think it was support guy number two who gave me an email address, eventually. Hooray! A dedicated, no-nonsense address to get things sorted out.&lt;br /&gt;&lt;br /&gt;Then I &lt;a href="http://www.google.co.uk/search?q=rswebhelp%40ebay.com&amp;amp;ie=utf-8&amp;amp;oe=utf-8&amp;amp;aq=t&amp;amp;rls=org.mozilla:en-US:official&amp;amp;client=firefox-a"&gt;Googled it&lt;/a&gt;, and upon seeing the second entry down rolled my eyes. In for the long haul, baby....&lt;br /&gt;&lt;br /&gt;I think it was the day after this (or maybe the day after that) that I tried one more time.&lt;br /&gt;&lt;br /&gt;Dispensing with the first Live Support guy thrown in my general direction, I was put through to someone on the "Security Team". After finding out &lt;span style="font-style: italic;"&gt;this&lt;/span&gt; person couldn't help me either, I was suddenly dumped into a chat with what I can only assume was the Final Boss of the Internet - or at least, the top dog, crap-we're-running-out-of-support-staff King of Live Support Security Team Guy.&lt;br /&gt;&lt;br /&gt;The below webchat is 100% genuine, and I have screenshots to prove it (though I've removed some unnecessary text, typos and other junk). You may blink, rub your eyes and slap yourself in the face a couple of times while reading it.&lt;br /&gt;&lt;br /&gt;This is entirely natural.&lt;br /&gt;&lt;br /&gt;Just imagine that I'm not a security researcher - I'm a regular web user, who just found 5,000+ logins and I really, &lt;span style="font-style: italic;"&gt;really&lt;/span&gt; want to get this to someone who can do something about it.&lt;br /&gt;&lt;br /&gt;That's all.&lt;br /&gt;&lt;br /&gt;Now watch it go horribly wrong.&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody" style="font-family: verdana;"&gt;&lt;br /&gt;3:03:27 PM System&lt;br /&gt;Connected with A&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:03:32 PM A&lt;/span&gt;: Hello and thank you for contacting Account Security Live Help, my name is A. Please give me a moment to review what you have already typed.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:06:33 PM A&lt;/span&gt;: Thank you for patiently waiting, based on what I just read, you want to report a stolen eBay account, am I correct?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:07:19 PM Paperghost&lt;/span&gt;: To be accurate: five thousand, five hundred and thirty four stolen accounts&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:08:23 PM A&lt;/span&gt;: I see, thank you for taking the time to report this issue. I will be reviewing it shortly. For future reports you wish to make, please use our webform:&lt;br /&gt;&lt;br /&gt;http://&lt;br /&gt;&lt;br /&gt;It will reduce any possible wait time in our chat sessions and also ensure that the information is sent to the correct team so they can review it in a more timely manner.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:09:00 PM Paperghost&lt;/span&gt;: You want me to paste five thousand, five hundred and thirty four ebay username and passwords into a contact us form?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:09:14 PM Paperghost&lt;/span&gt;: isn't there an email address that works that i can just send it to?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:10:53 PM A&lt;/span&gt;: You can use the link that I just provided you and below that there is "EMAIL US" link where you can send or paste those names.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:11:43 PM A&lt;/span&gt;: Please separate it with a space in between them.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:14:14 PM Paperghost&lt;/span&gt;: that contact form page wants me to paste in each username one at a time - there are over five thousand usernames in a word document. that contact form has a limit of 10,000 characters. the sum total of the stolen data comprises 243,347 words including spaces. It isn't physically possible for me to send it to you via that form&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:16:49 PM A&lt;/span&gt;: Sorry but that is the only link for us to report an account that was taken over by unauthorized third party.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:17:56 PM Paperghost&lt;/span&gt;: Well I have over five thousand stolen accounts here that need to be reported so someone is going to have to find me an email address I can send an email with a word document attached to it to&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:23:15 PM A&lt;/span&gt;: What I am going to do is to report all the users that you have and report it to our Trust and Safety team, if you don't mind, typing all those member's in our chat window.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:24:26 PM A&lt;/span&gt;: As I check on the link that I just provide you, you can separate all those name by putting a comma on it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:24:38 PM Paperghost&lt;/span&gt;: How am I supposed to type more than five thousand usernames into a chat window? You realise most of the account owners will be retired or deceased by the time I finish typing?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:25:55 PM A&lt;/span&gt;: As I check on the link that I just provide you, you can separate all those name by putting a comma on it.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:26:10 PM A:&lt;/span&gt; Just copy and paste it on the username.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:28:18 PM Paperghost&lt;/span&gt;: The word document I have has one username per line, and there are more than five thousand lines of text in the document. it would take me about six months non-stop typing to cut and paste each name from the document then paste it into this chat box&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:29:25 PM A&lt;/span&gt;: I have an alternative link for you to report those members, just copy those name and paste in on the link below:&lt;br /&gt;&lt;br /&gt;http://&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:31:08 PM Paperghost&lt;/span&gt;: That page is not going to accept five thousand lines of userdata submitted to it - and even if it did, i'm not sending all those usernames and passwords via a standard http:// page&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:31:25 PM Paperghost&lt;/span&gt;: you realise i could send you the whole thing via email in three seconds and bam, its done&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:32:06 PM A&lt;/span&gt;: That is an alternative link that connects you to our Trust and Safety team.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:33:55 PM Paperghost&lt;/span&gt;: your trust and safety team must have an email address i can send this information to, this is crazy&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:37:57 PM Paperghost&lt;/span&gt;: what option do i pick on the drop down menu&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:38:05 PM Paperghost&lt;/span&gt;: as none of them are applicable as these arent my accounts&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:38:43 PM Paperghost&lt;/span&gt;: never mind, i tried it and it crashed my browser.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:39:19 PM A&lt;/span&gt;: First drop down is misuse of eBay -&gt; report a user.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:42:05 PM Paperghost&lt;/span&gt;: as i said, unfortunately it crashes my browser. i don't think the form is designed to handle that much text&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:42:48 PM A&lt;/span&gt;: How about sending 100 username at a time?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:44:12 PM Paperghost&lt;/span&gt;: there are FIVE THOUSAND usernames on there. do you have any idea how long that is going to take?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3:45:02 PM A&lt;/span&gt;:  I do apologize but that is the only way. &lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-family: verdana;"&gt;If you want you can try sending that at &lt;/span&gt;&lt;span style="font-family: verdana;"&gt;spoof@ebay.com&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:45:28 PM Paperghost&lt;/span&gt;: &lt;/span&gt;&lt;span style="font-family: verdana;"&gt;i've already sent it to &lt;/span&gt;&lt;span style="font-family: verdana;"&gt;spoof@ebay.com&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;. twice. is there someone there who can check if theres a mail there from xxxxxxxxxxx&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; A&lt;/span&gt;: Yes we have a designated department that handles those mails, and once they have receive it they will immediately review before sending a respond to you. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:48:44 PM Paperghost&lt;/span&gt;: Yes but can someone at least confirm its in that departments mailbox even if they don't open it up &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:49:10 PM Paperghost&lt;/span&gt;: I'm trying to help you reclaim five thousand stolen ebay accounts here and it doesn't seem to be going very well &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:49:40 PM A&lt;/span&gt;: As much as I want to help you with that, I don't have the necessary tools to check on the mailbox. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:50:56 PM Paperghost&lt;/span&gt;: and nobody there is able to contact anyone from that team to check if its there? &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:52:21 PM A&lt;/span&gt;: Don't worry since you already forwarded an email, what we can advise is to please wait for an email confirmation in regards to the investigations.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:53:24 PM Paperghost&lt;/span&gt;:&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-family: verdana;"&gt; Okay&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:53:45 PM A&lt;/span&gt;: I do understand your concern. And we thank you also for taking your time reporting those members.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="postbody"&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:53:49 PM Paperghost&lt;/span&gt;: Thanks&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="postbody"&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold;"&gt; 3:54:16 PM A&lt;/span&gt;: You're very much welcome and thank you for using eBay, I hope you have a great day.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;.....doh.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;As it turns out, I was (eventually) sent a reply from the EMail address I was given by one of the support people. It said:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;"Dear eBay member,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;Thanks for your email. We want to help resolve any problems with your&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;account as quickly as possible.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;The fastest way for us to help you is through Live Help, where you can&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;have a one-on-one chat with one of our customer service agents. The chat&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;happens right in your web browser, so you don't need any special&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;software.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;Please let the chat agent know that you already sent us an email, as&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;that will help us speed things along.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;We won't receive any replies to this email, so please contact Live Help&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-family: verdana;"&gt;for further assistance."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;You couldn't make it up.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Of course, all of this was kind of irrelevant - the wheels were already in motion behind the scenes, and I'd consulted the Little Black Book of Security. Because of that, &lt;/span&gt;&lt;span style="font-family: verdana;"&gt;the data had &lt;span style="font-style: italic;"&gt;already&lt;/span&gt; been passed onto the people it needed to go to, despite the frontline support boobery, and I'd been assured it was being sorted out.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;But again - if I &lt;span style="font-style: italic;"&gt;didn't&lt;/span&gt; have access to that Black Book....what would have happened to this data? Would it still be sitting online for all and sundry to take what they wanted? Would I be going back into Live Chat in an endless cycle of utterly pointless attempts to get someone to do something about it?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Sad to say, but based on the evidence above - quite probably.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;It's kind of amazing that such a basic thing - look, here's some fraud and I want you to fix it - can't get past the brick wall that is frontline customer support.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;And also kind of depressing. No....make that alarming. Actually, make that puzzling.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;No....come to think of it, make it all of the above.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;And then some.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10483427-3722894344492227960?l=toshogucentral.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://toshogucentral.blogspot.com/feeds/3722894344492227960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10483427&amp;postID=3722894344492227960' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10483427/posts/default/3722894344492227960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10483427/posts/default/3722894344492227960'/><link rel='alternate' type='text/html' href='http://toshogucentral.blogspot.com/2009/04/little-black-book-of-security.html' title='The Little Black Book of Security'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
