Results 1 to 19 of 19

Thread: Paypal

  1. #1
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default Paypal

    Well, until now after having my Paypal account for over 5 years (with the same simple password ) I haven't had any issues. On Jan. 31, I get an email from Paypal saying that my account has been frozen and I had to confirm my identity. I was under the impression that this was just a random thing. I logged in and it made me change my password and security question. It turns out that a hacker somehow figured out my password, logged into my account and spent 60 bucks. Already by this time Paypal had started a payment dispute and within a week I had the money back. This was very scary because the person who accessed my account had full access to withdraw money from my primary bank account.

    For that Paypal gets two thumbs up for me. Within 24 hours of this happening (without my knowledge at all) they had my account locked and started a payment dispute.

    For some reason I missed the initial payment email in my inbox. I have no idea how paypal realized that my account was hacked. I am assuming they used IP addresses, but I am not sure.

    I just wanted to share my positive experience with Paypal.
    {*insert snide remark here*}
    Trader Rating: +2112


  2. #2
    Join Date
    Dec 2006
    Location
    Cincinnati, OH
    Posts
    253

    Default

    Cool

    I use paypal for everything

  3. #3

    Default

    Quote Originally Posted by drew_goring View Post
    On Jan. 31, I get an email from Paypal saying that my account has been frozen and I had to confirm my identity ... I logged in and it made me change my password and security question. It turns out that a hacker somehow figured out my password,
    Sounds like you got Phished... Hook, line and stinker!

    http://www.paypal.com/cgi-bin/webscr...ySpoof-outside
    http://antivirus.about.com/cs/emails...lebayscam5.htm
    http://www.whitecanyon.com/newslette...scam-02-06.php

  4. #4
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Nope. Although I do have the sum of one hundred thousand united states dollars coming any day now via western union...

    That is what I first thought when I got the email. Then I looked back and I got a transaction record email from paypal the day before that I didn't notice saying that I paid 60 bucks for a 1 year membership to megaupload, which I didn't.

    I logged into my paypal account (not clicking on any email links because phishing was what I suspected), and was forced right away to change my password, security question and confirm my address (via phone which I have yet to do).

    They also started a dispute for me and on the 7th I got my money back, and it is in my PP account.
    {*insert snide remark here*}
    Trader Rating: +2112


  5. #5
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Here's the email that I got on Feb. 1...the day after the purchase was made on my account.

    {*insert snide remark here*}
    Trader Rating: +2112


  6. #6
    Join Date
    Jan 2007
    Location
    California, PA
    Posts
    234

    Default

    That's awesome that their security is that good. I get those paypal phishing emails now and then, and it always gives you a jump when it says that somebody used your account. Glad you got your money back.

  7. #7

    Default

    I had my Ebay account hacked at some point. I could no longer log into the account - password didn't work, security question didn't work. Emailed ebay, they told me I'd been hacked and would email me a new password.

    The email never came. Not in my inbox, not in my junk mail folder. Emailed to ask them to resend it, could not get a proper reply (just form responses that didn't speak to my request at all). Finally gave up and still don't have any access.

    Sounds like Paypal's support is a hell of a lot better than Ebay's.

  8. #8
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Quote Originally Posted by aceswired View Post
    I had my Ebay account hacked at some point. I could no longer log into the account - password didn't work, security question didn't work. Emailed ebay, they told me I'd been hacked and would email me a new password.

    The email never came. Not in my inbox, not in my junk mail folder. Emailed to ask them to resend it, could not get a proper reply (just form responses that didn't speak to my request at all). Finally gave up and still don't have any access.

    Sounds like Paypal's support is a hell of a lot better than Ebay's.
    I think if I had to contact them about anything I might have had a different experience. I never once had to email somebody, or wait for an email. I just can't believe how they determined that somebody unauthorized used my account, and then started a dispute for me...before I had any idea something happened.
    {*insert snide remark here*}
    Trader Rating: +2112


  9. #9

    Default

    Quote Originally Posted by aceswired View Post
    Sounds like Paypal's support is a hell of a lot better than Ebay's.
    One would think that their customer support would be the same, seeing as Ebay owns PayPal
    "Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
    - Albert Einstein (1879-1955)

  10. #10
    Join Date
    Jan 2006
    Location
    Toronto, Canada
    Posts
    682

    Default

    Drew how crap was your password? was it "igloo1" again?

    Maybe they knew because there was an internal breach where there was some password compromises, or they detected a brute force attack and then checked the password strengths. That is my guess.

    Remember everyone: use STRONG PASSWORDS! Over 7 characters in length with a combination of a symbol, a number, uppercase and lowercase!

    And change it every 60 days!

    -W.
    The Internet - All the Piracy, None of the Scurvy

  11. #11

    Default

    Quote Originally Posted by Monk View Post
    Remember everyone: use STRONG PASSWORDS! Over 7 characters in length with a combination of a symbol, a number, uppercase and lowercase!

    And change it every 60 days!
    Haha - then I'd be locked out of every account I own, because I'm not nearly organized to keep up with that.

  12. #12
    Join Date
    Jan 2006
    Location
    Toronto, Canada
    Posts
    682

    Default

    Quote Originally Posted by aceswired View Post
    Haha - then I'd be locked out of every account I own, because I'm not nearly organized to keep up with that.
    hehe. Well a good secret is to make it a phrase or something substituted in a kind of 'leetspeak (I know, I know terrible but it works). So for example Drew should have used My1gl00! instead as a password

    -W.
    The Internet - All the Piracy, None of the Scurvy

  13. #13
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Quote Originally Posted by Monk View Post
    hehe. Well a good secret is to make it a phrase or something substituted in a kind of 'leetspeak (I know, I know terrible but it works). So for example Drew should have used My1gl00! instead as a password

    -W.
    That is a great idea. I have used the same simple password for basically all of my online accounts for the past 5 years. Now I have it changed to a combination of letters, symbols and numbers. A great lesson for me to learn that could have turned out A LOT worse.
    {*insert snide remark here*}
    Trader Rating: +2112


  14. #14
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Quote Originally Posted by Monk View Post
    Drew how crap was your password? was it "igloo1" again?

    Maybe they knew because there was an internal breach where there was some password compromises, or they detected a brute force attack and then checked the password strengths. That is my guess.

    Remember everyone: use STRONG PASSWORDS! Over 7 characters in length with a combination of a symbol, a number, uppercase and lowercase!

    And change it every 60 days!

    -W.


    I am assuming brute force as well, although I am sure there are some things that I have signed up for in the past with the same password may have contributed to it as well.

    edit: actually igloo1 was a lot stronger than my old password...
    {*insert snide remark here*}
    Trader Rating: +2112


  15. #15

    Default

    Quote Originally Posted by drew_goring View Post
    Nope. Although I do have the sum of one hundred thousand united states dollars coming any day now via western union...

    That is what I first thought when I got the email. Then I looked back and I got a transaction record email from paypal the day before that I didn't notice saying that I paid 60 bucks for a 1 year membership to megaupload, which I didn't.

    I logged into my paypal account (not clicking on any email links because phishing was what I suspected), and was forced right away to change my password, security question and confirm my address (via phone which I have yet to do).

    They also started a dispute for me and on the 7th I got my money back, and it is in my PP account.
    Interesting. Guess you just gotta quit downloading all the goatse porn or get a trojan checker...

  16. #16
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Quote Originally Posted by Shagaroo View Post
    Interesting. Guess you just gotta quit downloading all the goatse porn or get a trojan checker...
    What I am thinking is it was a forum or something that somebody accessed the password through. I know that most encrypt the passwords, but a lot I guess don't either.

    So you think having tubgirl as my homepage has something to do with it??
    {*insert snide remark here*}
    Trader Rating: +2112


  17. #17
    Join Date
    Jan 2006
    Location
    Havana, Cuba
    Posts
    2,339

    Default

    Oh, and if I told you what my password has been for the last 5 years, you would laugh at how simple it is. Any simple cracking program out be able to figure it out.

    It's dumb because I know better too...I just though it could never happen to me.
    {*insert snide remark here*}
    Trader Rating: +2112


  18. #18
    Join Date
    Apr 2006
    Location
    Westminster, CO
    Posts
    2,067

    Default

    Quote Originally Posted by drew_goring View Post


    I am assuming brute force as well, although I am sure there are some things that I have signed up for in the past with the same password may have contributed to it as well.

    edit: actually igloo1 was a lot stronger than my old password...

    Brute force is tough if you have a good password. Encryption is one way, i.e., ther is no way to take an encrypted string and decrypt it back to the original. Most brute force password crackers will encrypt common words followed by a "1" or a "2" and compare the resulting encrypted string.

    I have found that taking a sentence or two and using the first letters of each word works well, then replace some of the letters with numbers. For example

    The days of summer are blazingly hot!

    would be

    Td0sabh!

    (no... I never used that one.)

    We ran brute force crackers years ago against several UNIX accounts and found that "susan1" and "susan2" were the most popular.

  19. Default

    I cancelled my Ebay account because someone other than me gained access and bid $1,000 on a pair of floral print mens jeans. Yeah, not only was I scammed, but the scammer must have been....well....you know....

    I cancelled my PayPal account after a friend had their funds frozen after buying a part for their AR-15. It seems that PayPal has a strict anti-gun tilt. Even when conducting buisness with certain people (totally legal, legit buisness), or anything pertaining to firearms PayPal reserves the right to freeze assets. Obivously I left.

    I look at it this way, in todays political climate if a private buisness wants to attack firearms because they are politically incorrect, now far behind is tobacco?

    I am a shooter, and cigar smoker. I couldn't justify supporting their buisness anymore.
    Last edited by mace85; 05-29-2007 at 07:23 PM. Reason: sp

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •