Whatever information was obtain was used to attempt to access my paypal account on September 6th and September 9th.
This is the IP of the first attempt, the second, on September 9th is identical.
84.47.180.168 Sep. 6, 2006 14:52:33 PDT Russia
These forums are CLOSED. Please visit the new forums HERE
Change your PayPal Password - Access Attempts |
|
Rakkasa Lewellen
Registered User
Join date: 21 Jun 2006
Posts: 43
|
09-11-2006 10:12
Whatever information was obtain was used to attempt to access my paypal account on September 6th and September 9th.
This is the IP of the first attempt, the second, on September 9th is identical. 84.47.180.168 Sep. 6, 2006 14:52:33 PDT Russia |
Michi Lumin
Sharp and Pointy
![]() Join date: 14 Oct 2003
Posts: 1,793
|
09-11-2006 10:16
Whatever information was obtain was used to attempt to access my paypal account on September 6th and September 9th. This is the IP of the first attempt, the second, on September 9th is identical. 84.47.180.168 Sep. 6, 2006 14:52:33 PDT Russia Hm. Where on paypal is that logged? _____________________
![]() |
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-11-2006 10:24
Hm. Where on paypal is that logged? Good question! I can't find IP logs anywhere in my PayPal interface. _____________________
A man without religion is like a fish without a bicycle.
|
Vares Solvang
It's all Relative
Join date: 26 Jan 2005
Posts: 2,235
|
09-11-2006 10:26
Why would I need to change my password? It's just as safe as any other password I might choose.
_____________________
|
Csven Concord
*
![]() Join date: 19 Mar 2005
Posts: 1,015
|
09-11-2006 10:30
I'd like to see a screenshot of what PayPal shows when it tells users of attempted intrusion. This isn't the first mention of an attempt to access a PayPal account.
Of course, I/we expect that sensitive personal info will be hidden. Thanks. |
Mugzy Shilton
Registered User
Join date: 28 Aug 2006
Posts: 3
|
09-11-2006 10:35
It could also be an email he got from a scammer out doing a bit of phishing.
If you ever get an email that say anything about bank/credit card accounts and has a link, do not click on the link. Go directly to the organizations site and if you don't see anything there about the email that was sent, give them a call. |
Rakkasa Lewellen
Registered User
Join date: 21 Jun 2006
Posts: 43
|
09-11-2006 10:38
I received an emal from them informing me of the possible intrusion attempts.
The forced me to go through a security verification and, during that process, showed me the suspect access actions. I copied one of them as a demonstration for other SL people that might not have checked their paypal email. Unfortunately, I can't access the information outside their security validation procedure. Anyway, if you haven't checked your paypal email since the 6th, I strongly recommend that you do. In terms of the password - it was the recommended action, so I'm passing that on, whether it makes sense in your particular situation is up to you. Apparently, there was sufficient unencrypted information and they have sufficient computer resourses to act upon the information they obtained from the database in a short amount of time. Mugzy, I've gotten paypal phished before - I always go directly to the site - great advice though. |
Solstice Asturias
Registered User
![]() Join date: 16 Oct 2005
Posts: 7
|
09-11-2006 10:39
Russia??
Search results for: 84.47.180.168 OrgName: RIPE Network Coordination Centre OrgID: RIPE Address: P.O. Box 10096 City: Amsterdam StateProv: PostalCode: 1001EB Country: NL ReferralServer: whois://whois.ripe.net:43 NetRange: 84.0.0.0 - 84.255.255.255 CIDR: 84.0.0.0/8 NetName: 84-RIPE NetHandle: NET-84-0-0-0-1 Parent: NetType: Allocated to RIPE NCC NameServer: NS-PRI.RIPE.NET NameServer: SEC1.APNIC.NET NameServer: SEC3.APNIC.NET NameServer: SUNIC.SUNET.SE NameServer: TINNIE.ARIN.NET NameServer: NS3.NIC.FR |
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-11-2006 10:40
I received an emal from them informing me of the possible intrusion attempts. The forced me to go through a security verification and, during that process, showed me the suspect access actions. hooooo boy... You did not happen to click on a LINK in that email, did you? I do hope you opened your browser and typed in Paypal's URL directly. _____________________
A man without religion is like a fish without a bicycle.
|
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-11-2006 10:41
Russia?? Search results for: 84.47.180.168 OrgName: RIPE Network Coordination Centre OrgID: RIPE Address: P.O. Box 10096 City: Amsterdam StateProv: PostalCode: 1001EB Country: NL ReferralServer: whois://whois.ripe.net:43 NetRange: 84.0.0.0 - 84.255.255.255 CIDR: 84.0.0.0/8 NetName: 84-RIPE NetHandle: NET-84-0-0-0-1 Parent: NetType: Allocated to RIPE NCC NameServer: NS-PRI.RIPE.NET NameServer: SEC1.APNIC.NET NameServer: SEC3.APNIC.NET NameServer: SUNIC.SUNET.SE NameServer: TINNIE.ARIN.NET NameServer: NS3.NIC.FR % This is the RIPE Whois query server #2. % The objects are in RPSL format. % % Note: the default output of the RIPE Whois server % is changed. Your tools may need to be adjusted. See % http://www.ripe.net/db/news/abuse-proposal-20050331.html % for more details. % % Rights restricted by copyright. % See http://www.ripe.net/db/copyright.html % Note: This output has been filtered. % To receive output for a database update, use the "-B" flag % Information related to '84.47.180.0 - 84.47.180.255' inetnum: 84.47.180.0 - 84.47.180.255 netname: VPN-3 descr: Formatek, Moscow,Sokol country: RU admin-c: VA902-RIPE tech-c: VA902-RIPE status: ASSIGNED PA "status:" definitions mnt-by: NAUKANET-MNT source: RIPE # Filtered person: Vladimir Aksenov address: OOO "Formatek" address: 2-nd Peschanaya str, 2/1 e-mail: [email]admin@formatek.ru[/email] phone: +7 495 1577677 fax-no: +7 495 1577677 nic-hdl: VA902-RIPE source: RIPE # Filtered _____________________
A man without religion is like a fish without a bicycle.
|
Mugzy Shilton
Registered User
Join date: 28 Aug 2006
Posts: 3
|
09-11-2006 10:41
I received an emal from them informing me of the possible intrusion attempts. The forced me to go through a security verification and, during that process, showed me the suspect access actions.. If you go this via email, you better go change your password again. Its common practice for scammers to send out emails directing someone to a site that looks like the paypal site, but really just logs your user information so they can gain access to your account. |
Rakkasa Lewellen
Registered User
Join date: 21 Jun 2006
Posts: 43
|
09-11-2006 10:41
hooooo boy... You did not happen to click on a LINK in that email, did you? I do hope you opened your browser and typed in Paypal's URL directly. No, I'm too old and abused by life to fall for that one ![]() |
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-11-2006 10:44
No, I'm too old and abused by life to fall for that one ![]() I deleted my post too late - I saw your last sentence. ![]() _____________________
A man without religion is like a fish without a bicycle.
|
Fred Extraordinaire
Weapons Specialist
Join date: 29 Jun 2004
Posts: 134
|
09-11-2006 10:46
I am seeing charges on my cc, it would be nice to know when exactly the database was considered 'compromised'
_____________________
-----
<3 LL ![]() |
Mugzy Shilton
Registered User
Join date: 28 Aug 2006
Posts: 3
|
09-11-2006 10:47
Anyway, SL does not have anyone's paypal password.
Remember, when you setup paypal as your payment method, it sends you to paypal.com to authorize SL to bill you. |
Rakkasa Lewellen
Registered User
Join date: 21 Jun 2006
Posts: 43
|
09-11-2006 10:48
sounds like you got totaly phished which makes sense in a way as i'm sure post-september 6th attempts have doubled. reading comprehension FTW ![]() |
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-11-2006 10:50
Anyway, SL does not have anyone's paypal password. However, if you used the SAME password on SL as you do Paypal, it just might be a good idea to change it. _____________________
A man without religion is like a fish without a bicycle.
|
Cristiano Midnight
Evil Snapshot Baron
![]() Join date: 17 May 2003
Posts: 8,616
|
09-11-2006 10:50
sounds like you got totaly phished which makes sense in a way as i'm sure post-september 6th attempts have doubled. They were not phished. These alerts are appearing when you sign into your Paypal account - it has happened to SL members this weekend, this is not the first report of it. The warning is legit - it is coming from Paypal within their own site. _____________________
Cristiano
ANOmations - huge selection of high quality, low priced animations all $100L or less. ~SLUniverse.com~ SL's oldest and largest community site, featuring Snapzilla image sharing, forums, and much more. ![]() |
Rakkasa Lewellen
Registered User
Join date: 21 Jun 2006
Posts: 43
|
09-11-2006 10:53
Here's what the email looks like - I go directly to the site as a matter of habit, legit though
We recently noticed one or more attempts to log in to your PayPal account from a foreign IP address. If you recently accessed your account while traveling, the unusual log in attempts may have been initiated by you. However, if you did not initiate the log ins, please visit PayPal as soon as possible to change your password: Changing your password is a security measure that will ensure that you are the only person with access to the account. Thanks for your patience as we work together to protect your account. Sincerely, PayPal |
Mugzy Shilton
Registered User
Join date: 28 Aug 2006
Posts: 3
|
09-11-2006 11:00
Yep. this is phishing.
http://tinyurl.com/4pn9h The link goes to a post telling all about this scam, the post is on antiphishing.org. |
Cristiano Midnight
Evil Snapshot Baron
![]() Join date: 17 May 2003
Posts: 8,616
|
09-11-2006 11:03
Yep. this is phishing. http://www.antiphishing.org/phishing_archive/11-09-04_Paypal(Your_Account_Will_Be_Suspended)/11-09-04_Paypal(Your_Account_Will_Be_Suspended).html No, it is not phishing. Two of the people affected by this got the messages after DIRECTLY signing into Paypal. April Chung and Torrid Midnight both had the exact same warnings in the Paypal account. Not from an email. April Chung received the warning when confirming a payment by signing into Paypal, and Torrid received it when checking her account after signing in directly at Paypal.com . The phishing email in question is effective because it does make use of an actual warning message that Paypal uses, which is how phishing attempts are successful. There is definitely a problem going on related to the SL security breach and Paypal accounts. The only way to tell is to actually go to Paypal.com and sign in directly - the warning message will appear upon signin. _____________________
Cristiano
ANOmations - huge selection of high quality, low priced animations all $100L or less. ~SLUniverse.com~ SL's oldest and largest community site, featuring Snapzilla image sharing, forums, and much more. ![]() |
Chronic Skronski
SL Live Musician
Join date: 23 Jun 2006
Posts: 997
|
09-11-2006 11:05
Good find, Mugzy. Rakka... please humour us and change your PayPal password again.
![]() Edit: Cris, good point. However, people will still be getting those emails sometimes and clicking the link within. Now is as good a time as any to educate people: IF this notice comes as an email, delete it! Only log into Paypal by using a bookmark you made, or by typing the URL. _____________________
A man without religion is like a fish without a bicycle.
|
Fred Extraordinaire
Weapons Specialist
Join date: 29 Jun 2004
Posts: 134
|
09-11-2006 11:09
i dont have issues with my paypal, nor a warning to change anything, but i do have charges dating from 8/28 from someone using the in-grme system to buy lindibux...anyone have or heard similar reports?
_____________________
-----
<3 LL ![]() |
Solstice Asturias
Registered User
![]() Join date: 16 Oct 2005
Posts: 7
|
09-11-2006 11:14
Wow thanks for that Phishing link! This is one of the best Phishing schemes I have seen!
My question is though....how did they already know part of my account info, like it named my bank in the drop down menu when asking for my complete info??? |
Cristiano Midnight
Evil Snapshot Baron
![]() Join date: 17 May 2003
Posts: 8,616
|
09-11-2006 11:16
Good find, Mugzy. Rakka... please humour us and change your PayPal password again. ![]() Edit: Cris, good point. However, people will still be getting those emails sometimes and clicking the link within. Now is as good a time as any to educate people: IF this notice comes as an email, delete it! Only log into Paypal by using a bookmark you made, or by typing the URL. Yeah, I get about 5 Paypal phishing things a day. If this had only been an email thing, I wouldn't have thought twice about it. However, reports keep coming in of people having their Paypal accounts accessed from Russia this weekend, and it is quite concerning. At a minimum, it can't hurt to change your password anyway just to be on the safe side - it is a good practice to regularly change your password anyway. _____________________
Cristiano
ANOmations - huge selection of high quality, low priced animations all $100L or less. ~SLUniverse.com~ SL's oldest and largest community site, featuring Snapzilla image sharing, forums, and much more. ![]() |