11.20.07

19:48:12

EBAY.COM ZOMBIED AND HACKED BY WWW.WEB-HACK.COM

Looks like ownage to me.


Well now, this sure is interesting. I was looking into something when I came across this curious entry at Wikipedia for Usertalk:216.113.168.128

(Update 09.02.2009 -- Adding screencapture of the vandalism warnings from that day after curious events)


I was having a lot of fun reading some of the steady stream of various warnings which have apparently been issued to that IP, (which is an outbound ebay IP ) for things like Vandalism, when for whatever wild reason I decided to do a reverse DNS search for 216.113.168.128 and found this:

"EBAY.COM.ZOMBIED.AND.HACKED.BY.WWW.WEB-HACK.COM"

Doesn't that seem like a funny server name?

(Not to mention the "EBAY.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM" one.)

I wonder why that is?
A regular WHOIS for ebay looks normal, but I sure don't trust anything with those server names or anything like them associated with it.  Do you?

I see this has been reported elsewhere.  I did a couple more quick searches, like google and google blog, along with Yahoo!

I found hits on each search, going back as far as 2005. I do not find any satisfactory explanation from anyone who seems to be an unbiased authority. Apparently, anyone can "point" any domain to any server from what I gather, but that only leaves me with more questions.

  I really don't know what all this means, but I sure begin to wonder if this is, or has anything to do with ebay's network of "externally visible" servers,(or any part of it/them) which we all heard about not long ago when Vladuz hacked ebay and played customer service rep for a day on October 5th, 2007.


Uh... just going by those names alone, being listed on their  reverse DNS lookup, before you even review any of their other safety/hacking record/history, or some of the other stunts they have tried, or looking into any long-standing, uncorrected critical safety flaws found on the site, is this an outfit you can really trust?


I really have not looked, but are there any other huge multi-billion dollar auction or ecommerce outfits on the internet that come back with that sort of result, do you suppose?
Oh everyone should look into webhack.com BTW

Below is the some of the text, you can see a full page screencapture, reduced to 640 width here

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

Server Name: EBAY.COM.ZZZZZ.GET.LAID.AT.WWW.SWINGINGCOMMUNITY.COM
IP Address: 69.41.185.206
Registrar: INNERWISE, INC. D/B/A ITSYOURDOMAIN.COM
Whois Server: whois.itsyourdomain.com
Referral URL: http://www.itsyourdomain.com

Server Name: EBAY.COM.ZOMBIED.AND.HACKED.BY.WWW.WEB-HACK.COM
IP Address: 217.107.217.167
Registrar: ONLINENIC, INC.
Whois Server: whois.35.com
Referral URL: http://www.OnlineNIC.com

Server Name: EBAY.COM.Z-A.MAKE.MONEY.AT.WWW.ONLINESUPPLIER.COM
IP Address: 66.135.192.87
Registrar: MONIKER ONLINE SERVICES, INC.
Whois Server: whois.moniker.com
Referral URL: http://www.moniker.com/whois.html

Server Name: EBAY.COM.MORE.INFO.AT.WWW.BEYONDWHOIS.COM
IP Address: 203.36.226.2
Registrar: TUCOWS INC.
Whois Server: whois.tucows.com
Referral URL: http://domainhelp.opensrs.net

Server Name: EBAY.COM.IS.NOT.AS.1337.AS.GULLI.COM
IP Address: 80.190.192.34
Registrar: KEY-SYSTEMS GMBH
Whois Server: whois.rrpproxy.net
Referral URL: http://www.key-systems.net

Server Name: EBAY.COM.AU
Registrar: PLANETDOMAIN PTY LTD.
Whois Server: whois.planetdomain.com
Referral URL: http://www.planetdomain.com

Domain Name: EBAY.COM
Registrar: NETWORK SOLUTIONS, LLC.
Whois Server: whois.networksolutions.com
Referral URL: http://www.networksolutions.com
Name Server: SJC-DNS1.EBAYDNS.COM
Name Server: SJC-DNS2.EBAYDNS.COM
Name Server: SMF-DNS1.EBAYDNS.COM
Name Server: SMF-DNS2.EBAYDNS.COM
Status: clientTransferProhibited
Updated Date: 26-jun-2006
Creation Date: 04-aug-1995
Expiration Date: 03-aug-2010

>>> Last update of whois database: Wed, 21 Nov 2007 03:24:16 UTC <<<



http://budmalcolm.bravejournal.com/entry/24767

2 comment(s).

Posted by scamthis:

The IP 216.113.168.128 is an eBay Bot that archives any sites content that it finds. I have it blocked on my servers.

Here is a little page i created just for eBay.

http://www.ebaymotorssucks.com/403.htm
12.10.07 @ 11:23:43

Posted by Giovanni:

Hi Doc Thanks for commenting.
I do not understand why the entire ebay site is not on secure servers, or why those results wouyd show like that, but it is saying something.
Yeah, I have seen that 403 page before. LMAO! Classic!
It sure is funny when someone rejoins a discussion, in a bad mood, telling everyone that the link to your site is broken.
& I sure have seen it happen a few times now.

Too funny!
12.12.07 @ 06:54:55

Post New Comment

 BraveJournal Member Non-Member
No Smilies More Smilies »
Please type the letters you see