LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-05-2017, 12:39 PM   #1
mike3644
Member
 
Registered: Apr 2016
Posts: 35

Rep: Reputation: 0
Strange popups from unidentified source, warning of fraudulent URLs


After reading other postings enumerating similar but not identical difficulties with erroneous popups, I decided to go ahead with my version of this anomaly for the benefit of others who may read it.

My main computer is a 2014 System76 laptop running Intel® Core™ i7-4910MQ CPU @ 2.90GHz × 8 & Ubuntu 16.04 LTS with ClamTK and Firefox

This morning, checking email (Sylpheed free Version 3.5.0 (Build 1169) I noticed a message from ebay advising that their Security wing suspected my account had been tampered (He sez, "I told you I wuz gonna tamper with you, baby, not take you to Florida") and that my password had been rescinded, pending renewal. I'm pasting the message below:

From: no.reply@ebay.com
To: mike1792@yandex.com
Subject: Unauthorized use of your account -- action required
Date: Fri, 4 Aug 2017 21:14:36 -0700 (GMT-07:00)


Unauthorized use of your account -- action required


Hello Mike,

We have reason to believe that your eBay account has been used fraudulently without your permission. We've reset your eBay password. If you had your PayPal account linked to your eBay account, we've disabled your PayPal link to protect your funds. Any unauthorized activity, such as buying or selling, has been canceled and any associated fees have been credited to your account. Any listings that we removed are included toward the end of this email. We assure you that your financial information is securely stored on a server and cannot be seen by anyone.

Although we've taken steps to secure your eBay account, your personal email account or third-party listing tools may have also been accessed without your permission. Please change these passwords as soon as possible.

Once you've secured your personal email account and third-party listing tools, please change your eBay password, and reset your PayPal link (if applicable):

1. Select the "Sign in" link at the top of the eBay home page.
2. Select the "Forgot your password" link.
3. Enter your email or username, and then select the "Next" button.
4. Follow the instructions to change your password.
5. To relink your PayPal account (if desired), go to "My eBay" and click the "Account" tab.
6. Click the "PayPal Account" link on the left-hand side of the page.
7. Click the "Link My PayPal Account" button.
8. Log into PayPal to finish linking your accounts.

If you are an active seller and use PayPal to pay your fees, it's important that you reset your PayPal link before your next billing cycle to avoid any further disruption.

Once your password is changed, we recommend updating your secret questions and verifying that the contact information on your eBay account is correct. For detailed instructions, please visit:
http://pages.ebay.com/help/account/s...nt.html#secure

To learn more about keeping your eBay account secure, please visit:
http://pages.ebay.com/help/account/p...g-account.html

If you have any problems changing your password, please contact us:
http://ocsnext.ebay.com/ocs/eua?doma...ForgotPassword
------------------------------------------------------------------------------

I'm almost positive that this response from ebay was generated by the fact that as of two days ago I joined IPVanish VPN and now have a concealed presence on the Net.
. . . Ebay intimated me as being the bad guy, which if true is laughable.
At any rate I went ahead with the semantic of changing my long-held ebay email handle, just as enumerated above and when the message from ebay with the verification URL arrived in my Inbox and I clicked it, a strange popup appeared (as attached to this post) advising of a fraudulent URL.
This same type of thing happened just a few days back and so far I have never been able to discover definitively what on-board software may be responsible.
But assuming Firefox is the instigator it will now be my aim to disable Firefox' authorization for such actions, which thing I believe can be accomplished by UN-checking a few boxes in the Preferences section.
As lindav, a poster with similar complaints put it (to paraphrase). . . why should we be made to pay a toll for honesty?
Attached Thumbnails
Click image for larger version

Name:	Screenshot from 2017-08-05 12-16-59.png
Views:	22
Size:	54.5 KB
ID:	25659  
 
Old 08-05-2017, 01:20 PM   #2
Trihexagonal
Member
 
Registered: Jul 2017
Posts: 362
Blog Entries: 1

Rep: Reputation: 334Reputation: 334Reputation: 334Reputation: 334
You might want to remove your email addy from your post so spammers don't harvest it.

Last edited by Trihexagonal; 08-05-2017 at 01:23 PM.
 
1 members found this post helpful.
Old 08-08-2017, 04:02 PM   #3
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
Are you using the latest firefox? Oh, BTW, I've seen that email. It's legit.
 
Old 08-08-2017, 04:52 PM   #4
justmy2cents
Member
 
Registered: May 2017
Location: U.S.
Distribution: Un*x
Posts: 237
Blog Entries: 2

Rep: Reputation: Disabled
If I understand the question correctly you're trying to figure out the origins of that pop up as it relates to your on-board software? If that's the case you open up top, then kinda keep hovering your cursor over the pop up which should cause the pop up's process to be listed at the top of top... Then you can get further details in /proc.. And if it also helps you can see what log files are in use and over which network connections via lsof -i +D /var/log

Last edited by justmy2cents; 08-08-2017 at 04:58 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
In ScientificLinux- 6.4, I get too many popups warning of "DNS Spoofing"..? lindav Linux - Security 22 12-15-2013 02:23 PM
Fraudulent Google credential found in the wild H_TeXMeX_H Linux - News 1 09-05-2011 01:54 PM
firefox - strange popups ungua Linux - Software 4 11-08-2006 08:10 AM
how to check urls and stop internet urls in network gface Linux - Networking 5 03-24-2005 09:48 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration