Closing Doman Auctions
DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeRegisterMembershipsGetting StartedDomain Tools Domain EbooksSEO Software Domain Resellers Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Industry Leaders > Industry Watchdogs
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 12-26-2008, 05:31 PM   #1 (permalink)
Platinum Lifetime Member
 
myst woman's Avatar
 
Last Online: Yesterday 01:09 PM
iTrader: (22)
Join Date: Sep 2005
Posts: 982
DNF$: 1,145
Location: Los Angeles
Country:


Paypal security hole-BEWARE

While I was offline due to a storm Christmas Day Paypal paid an unauthorized charge to a company called BBG Londoon, a Google result fraud and scam site. I have never heard of them. I just happned to log in after walking to a starbucks through the snow for Internet.

get this: I have to fill out a form that takes ten days to investigate. What if Paypal lets this entity drain my account before their little elves return form Christmas vacation and get around to my security warning? Why isn't Paypal working harder to guard my money and look out for their customers?

FYI: no email notification of this BBG Londoon transaction came to my main email address for this paypal account, but email notifications for transactions I did authorize on either side of it were emailed. Check your Paypal accounts!
__________________
lotrblog.com

Last edited by myst woman; 12-26-2008 at 05:37 PM.. Reason: ed
myst woman is offline   Reply With Quote
Sponsored Ads
Old 12-26-2008, 07:33 PM   #2 (permalink)
CrossLogix.com
 
copper's Avatar
 
Last Online: Yesterday 05:46 PM
iTrader: (65)
Join Date: Mar 2006
Posts: 2,245
DNF$: 2,179
Location: Matthews, NC. U


Sorry to hear that.
I better get that paypal security key thing.
__________________

Domain Names For Sale
copper is offline   Reply With Quote
Old 12-26-2008, 07:35 PM   #3 (permalink)
jdk
DNF Addict
 
jdk's Avatar
 
Name: Doug
Last Online: 11-19-2009 06:09 PM
iTrader: (175)
Join Date: Jul 2004
Posts: 6,886
DNF$: 68,548
Location: Florida
Country:


Quote:
Originally Posted by copper View Post
Sorry to hear that.
I better get that paypal security key thing.
More info on this please.
jdk is offline   Reply With Quote
Old 12-26-2008, 08:13 PM   #4 (permalink)
Platinum Lifetime Member
 
myst woman's Avatar
 
Last Online: Yesterday 01:09 PM
iTrader: (22)
Join Date: Sep 2005
Posts: 982
DNF$: 1,145
Location: Los Angeles
Country:


i have not received any response From Paypal yet. They say 2-3 days they will get back to my email. How can Paypal allow such a gaping hole? Obviously the perfect time to seed a fraud scam is Christmas day when people are doing other things than checking their Paypal. If nobody is working at Paypal the day after Christmas at 5:10 PST then the charges go through? The "Security Center" just refers you to a robot chat question answererer and a form to print fax and then wait 10 days? How on earth can this be a time sensitive way to respond to electronic banking fraud?

If they can get away with one time, then they can just go ahead and I am guessing the Paypal matrix will approve an even greater charge based on previous payment history relationship. No resposne from the spoof forward either, i was hoping someone there would wake up.

I have looked in my bulk mail and everything, I am shocked that the charge was made without any email notification. How did they get a charge through Paypal without email notification to the customer account holder? From overseas? On a holiday?
__________________
lotrblog.com
myst woman is offline   Reply With Quote
Old 12-26-2008, 10:18 PM   #5 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: 01-20-2009 11:29 PM
iTrader: (4)
Join Date: Dec 2008
Posts: 7
DNF$: 10


Did you call Paypal? They are a bit slow, but I have always had the best luck skipping the whole email support problem and calling.
wjtyoung is offline   Reply With Quote
Old 12-26-2008, 10:46 PM   #6 (permalink)
41 LLL.nets For $35k!
 
tekz999's Avatar
 
Last Online: Yesterday 09:11 PM
iTrader: (318)
Join Date: Jun 2003
Posts: 5,198
DNF$: 18,526
Location: Hong Kong
Country:


This is very frustrating. Never keep more than $500 in your paypal balance. Please keep us updated.
tekz999 is offline   Reply With Quote
Old 12-26-2008, 11:27 PM   #7 (permalink)
Those Damn Hippies
 
justinXcore!'s Avatar
 
Last Online: 11-04-2009 07:27 PM
iTrader: (39)
Join Date: Apr 2006
Posts: 869
DNF$: 4,122
Location: Atlanta
Country:


Were the funds taken from paypal balance or your bank account?
__________________
<a href=http://dreadies.com target=_blank>http://dreadies.com</a>
justinXcore! is offline   Reply With Quote
Old 12-27-2008, 01:28 AM   #8 (permalink)
Platinum Lifetime Member
 
myst woman's Avatar
 
Last Online: Yesterday 01:09 PM
iTrader: (22)
Join Date: Sep 2005
Posts: 982
DNF$: 1,145
Location: Los Angeles
Country:


ppal balance.
__________________
lotrblog.com
myst woman is offline   Reply With Quote
Old 12-27-2008, 01:59 AM   #9 (permalink)
Platinum Lifetime Member
 
exxe's Avatar
 
Name: Andrei
Last Online: Today 03:45 AM
iTrader: (13)
Join Date: Nov 2007
Posts: 658
DNF$: 211
Location: Europe
Country:


Quote:
Originally Posted by myst woman View Post
I have looked in my bulk mail and everything, I am shocked that the charge was made without any email notification. How did they get a charge through Paypal without email notification to the customer account holder? From overseas? On a holiday?
I doubt it's PayPal's fault, maybe your computer/email is compromised. I suggest you to scan your computer and change the passwords afterwards.
exxe is offline   Reply With Quote
Old 12-27-2008, 03:17 PM   #10 (permalink)
Platinum Lifetime Member
 
myst woman's Avatar
 
Last Online: Yesterday 01:09 PM
iTrader: (22)
Join Date: Sep 2005
Posts: 982
DNF$: 1,145
Location: Los Angeles
Country:


How could that be the case if the transaction went through and no notification was sent? How could my computer be compromised if I was offline for 6 days?
__________________
lotrblog.com
myst woman is offline   Reply With Quote
Old 12-27-2008, 03:57 PM   #11 (permalink)
Platinum Lifetime Member
 
exxe's Avatar
 
Name: Andrei
Last Online: Today 03:45 AM
iTrader: (13)
Join Date: Nov 2007
Posts: 658
DNF$: 211
Location: Europe
Country:


Quote:
Originally Posted by myst woman View Post
How could that be the case if the transaction went through and no notification was sent? How could my computer be compromised if I was offline for 6 days?
It does not matter if you were offline for 6 days. Maybe the notification was sent, but the thief has access to your email account and deleted the notification. Just a scenario...
exxe is offline   Reply With Quote
Old 12-27-2008, 05:24 PM   #12 (permalink)
 
meganerd's Avatar
 
Name: Tia Wood
Last Online: Today 03:17 AM
iTrader: (75)
Join Date: Jan 2006
Posts: 2,608
DNF$: 210
Location: Missouri
Country:



Quote:
Originally Posted by jdk View Post
More info on this please.

I've had the Paypal Security Key for about a year. I love it! It uses RSA technology to generate an offline password every time you login. I keep it on my key chain and haven't lost my keys since.

https://www.paypal.com/cgi-bin/websc...ityKey-outside
__________________
MY BLOG | Parking & PPC Alternative
Graphic Designer & Web Developer, yes. But overall, I am an artist. Give me a mouse and I'll show you art.
meganerd is offline   Reply With Quote
Old 12-27-2008, 05:55 PM   #13 (permalink)
 
JuniperPark's Avatar
 
Last Online: 11-20-2009 08:56 PM
iTrader: (86)
Join Date: Aug 2003
Posts: 2,478
DNF$: 3,134
Location: San Diego, CA
Country:


You 'walked through snow' in Los Angeles???
__________________
The only domain reseller BRAVE enough to post prices: TheNameStore.com ][
JuniperPark is offline   Reply With Quote
Old 12-27-2008, 06:04 PM   #14 (permalink)
Domain Buyer
 
DaddyHalbucks's Avatar
 
Name: Hal
Last Online: 11-18-2009 11:20 AM
iTrader: (57)
Join Date: Oct 2002
Posts: 2,730
DNF$: 120,139
Location: Las Vegas, USA
Country:


Beware of using shared computers at coffee shops/ kiosks/ copy centers.
__________________

www.ParkingCash.com
<==Click here

www.RingtoneCash.com
<==and here
DaddyHalbucks is offline   Reply With Quote
Old 12-27-2008, 06:35 PM   #15 (permalink)
CrossLogix.com
 
copper's Avatar
 
Last Online: Yesterday 05:46 PM
iTrader: (65)
Join Date: Mar 2006
Posts: 2,245
DNF$: 2,179
Location: Matthews, NC. U


Quote:
Originally Posted by exxe View Post
It does not matter if you were offline for 6 days. Maybe the notification was sent, but the thief has access to your email account and deleted the notification. Just a scenario...
This is possible.
Similar thing happened before with domain transfer.

Thief go into gmail acct thru back door.
Started domain transfer process.
Any email received will be forwarded to thief's email elsewhere
and original email received get deleted. Thus, it may appear
you never received any email.

Paypal thief is exactly same as domain thief as mentioned above.
__________________

Domain Names For Sale
copper is offline   Reply With Quote
Old 12-28-2008, 12:21 PM   #16 (permalink)
Platinum Lifetime Member
 
myst woman's Avatar
 
Last Online: Yesterday 01:09 PM
iTrader: (22)
Join Date: Sep 2005
Posts: 982
DNF$: 1,145
Location: Los Angeles
Country:


Quote:
Originally Posted by JuniperPark View Post
You 'walked through snow' in Los Angeles???
I am currently somewhere where there is snow.

Go fish.
__________________
lotrblog.com
myst woman is offline   Reply With Quote
Old 12-28-2008, 02:22 PM   #17 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: Today 03:55 AM
iTrader: (35)
Join Date: Dec 2005
Posts: 960
DNF$: 4,810


1. Scan, scan again, then scan in safe mode
2. Change ALL passwords .. immediately AFTER you scan (I'm assuming you know how to scan - There are also a few good online scanners .. Use them!
http://housecall.trendmicro.com/
http://www.kaspersky.com/virusscanner
http://www.pandasecurity.com/homeuse...ns/activescan/

Run each one separately .. not at the same time ..

Keylogger / Spyware --> http://www.pctools.com/spyware-doctor/google_pack/)
Initiate the Google Pack .. uncheck all the other stuff you don't want and 'Download Now'
mulligan is offline   Reply With Quote
Old 12-31-2008, 06:08 AM   #18 (permalink)
Platinum Lifetime Member
 
domaingenius's Avatar
 
Last Online: 11-07-2009 12:10 PM
iTrader: (5)
Join Date: Mar 2006
Posts: 1,027
DNF$: 148
Location: United Kingdom
Country:


You might want to read this website. If you read carefully you will see some
useful email addresses that worked for me to get people moving.
http://www.screw-paypal.com/paypal_c...formation.html
(not my site by way)

By the way, I see Paypal CHARGE for that security key !! >So clients
of theirs have to pay them to make their site secure. **** them.

DG
domaingenius is offline   Reply With Quote
Old 01-06-2009, 08:40 AM   #19 (permalink)
Gold Lifetime Member
 
Clayton's Avatar
 
Name: Clayton
Last Online: 08-31-2009 10:26 PM
iTrader: (1)
Join Date: Dec 2008
Posts: 28
DNF$: 10
Location: Orlando, FL
Country:

Send a message via AIM to Clayton Send a message via MSN to Clayton

Any update on the outcome of this?
Clayton is offline   Reply With Quote
Old 01-09-2009, 06:22 PM   #20 (permalink)
Platinum Lifetime Member
 
myst woman's Avatar
 
Last Online: Yesterday 01:09 PM
iTrader: (22)
Join Date: Sep 2005
Posts: 982
DNF$: 1,145
Location: Los Angeles
Country:


mamas don't let your babies grow up to use Paypal.

Paypal found the disputed action was not fraudulent then sent me the most bogus email I ever saw:

"Dear XXXXXX,

Despite being advised to close your debit card ending in 29, (nobody ordered this) the card
remained open as of today. Your card is now closed, to alleviate
further losses.

You are required to submit a signed affidavit to us listing the
charge(s) in dispute and why. To date, we have received no affidavit
from you.

You may file a dispute on a completed transaction made with your PayPal
Debit Card or PayPal Plug-In Secure Card. Before filing a dispute on a
PayPal Debit Card transaction:

* The disputed transaction must be completed.
* Transactions that are pending, denied, or expired cannot be
disputed. If you are reporting a transaction as unauthorized and select
the reason for the dispute as "I did not make this purchase," your
PayPal Debit Card must be reported lost/stolen.* This is a requirement
to help prevent any further unauthorized transactions.
* For all other disputes, MasterCard requires that you try to
contact the merchant and attempt to resolve the dispute with them prior
to filing a dispute. If you have done so, please document your attempts
on the dispute form.
"

This is most stupid banking action I have ever seen. They found the charge was not in dispute then closed the card to alleviate "any future losses". WHAT LOSSES IF THEY FOUND THE CHARGE WAS NOT IN ERROR?

I am now two states away without a credit card because nobody asked Paypal to close or cancel the card and they claim somebody did and they did it before I could anything or say anything. The only email i got was a response saying Paypal found the charge valid. Then a cancellation. For a $.95 transaction.

so, in response to my concern about a fraudulent charge and my inquiries they canceled my credit card.

Fantastic banking help. Stranding traveling customers after shutting their resolution valve!

Yay paypal!

more happy customers await!
__________________
lotrblog.com

Last edited by myst woman; 01-09-2009 at 06:36 PM.. Reason: sp
myst woman is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 05:08 AM.
Copyright @2001-2009 DNForum.com