The fraud associated with purchasing ecig related stuff is getting ridiculous

Status
Not open for further replies.

mistinthewoods

Vaping Master
ECF Veteran
Feb 4, 2010
4,956
1,822
67
Brooklyn, MI
It seems a tad ridiculous that a vendor would take your card info and use it to make the kinds of purchases that people tend to report after a "vendor" steals their info.

WoW accounts and Xbox Live purchases sound more like script kiddies and/or Chinese gold farmer organizations.

The first time on mine $900.00 the was for shoes bought in Paris, France and over $500.00 was charged to some phony charity organization with the wod "Aide" in the title. The second time all the charges were to "New York Times / something or other.
 

crashtestjeep

Vaping Master
ECF Veteran
Aug 14, 2009
3,935
100
Wilmington, NC
www.myspace.com
Whether its ecig related or not, I talk to at least one person a day that has been scammed in one way or another. Its the new times it seems. Unfortunately, with the worlds economy in the shape it is, (and where its going for that matter) we all need to just be very careful not only w our banking n cc info, but in other avenues as well.

Online scams are just a single venue of non-violent robbery going on by people that used to have decent jobs and have been foreclosed on, laid-off and outsourced and are basically angry at society but arent willing to go out and rob anyone face to face, IMO.

We all know that tough times make desperate people do desperate things, and with holidays around the corner, make sure you take all ohysical porecautions as well while out and about. Noone wants thier children waking up Xmas morning without any presents, so we can imagine what the upcoming season may have in store.

I see this getting wayyyyy worse before getting better, if it DOES ever get better.

Eeehhh, thank god for nicotine! :)
 

Pendarus

Full Member
ECF Veteran
Verified Member
Sep 25, 2009
51
3
On the fringe of the Outer Rim
This is why I only use a PayPal one time use credit card.

It's only good at the site you generate it for. I've tried using it twice at the same site, and it never authorizes.

These are also good for "free" trials that require a CC#. Generate a card, start the trial and then cancel the card. No way they can charge you after the trial ends. This way I don't have to remember when to cancel, and don't have to go through the twenty step cancellation procedure.
 

VPDownunder

Ultra Member
ECF Veteran
Verified Member
Jul 1, 2010
1,591
325
56
Tasmania, Australia
I wish Paypal would make this feature available to all it's members, I wasn't lucky enough to be invited into the beta test so the feature isn't available to me and I refuse to pay $10 every time I need to add cash to a prepaid CC (that's what they charge here on pre paid cards for topups plus the initial registration fee.
 

Smix

Senior Member
ECF Veteran
Verified Member
Feb 9, 2010
120
1
Wellington, New Zealand
What about getting a Visa debit card? That's what I do. Any purchases I make, I just transfer money to it. I never leave money in it so if someone was to steal my details, it'd be declined due to insufficient funds.

I also use a Mac so spyware and viruses aren't really an issue (I still use an antivirus/spyware though).
 

Dkrom68

Unregistered Supplier
ECF Veteran
Nov 17, 2009
5,288
3,094
57
Backwoods NY USA
I would like to see a poll of what the charges of fraud on everyone was. I was hit for Xbox live and some plumbing company. My security on my internet and computer is not the issue in any way at all so I believe its coming from a vendors vunerability. Please post your farud charges and maybe it can narrow something down. I believe its young kids cause I have seen alot of Xbox live claims of fraud lately.
 

crashtestjeep

Vaping Master
ECF Veteran
Aug 14, 2009
3,935
100
Wilmington, NC
www.myspace.com
I WILL mention one EXVendor, which was banned for ripping people off, just to see if this has anyone in common with me. "Dinosaur vapor". He was out of wa state and my charges were in CA and WA, I live in NC....He was young (20) and was into gaming - as he mentioned on another thread some time ago. This vendor has been banned for quite some time now, but I DO wonder if he saved any info from past "Marks" and later used the cards info for personal use. I only mentioned this name bc he ripped off about a hundred people on here alone, and even another vendor so Im not opening any doors that may accuse the innocent, just a door of possibility.

Moderators, Please delete this if Im in any rule violation here. I am CERTAINLY nOT trying to violate rules, just mentioning a possibility that may or may NOT have anything to do with anything. Nor am I accusing this EX-vendor of any such act, but with his track record, its worth seeing if there are any links.
 

Mr.Stick

Senior Member
ECF Veteran
Mar 26, 2010
154
10
44
Colorado
Oh yeah, and don't use a bank card to shop online!

I'm starting to think that's the best option. All the protections money can buy still won't spare the hasstle of waiting for money to be refunded IF something manages to go wrong.

And scrape those plates before you put them in the dishwasher!
 

K-Space

Ultra Member
ECF Veteran
Verified Member
Jul 20, 2010
2,429
1,900
Delaware
Hey all! something very weird happend to me 2 days ago after ordering from a vendor. I recieved an e-mail from the vendor confirming my order and a tracking number for usps.there was a link on the vendors site for you to enter the tracking number. i entered the tracking number and pressed enter. when i did this i noticed that my hardrive was making a noise like it was searching for something. actually it was my antivirus starting a scan. it found this. maybe it will help. Trojan-PSW.Win32.LdPinch.a and this is what this trojan does.This family of Trojans steals user passwords.

When launching, the Trojan writes the following value to the system registry.

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
putil = %windir%\%file name%
This ensures that the Trojan will be run every time the system is started.

It then copies itself to the Windows folder, and launches itself from there, deleting the original file.

The Trojan harvests information about the system (operating system, configuration etc.) and passwords for a range of services and applications, including RAS, POP3, IMAP, ICQ, FTP etc.

The information collected is encoded using MIME (Base64) and sent to the Trojan's author by email, using an SMTP server with an IP address which is coded in the Trojan's body.



Summary
Implements network activity
Performs potentially dangerous activity


Technical details
File size of 8624 bytes.



Installation
Makes copies of itself with the following names once launched:

Windows directory (usually, C:\Windows)%Windir%\<­file of source program ­>

Ensures Using the system registry, system services or special system files, the program can launch itself or launch the creation of its files every time the Windows OS is subsequently booted autorun of the following installed files:

by adding values to autorun keys in the system registry:

[ System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ] "putil" = " Windows directory (usually, C:\Windows)%Windir%\<­file of source program ­>"




Malicious activity
Connects to to the following Internet addresses:

***.67.23.10:6400

Checks for Dial-Up connections on the infected computer



Other activities
Runs the following files (commands):

Windows directory (usually, C:\Windows)%Windir%\<­file of source program ­>


hopefully this might help. steve
 

BigTarBall

Full Member
Jul 24, 2010
19
1
Crop County CA
You want to make sure that the vendors you purchase from has a secure cart, make sure the url starts out with https://

It's also always a good idea to make sure they have a valid SSL certificate. Many stores will have a link to their SSL somewhere on their front page.

I have only ordered e-cig stuff from 2 company's so far. The day I ordered from the second company I got a spam mail in my junk box, I thought it was weird. About 3 weeks later my credit card got canceled because someone tried to charge something in France to it.

The place that I have been doing most of my business with does have the SSL there on the front page. The other company (the one I think with the breach) I cannot find the SSL anywhere.

Thank you for pointing out the SSL, I'll keep an eye out in the future for it. This is something that noobs need to know, I do most of my online shopping on Ebay with paypal but they don't sell E-cigs on there.
 

Dkrom68

Unregistered Supplier
ECF Veteran
Nov 17, 2009
5,288
3,094
57
Backwoods NY USA
It woudl be so nice to poll all the vendors name people have used cause it would really narrow things down ans could possibly pinpoint the source of it. The way it is now is a guessing game. I agree its not a good thing to out vendors names but something needs to be done to stop this. No matter where its coming from the gateway being used is supposed to be secured and PCI scan compliance in place for vulnerabilities of sites to insure this doesnt happen. If there is some way maybe there is info stored on a vendors system which shouldnt be the case it could be a third party getting it of the system with out the vendors actual knowledge by someone working for them. Its just a scary thing and something needs to be done about it.
 
Status
Not open for further replies.

Users who are viewing this thread