Poker Chip Forums-ChipTalk.net
One of the Largest Selections of 100% Plastic Playing Cards
One of the Largest Selections of 100% Plastic Playing Cards
Home Classifieds Site Tools User Tools Quick Links Help
Go Back   Poker Chip Forums-ChipTalk.net > General Poker > Online Poker
User Name
Password Register

» Navigation Menu
» Latest Auction Listings
Title, Username, & Date
25% Cashback for Buy-it-Nows on eBay, using live.com and PayPal
11-17-2008 08:03 PM
Mark Twain Casino Paulsons on Ebay
11-15-2008 02:47 PM
Crystal Card Club-- Billings, MT
11-19-2008 12:40 AM
Very valuable HHR Tonopah Club chips
11-18-2008 12:09 AM
Paulson Legends of the West
11-18-2008 07:55 PM
65 Grey NCV Paulson Private Cardroom Poker Chips
11-18-2008 02:23 PM
custom asm's on ebay 47 chips
11-16-2008 03:18 PM
"Jockey&qu...
11-18-2008 04:59 PM
legends...
11-18-2008 03:57 PM
Let It Ride table
11-17-2008 11:43 PM
Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #81 (permalink)     Top 
Old 01-05-2007, 01:26 AM
shadesofgrey's Avatar
shadesofgrey shadesofgrey is offline
World Series Final Table
 
Join Date: Apr 2005
Location: portland
Age: 98
Posts: 2,833
Chips: 1,818
Rating: 0% (0)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

Quote:
Originally Posted by Zentish
I keep thinking through the vector of your credential compromise, and the simplest explanation would seem that someone got your P* credentials and worked backwards to your netteller account.

I have to assume that the P* client encrypts all it's internet traffic and the only way for someone to obtain your credentials is at one end or the other, your PC or the P* servers.

If the P* authentication systems were compromised, your account and $1000 would be small time compared to what someone could go after. So again, everything points to it being on your side of things.

Your computer and network appears to be secure, although there are a lot of ways these scumbag bot nets can hide themselves on a windows box. Is it possible that you logged on to P* from some other computer or on some other network? Are there other computers on your network that may be compromised?
I remember a while back I wanted to test the security level of poker rooms.. I ran a packet sniffer on all the traffic sent to and from P* to see if login info or card info was being transmitted unencrypted. P*'s was fine, pokerroom was not. Pokerroom sent login and password in a packet unencrypted.... I dropped pokerroom like a rock.

So I think P* is fairly secure. Jambys problem has got to be local....

The fact that her PC looks solid is whats scaring me. obvious good firewall... i snitched nill from jambys IP address. all ports stealth. there's something local to her PC. id like to figure this out / without getting it. period.

Jamby, before you read the rest.... I offer you help beyond this point.

Jamby, In truth, right now, i'd be reinstalling the whole OS. you've been comprimised. not sure how, but for sure it happened.

my money is on an email distro of nasties. not a phishing scam....THIS IS SPOOKY! Its probably all over IRC.

Two last thoughts, its late & im going to vegas tomorrow
Check your keyboard and mouse plugins... make sure there's no HW inbetween.

Jamby, how do you do email? what program? think lists, buyers, sellers, anyone who could also be infected and passing it on?

PM me your email address... i'll send you a google invite.... or anyone else who wants one... ive got over a hundred available.

Going to bed & Going to vegas tomorrow!!
__________________
“One cannot step twice in the same river.” – Heraclitus

Last edited by shadesofgrey : 01-05-2007 at 04:34 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #82 (permalink)     Top 
Old 01-05-2007, 08:31 AM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

No, I've never logged onto P* from any other computer and these are the only two computers on my network that have P* client software. The other laptop is my partner's and it has never been used for any kind of poker or money transfer.
Quote:
Originally Posted by Zentish
Is it possible that you logged on to P* from some other computer or on some other network? Are there other computers on your network that may be compromised?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #83 (permalink)     Top 
Old 01-05-2007, 08:34 AM
WolfPack's Avatar
WolfPack WolfPack is offline
ChipTalk.net Article Writer
 
Join Date: Feb 2006
Location: O-H-I-O
Age: 36
Posts: 2,188
Chips: 223
Rating: 0% (0)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

I don't think NT could have been compromised from someone accessing her P* account.


NT has not only a password, but a pin number and I don't see how someone could get the pin number from P* account, even if they both used the same password.
__________________
Insert something witty here.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #84 (permalink)     Top 
Old 01-05-2007, 08:38 AM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

Google's what I use already. Thanks anyway though.

If it's local it doesn't really make sense that the offender's IP is in Arkansas does it?

Enjoy LV - I hope you get lucky there. Thanks for all your help.
Quote:
Originally Posted by shadesofgrey
IJamby, how do you do email? what program? ... PM me your email address... i'll send you a google invite.... or anyone else who wants one... ive got over a hundred available.
... Going to bed & Going to vegas tomorrow!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #85 (permalink)     Top 
Old 01-05-2007, 09:22 AM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

I heard from Betway today regarding the $300 that went to them. The perpetrator's IP address is: 82.2.232.170.

Here's their response. Real helpful.

Your Netelleraccount have been used on this registration, and the IP adress is:
82.2.232.170

please note that he lost all the funds in Poker and we can not retrieve that money back to you.

Regards,
Betway.com Ltd
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #86 (permalink)     Top 
Old 01-05-2007, 09:37 AM
Nexttime's Avatar
Nexttime Nexttime is offline
World Series Final Table
 
Join Date: Nov 2005
Location: Roch cha cha, NY
Posts: 2,543
Chips: 2,343
Rating: 100% (5)
Re: My Neteller account compromised - already lost over $1100

Quote:
Originally Posted by jamby
My P* and NT passwords were the same. Conceivably, he could have hacked into NT, checked the history for transactions, saw P* and tried the obvious. He then drained my P* account. That's what the P* folks think happened anyway. They weren't suspicious because there were no logon failures when he logged in there and he transferred the funds out the same way they had gone in. No red flags at all. Their conention is that the folks at Betway and ParadiseBet should have used the same precautions and matched the funding source with the account.
Umm.. Don't you have to login with a username, password and a backup id on neteller? The password might have been the same as P* but the P* doesn't use a pin code, right?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #87 (permalink)     Top 
Old 01-05-2007, 09:39 AM
Nexttime's Avatar
Nexttime Nexttime is offline
World Series Final Table
 
Join Date: Nov 2005
Location: Roch cha cha, NY
Posts: 2,543
Chips: 2,343
Rating: 100% (5)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

Quote:
Originally Posted by jamby
I heard from Betway today regarding the $300 that went to them. The perpetrator's IP address is: 82.2.232.170.

Here's their response. Real helpful.

Your Netelleraccount have been used on this registration, and the IP adress is:
82.2.232.170

please note that he lost all the funds in Poker and we can not retrieve that money back to you.

Regards,
Betway.com Ltd

nslookup 82.2.232.170

Non-authoritative answer:
170.232.2.82.in-addr.arpa name = cpc1-seve1-0-0-cust169.popl.cable.ntl.com.

Authoritative answers can be found from:
232.2.82.in-addr.arpa nameserver = dns2.ntli.net.
232.2.82.in-addr.arpa nameserver = dns1.ntli.net.
dns1.ntli.net internet address = 62.253.162.237
dns2.ntli.net internet address = 194.168.4.237



A cable modem at ntl.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #88 (permalink)     Top 
Old 01-05-2007, 09:42 AM
jamby's Avatar
jamby jamby is offline
ChipTalk.net Article Writer
 
Join Date: Oct 2005
Location: Obamaland
Age: 1
Posts: 12,583
Chips: 1,186
Rating: 100% (3)
Re: My Neteller account compromised - already lost over $1100

True enough.
Quote:
Originally Posted by Nexttime
Umm.. Don't you have to login with a username, password and a backup id on neteller? The password might have been the same as P* but the P* doesn't use a pin code, right?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #89 (permalink)     Top 
Old 01-05-2007, 09:47 AM
Harlequin011's Avatar
Harlequin011 Harlequin011 is offline
Sin City Showdown Host
 
Join Date: Feb 2006
Location: In Cincinnati, Out of Position
Posts: 6,014
Chips: 4,683
Rating: 100% (3)
Send a message via AIM to Harlequin011
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

Shades,

It's possible that either P* or Neteller themselves were compromised without Jamby's PC being breached. Possible brute force or something.

Like she said, she hasn't logged into P* for 9 months. That would mean that whoever got this info has probably been sitting on it for 9 months. That seems a little odd to me.

Unless a hash was obtained and it was run against a cracker... That would make sense for the long delay. Do you know what encryption is being used?

Good on you BTW for finding out who protects there traffic.
__________________
C'mon J, let some air out of your balls and get back to playing good profitable poker....
-tomb1

How am I running? Twitter Blog
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #90 (permalink)     Top 
Old 01-05-2007, 10:07 AM
WolfPack's Avatar
WolfPack WolfPack is offline
ChipTalk.net Article Writer
 
Join Date: Feb 2006
Location: O-H-I-O
Age: 36
Posts: 2,188
Chips: 223
Rating: 0% (0)
Re: My Neteller & PokerStars accounts compromised - already lost over $1100

damn, not only is the guy a crook, but a donk as well. He lost $300 in a day.
__________________
Insert something witty here.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

vBClassified Featured Listings
Paulsons, ASM Rounders replicas, ASM solid ca..,
WTS: 44mm/39mm Mixed High Stakes Tournament S..,
650pc Empty Hourglass set
St JOs Casino Paulson Cash Set



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Chips Per Thread View: 0
Chips Per Thread: 3
Chips Per Reply: 1

» Sponsors
Sponsor Forum!
HoldemPokerChips makes special offers to ChipTalk.net members.

The perfect way to display your poker chip collection!

Specializing in high quality world class poker tables & casino gaming equipment

Play Online Poker

Powered by vBadvanced CMPS v3.0 RC2
Play online and get FREE GEAR! High end chips, cards, more! Online Casino Click here for your favorite eBay items FREE MONEY when you sign up through our link!

All times are GMT -5. The time now is 02:47 AM.


Sitemap: All, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19,