Username
Password
Login is SSL protected. By clicking on "Log in Now" you agree to gixen.com terms of usage.


   SearchSearch     

Gixen under attack today

 
Post new topic   Reply to topic    Gixen.com Forum Index -> Support
View previous topic :: View next topic  
Author Message
mario
Site Admin


Joined: 03 Oct 2006
Posts: 7253

PostPosted: Mon Jun 20, 2016 1:11 pm    Post subject: Gixen under attack today Reply with quote

Gixen has been under attack today for several hours. The issue seems to be resolving now after I blocked all requests coming through proxies.

Apparently the attack originates from Hong Kong (the IP from which it originates is known now), and the attacker has used some 4,500 web proxies to issue login requests to Gixen. This has in several instances compromised Gixen's IPs with eBay, which resulted in many Gixen users triggering ebay's verification.

Things are normalizing now after I managed to block proxies.
Back to top
View user's profile Send private message Send e-mail
fred100
Guest





PostPosted: Mon Jun 20, 2016 4:54 pm    Post subject: Reply with quote

i have an german ebay account and my password was just reset by ebay.
so this has then obviously something to do with this incident?

was there any user data stolen from gixen?
Back to top
mario
Site Admin


Joined: 03 Oct 2006
Posts: 7253

PostPosted: Mon Jun 20, 2016 5:15 pm    Post subject: Reply with quote

No, no data was stolen. My own ebay account was also reset by eBay, probably as a precaution.

This is something I have never seen before, both in sophistication and magnitude. Over 8,000 web proxies have been used, and more than 200,000 login attempts made. I disabled attack after 20,000 or so login attempts that were made just in a few hours, but kept logging information to see what's going on. Now I also blocked all 8,000 proxies in the firewall so cannot longer see further attacks. No need for it anyway.

Since not all the proxies used were anonymizing proxies, I was able to find out the original IP addresses from which attacks are made, and they originate in Hong Kong and two more different locations in China.
Back to top
View user's profile Send private message Send e-mail
Fire_Bad_Tree_Ppretty
Guest





PostPosted: Mon Jun 20, 2016 5:15 pm    Post subject: Re: Gixen under attack today Reply with quote

mario wrote:
Gixen has been under attack today for several hours. The issue seems to be resolving now after I blocked all requests coming through proxies.

Apparently the attack originates from Hong Kong (the IP from which it originates is known now), and the attacker has used some 4,500 web proxies to issue login requests to Gixen. This has in several instances compromised Gixen's IPs with eBay, which resulted in many Gixen users triggering ebay's verification.

Things are normalizing now after I managed to block proxies.


Because of the hack I had to reset my eBay password.

I can now log back into my eBay account just fine.

Logging into Gixen.com with the new password works also but all of my upcoming snipes are gone.

History does show my past snipes.

Can my upcoming snipes be recovered.
Back to top
Gixen
Advertisements





PostPosted: Mon Jun 20, 2016 5:15 pm    Post subject: Re: Gixen under attack today

Back to top
rketmps
Guest





PostPosted: Mon Jun 20, 2016 5:25 pm    Post subject: That's My Issuw Too... Reply with quote

...can the snipes be recovered that I listed for the next few days?
Back to top
mario
Site Admin


Joined: 03 Oct 2006
Posts: 7253

PostPosted: Mon Jun 20, 2016 5:37 pm    Post subject: Reply with quote

Please email me and include your ebay username and description of some of the snipes scheduled.
Back to top
View user's profile Send private message Send e-mail
Guest






PostPosted: Mon Jun 20, 2016 8:05 pm    Post subject: under attack Reply with quote

once password is changed, log back in to gixen, all good once watchlist imported

eBay in Major spin lol Laughing
Back to top
namewitheld
Guest





PostPosted: Mon Jun 20, 2016 8:33 pm    Post subject: Attack Reply with quote

My internet security knowledge is pretty basic. Can you explain how the attack was able to cause ebay to reset my password but the attacker didn't get any login info? At the minimum they were able to get my ebay username, or how else would ebay identify my account as "Unauthorized use of your account"?.
Back to top
mario
Site Admin


Joined: 03 Oct 2006
Posts: 7253

PostPosted: Mon Jun 20, 2016 8:49 pm    Post subject: Reply with quote

Hackers didn't get anything.

What happened is - they did a brute force attack with login attempts that resulted in Gixen's IPs getting flagged by eBay, as Gixen relayed those attempts to eBay servers. When Gixen subsequently tried to submit your bids using the same IPs, eBay decided to reset many users' passwords.

So it's a correlation thing - hackers submit a bad login request to Gixen, Gixen relays those to eBay, and after several of those eBay's flags Gixen's IPs. And then even a legitimate login from Gixen servers gets refused and passwords reset.

Things are clearing now after I blocked some 10,000 proxy IPs already through which this brute force attack came.
Back to top
View user's profile Send private message Send e-mail
genri200
Guest





PostPosted: Mon Jun 20, 2016 9:23 pm    Post subject: Reply with quote

I also received "Unauthorized use of your account" message from ebay. Sad
Back to top
namewitheld
Guest





PostPosted: Mon Jun 20, 2016 10:22 pm    Post subject: ebay server Reply with quote

Thank you for the clarification. Will ebay blacklist Gixen IP's if this happens again?
Back to top
lazy*daysleeper
Guest





PostPosted: Mon Jun 20, 2016 11:20 pm    Post subject: Reply with quote

eBay has reset my password earlier today and asks me to change my old password. But how am I supposed to change it, when I'm unable to log in?
Back to top
lazy*daysleeper
Guest





PostPosted: Mon Jun 20, 2016 11:34 pm    Post subject: Reply with quote

Done. They provided link with instructions that I overlooked..
Back to top
ianoid
Guest





PostPosted: Tue Jun 21, 2016 12:54 am    Post subject: link/TIMEOUT error Reply with quote

lazy*daysleeper wrote:
Done. They provided link with instructions that I overlooked..


do yourself a favor and avoid clicking on links to do things like reset your password- from any company. If you need to reset your password, login to any account you have separately and then find the link yourself to avoid becoming a victim of phishing.


And on another note I had several bids that didn't go through with the error "HTTP TIMEOUT (77)"

Is this related to the attack? Will my other bids work normally?
Back to top
Guest






PostPosted: Tue Jun 21, 2016 2:47 am    Post subject: Reply with quote

Same with me, got password reset email from eBay. Went to eBay and did password change process. Can log into eBay now, but Gixen Desktop Manager is missing my scheduled bids and so is gixen.com/home_2.php after I log into gixen.com.
Back to top
TIO200
Guest





PostPosted: Tue Jun 21, 2016 3:21 am    Post subject: RESETTING YOUR UPCOMING BIDS Reply with quote

I reset my password as requested by ebay. but I still see that over 40 of my upcoming bids read as having been cancelled. I used the edit feature to add a few pennies to each bid and am hoping that they go through; as they now read scheduled ! Without trying to be wicked, perhaps the newer higher bids that I see on my want list won't go through as perhaps not every diligent gixen user bothered to make any changes. if you don't make any edits. your old bids will remain cancelled.
Back to top
kevin
Guest





PostPosted: Tue Jun 21, 2016 4:23 am    Post subject: PASSWORD CHANGES Reply with quote

Don't forget to change you Gixen / ebay login as well or gixen will use the old password and not get in.... if you have changed it on ebay - also give it a few minutes for the password change to take effect - i had a couple of snipes right in the middle of all of this - got into my ebay after a password change then quickly changed the log in here - all ok
Back to top
tio200
Guest





PostPosted: Tue Jun 21, 2016 5:17 am    Post subject: GIXEN LOST SNIPES EVEN AFTER I CHANGED PASSWORDS AND RESET Reply with quote

I thought I was ahead of the game by editing my cancelled snipes and they read scheduled.. but still GIXEN couldn't get ebay to verify the sign in authentication. the last time this happened i had to remove all of my sign on saved passwords from google and Chrome before things cleared up. I got up at 6 am to make sure that things were alright.. they seemed fine when Gixen listed everything as scheduled,, but there were a few snipes scheduled for 27 minutes later that didn't go through because of this issue. I will try to delete all of my saved passwords and enter GIXEn manually. I was told by GIXEn that it didn't matter what settings that were on an individual's browsers; as once they were accepted by GIXEN, they would go directly to ebay, apparently this is not true.
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 7956
Location: Bristol, UK

PostPosted: Tue Jun 21, 2016 5:19 am    Post subject: Reply with quote

I'd like to highlight Kevins advice here.

If you change your credentials on Ebay you MUST then use the new credentials here before any of your snipes are going to work.

Gixen will accept your OLD credentials before you submit new ones... this allows you to see your old snipes that have those old credentials associated with them but NONE of them will work... I advise you to make a note of them and then delete them.

Once you log in with your new credentials you must then reschedule all your snipes before your new credentials will be associated with them, allowing them to be successful when Gixen logs in for you at the end of the auction.

Just logging in with your old credentials and editing the snipes is NOT going to work... in fact it is most likely to make things worse for you since you are then forcing Gixen to try to log into your Ebay account with the wrong credentials.
_________________
Mark
Back to top
View user's profile Send private message
sale1579
Guest





PostPosted: Tue Jun 21, 2016 9:50 am    Post subject: Thing not back to normal yet Reply with quote

item : 252427630138

still not working for me , CANCELED - VERIFICATION CODE REQUIRED BY EBAY or COULD NOT BID: PHONE OR TEXT VERIFICATION REQUESTED BY EBAY
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 7956
Location: Bristol, UK

PostPosted: Tue Jun 21, 2016 9:58 am    Post subject: Reply with quote

sale1579.

Please read my response to your last post on this thread:

http://www.gixen.com/forum/viewtopic.php?t=7978
_________________
Mark
Back to top
View user's profile Send private message
kmzs
Guest





PostPosted: Tue Jun 21, 2016 11:34 am    Post subject: Miami mirror not working Reply with quote

But gixen mirror is stilling not working for me. Error status:

COULD NOT BID: PHONE OR TEXT VERIFICATION REQUESTED BY EBAY
CANCELED - VERIFICATION CODE REQUIRED BY EBAY
Back to top
Guest
Guest





PostPosted: Tue Jun 21, 2016 11:55 am    Post subject: Hack attempt Reply with quote

I want to commend you on your effective response to this threat and your transparency about what happened. Thank you!
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 7956
Location: Bristol, UK

PostPosted: Tue Jun 21, 2016 11:55 am    Post subject: Reply with quote

kmzs,

Please email Mario at the support address given on the Contact tab above.

Include your Ebay id, and a brief explanation, that Main submits bids but Mirror fails for you with the status that you posted.
_________________
Mark
Back to top
View user's profile Send private message
julesjelev
Guest





PostPosted: Tue Jun 21, 2016 12:02 pm    Post subject: Reply with quote

Cupid wrote:

If you change your credentials on Ebay you MUST then use the new credentials here before any of your snipes are going to work.


Where can I change that?
I went into settings but couldn't see a spot to enter my new Ebay password.
Would Gixen automatically update my password based on my last Ebay log-in through Gixen's website?
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 7956
Location: Bristol, UK

PostPosted: Tue Jun 21, 2016 12:10 pm    Post subject: Reply with quote

julesjelev,

There isn't anything to do this in 'Settings' that isn't how Gixen works, this is a deliberate design choice for Gixen, so that your credentials are never held longer than necessary in order to submit bids on your scheduled snipes.

Yes as I think you are implying, Gixen uses the credentials that you use to log in here. They are verified with Ebay every time you log in with different ones from previously.

That is why you lose access to all your scheduled snipes when you log in with new credentials, because then none of the snipes that you had previously set up match those credentials.
_________________
Mark
Back to top
View user's profile Send private message
Guest






PostPosted: Tue Jun 21, 2016 12:18 pm    Post subject: Reply with quote

Thanks Cupid!

So it appears Gixen will save every scheduled bid together with my username and password and then use this information to place the bid. This makes sense. Smile
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 7956
Location: Bristol, UK

PostPosted: Tue Jun 21, 2016 12:29 pm    Post subject: Reply with quote

Yes, that is correct.
_________________
Mark
Back to top
View user's profile Send private message
animegination
Guest





PostPosted: Tue Jun 21, 2016 7:17 pm    Post subject: Can Gixen modify software to allow access to cancelled snipe Reply with quote

Just wondering if it is possible to modify your software to allow users to import the cancelled auction sniping information when an Ebay password is changed. It looks like this functionality is going to be critical as more of these attacks occur. I am lost now as when I look at the instructions for direct proxy modifications they are overwhelming for me right now.
Back to top
sale1579
Guest





PostPosted: Tue Jun 21, 2016 11:12 pm    Post subject: gixen miami still not working Reply with quote

Gixen main Chicago working for me, but gixen mirror miami still has the same error message :

COULD NOT BID: PHONE OR TEXT VERIFICATION REQUESTED BY EBAY
CANCELED - VERIFICATION CODE REQUIRED BY EBAY

item number : 262486950888
Back to top
Cupid



Joined: 09 Aug 2007
Posts: 7956
Location: Bristol, UK

PostPosted: Wed Jun 22, 2016 12:03 am    Post subject: Reply with quote

animegination,

I agree that a migration facility is now something that Mario should seriously look into providing.

The need for the socks proxy is a different issue, if you need to use that then there isn't really any other option that can be provided to help resolve the situation.

sale1579,

For a more speedy resolution I would recommend that you now go the email route, please include your Ebay id in all correspondence.
_________________
Mark
Back to top
View user's profile Send private message
fire_bad
Guest





PostPosted: Wed Jun 22, 2016 5:52 am    Post subject: Reply with quote

Cupid wrote:
I'd like to highlight Kevins advice here.

If you change your credentials on Ebay you MUST then use the new credentials here before any of your snipes are going to work.

Gixen will accept your OLD credentials before you submit new ones... this allows you to see your old snipes that have those old credentials associated with them but NONE of them will work... I advise you to make a note of them and then delete them.

Once you log in with your new credentials you must then reschedule all your snipes before your new credentials will be associated with them, allowing them to be successful when Gixen logs in for you at the end of the auction.

Just logging in with your old credentials and editing the snipes is NOT going to work... in fact it is most likely to make things worse for you since you are then forcing Gixen to try to log into your Ebay account with the wrong credentials.


Thanks for the tip in logging in with the old credentials to retrieve the snipes. I did not know that.

Also those who have are mirror subscribers you can do a CVS Export (under settings at the bottom) and use that data to Import your snipes with your new credentials.
Back to top
kmzs
Guest





PostPosted: Wed Jun 22, 2016 8:15 am    Post subject: Reply with quote

julesjelev wrote:
Cupid wrote:

If you change your credentials on Ebay you MUST then use the new credentials here before any of your snipes are going to work.


Where can I change that?
I went into settings but couldn't see a spot to enter my new Ebay password.
Would Gixen automatically update my password based on my last Ebay log-in through Gixen's website?


Gixen stores your username and password to each records, so it's impossible to just set new password within Gixen.

You need to use your old password to login Gixen. Open a new window/tab, use your new password to login Gixen again. Then you can manually add each of the items from the old 'account' to the new one.

For mirror users, I expect the csv export/import feature will work for this case, however, it appears that all bids canceled duo to the verification problem will not be exported. Sad
Back to top
deadbbaron
Guest





PostPosted: Wed Jun 22, 2016 5:51 pm    Post subject: Would this current problem be the reason I am not recieivinG Reply with quote

I had two bids on early this morning ,when I checked my emails there was no notification from Gixen that I had won these lots.Also there was no notification from eBay either.
Both show up as won on my won lots on eBay.
Could this all be tied in with this problem?
Back to top
jet_kit
Guest





PostPosted: Thu Jun 23, 2016 7:31 am    Post subject: Hackers Reply with quote

mario wrote:
Hackers didn't get anything.

What happened is - they did a brute force attack with login attempts that resulted in Gixen's IPs getting flagged by eBay, as Gixen relayed those attempts to eBay servers. When Gixen subsequently tried to submit your bids using the same IPs, eBay decided to reset many users' passwords.

So it's a correlation thing - hackers submit a bad login request to Gixen, Gixen relays those to eBay, and after several of those eBay's flags Gixen's IPs. And then even a legitimate login from Gixen servers gets refused and passwords reset.

Things are clearing now after I blocked some 10,000 proxy IPs already through which this brute force attack came.


Hi,
I've also had to change my ebay password as a result, but Gixen will not accept the new password. After two tries it locks me out for an hour. I've been trying to get back all day without success.
Any ideas.
Back to top
helloworld
Guest





PostPosted: Thu Jun 23, 2016 12:36 pm    Post subject: Reply with quote

I was forced to reset the password by eBay as well. After password reset, I can log in to eBay and bid without any issue. However, my new password would not work on Gixen after 2 tries with the new password I was locked out for an hour. After one hour, I cleared eBay and Gixen cookies, and set browser proxy to Gixen's and logged into eBay to make an successful bid, and I tried making another attempt to log in to Gixen, password is rejected.
Is this common for everyone else? Are there any solutions to this problem.
Back to top
guestognized
Guest





PostPosted: Thu Jun 23, 2016 7:19 pm    Post subject: Error Reply with quote

Hello team,

I am getting this error even after changing my password through eBay.

No items imported. If you have items on your watchlist, and they do not get imported, it is possible that eBay blocked watchlist import with captcha images. Please enter your items manually by copy/pasting item id(s).

Any one know of any ideas?
Back to top
Flo
Guest





PostPosted: Fri Jun 24, 2016 12:48 am    Post subject: Reply with quote

hi dude ,

I got this message on my snip after change password
CANCELED - VERIFICATION CODE REQUIRED BY EBAY or COULD NOT BID: PHONE OR TEXT VERIFICATION REQUESTED BY EBAY

I have send message to ebay but no answer :/


Have you got solution ? plz

Thx
Back to top
sale1579
Guest





PostPosted: Fri Jun 24, 2016 2:46 am    Post subject: Gixen mirrow error login time out Reply with quote

After changing password and change proxy it worked fine for me yesterday, but I noticed all the gixen miror Miami still have problems :

EBAY ERROR: LOGIN TIMEOUT (1)

Main gixen Chicago worked fine, only one auction had the error :

UNKNOWN ERROR (3)

The item is 391478679238

Thanks for looking into the problem for me !
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Gixen.com Forum Index -> Support All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

© 2006 - 2023 Gixen.com. Forum powered by phpBB © 2001, 2005 phpBB Group.