[ Phuket Info | Thailand Hotels | Phuket Diving | Phuket Nightlife | Phuket Classifieds | Phuket Links ]
PHUKET-INFO.COM Forums Mai Thai Bar Phuket

Go Back   PHUKET-INFO.COM Forums > PHUKET > Expats

Reply
 
Thread Tools Search this Thread
  #1  
Old 16-06-2007, 19:28
landofsmiles's Avatar
landofsmiles landofsmiles is offline
Registered User [7931]
Senior Elite Member
 
Join Date: Jun 2005
Location: Patong
Age: 52
Posts: 3,944
Nanai internet shop hacked account

I very much suspect a shop in Nanai road is involved in hacking accounts. If not someone working in the shop then one of their customers.

I know I've heard all the warnings about not logging on to bank accounts and such in these places but I've had poor connections in my apartment last few days and succumbed to logging on to my Paypal account yesterday morning in an internet/games shop.

2 hours later I get emails from Paypal saying my password and security questions/answers have been changed and also that I have authorised a payment to someone (an Italian sounding name) which was the exact amount in my account.

Luckily by the time I got to know about it the money had not yet been claimed by the thief and once I'd reported that to Paypal it was immediately restored to my account.

Coincidence probably, but I was in the shop for about 2 hours and there was only one other guy on the net and hearing him make a phone call he sounded Italian.

I don't suppose I need say exactly which shop as I suppose the warning should apply to all of them.
Reply With Quote
Guest Info

+:+:+ Forum Headquarter +:+:+
Mai Thai Bar
If you look for a hotel - Book hotel here
Register and become a member and you will not see this box.

  #2  
Old 16-06-2007, 19:55
JayBee's Avatar
JayBee JayBee is online now
Registered User [1976]
Senior Elite Member
 
Join Date: Mar 2004
Location: cALIFORNIA, usa
Posts: 7,851
Quote:
Originally Posted by landofsmiles;
I very much suspect a shop in Nanai road is involved in hacking accounts. If not someone working in the shop then one of their customers.

I know I've heard all the warnings about not logging on to bank accounts and such in these places but I've had poor connections in my apartment last few days and succumbed to logging on to my Paypal account yesterday morning in an internet/games shop.

2 hours later I get emails from Paypal saying my password and security questions/answers have been changed and also that I have authorised a payment to someone (an Italian sounding name) which was the exact amount in my account.

Luckily by the time I got to know about it the money had not yet been claimed by the thief and once I'd reported that to Paypal it was immediately restored to my account.

Coincidence probably, but I was in the shop for about 2 hours and there was only one other guy on the net and hearing him make a phone call he sounded Italian.

I don't suppose I need say exactly which shop as I suppose the warning should apply to all of them.

Good reminder to never log into bank account, brokerage account, or Paypal account in an internet cafe!!! Thanks, LOS!! You were lucky to catch the intruder in time to prevent a loss.

I think wifi is still safe, or at least I hope so!!
__________________
LOS is warm, soft, smooth, and brown.
Reply With Quote
  #3  
Old 16-06-2007, 20:16
LivinLOS's Avatar
LivinLOS LivinLOS is offline
Registered User [2776]
Senior Elite Member
 
Join Date: Jun 2004
Location: Phuket
Age: 35
Posts: 19,861
Wifi is not safe unless your over an encrypted connection..

I recently saw a 199 mini laptop design.. Pretty basic but a good idea for those travelling for banking and email..

If you have a laptop take your own to the net cafes.. Most will allow you to connect your own laptop and thats a LOT better, the same as wifi networking.
__________________
Men have only 2 emotional states, hungry and horny.. So ladies, if you see me without an erection, make me a sandwich.
Reply With Quote
  #4  
Old 16-06-2007, 20:55
ATMwalking's Avatar
ATMwalking ATMwalking is offline
Registered User [15129]
Senior Elite Member
 
Join Date: Jul 2006
Location: Phuket
Age: 47
Posts: 3,379
No hacking required. All they need to do is install a program that captures keystrokes.

Even easier, most cafes leave the form auto complete option on. So they are being saved automatically.
__________________
Women with a past and men without a future grope and shuffle on the dance floor.
Reply With Quote
  #5  
Old 16-06-2007, 21:51
Coolhand's Avatar
Coolhand Coolhand is offline
Registered User [559]
Senior Elite Member
 
Join Date: Aug 2003
Location: Hong Kong
Posts: 2,343
keep a text file with your user names and passwords on a memory stick. Plug memory stick into computer and open text file. Copy and paste user names and passwords if you have to.
Of course to make it harder the textfile should be full of different user names and passwords.
Dont forget to close the text file and taake your memory stick with you when you leave.
__________________
"管它黑貓白貓,會抓老鼠的就是好貓"
Reply With Quote
  #6  
Old 17-06-2007, 00:45
SiamGecko's Avatar
SiamGecko SiamGecko is offline
Registered User [21394]
Junior Member - Bronze
 
Join Date: Mar 2007
Location: Rawai, Phuket
Posts: 136
There's a few easy things to do to give yourself some more protection.

Use MobileFirefox as your browser running on a usb stick. No history will be left on the cafe's PC and no passwords will be cached. It's also a great way of keeping your own custom browser with you when you are travelling, so your fav's, cookies etc.. are all available.

Also when typing passwords, do it in a random order. So if your password was phuket123, type it as uket123 then go back and add the 2 letters at the beginning. To a keylogger it would look like uket123ph
Reply With Quote
  #7  
Old 17-06-2007, 00:49
SiamGecko's Avatar
SiamGecko SiamGecko is offline
Registered User [21394]
Junior Member - Bronze
 
Join Date: Mar 2007
Location: Rawai, Phuket
Posts: 136
Quote:
Originally Posted by Coolhand View Post
keep a text file with your user names and passwords on a memory stick. Plug memory stick into computer and open text file. Copy and paste user names and passwords if you have to.
Of course to make it harder the textfile should be full of different user names and passwords.
Dont forget to close the text file and taake your memory stick with you when you leave.
I wouldn't do that personally. It's not difficult for someone to hook up to your machine and read your usb key when you are using it.

Much better to go with the mobile firefox and you can even password protect accessing your passwords within the settings, so even if someone did copy your firefox profile off the usb key, then they would not be able to see any passwords.
Reply With Quote
  #8  
Old 17-06-2007, 01:11
Robaht's Avatar
Robaht Robaht is offline
Registered User [8745]
Junior Member - Gold
 
Join Date: Aug 2005
Location: Bangkok
Age: 36
Posts: 413
Those are 2 pretty good ideas. I like the idea of typing in your password in a weird order, don't know why I never thought of that. But how did you know my password was phuket123?

Cheers, Robaht

Quote:
Originally Posted by SiamGecko View Post
There's a few easy things to do to give yourself some more protection.

Use MobileFirefox as your browser running on a usb stick. No history will be left on the cafe's PC and no passwords will be cached. It's also a great way of keeping your own custom browser with you when you are travelling, so your fav's, cookies etc.. are all available.

Also when typing passwords, do it in a random order. So if your password was phuket123, type it as uket123 then go back and add the 2 letters at the beginning. To a keylogger it would look like uket123ph
Reply With Quote
  #9  
Old 17-06-2007, 02:35
JayBee's Avatar
JayBee JayBee is online now
Registered User [1976]
Senior Elite Member
 
Join Date: Mar 2004
Location: cALIFORNIA, usa
Posts: 7,851
Quote:
Originally Posted by Robaht;
But how did you know my password was phuket123?

Uh Oh!! Seems a lot of us have the same password! I'm changing mine to uket123ph.
__________________
LOS is warm, soft, smooth, and brown.
Reply With Quote
  #10  
Old 17-06-2007, 02:48
MrDK's Avatar
MrDK MrDK is online now
Registered User [6516]
Senior Elite Member
 
Join Date: Feb 2005
Location: Amalika - ลาร์ส
Age: 49
Posts: 6,968
Quote:
Originally Posted by JayBee View Post
Uh Oh!! Seems a lot of us have the same password! I'm changing mine to uket123ph.
I know a lot of people who have the same password as I: *******
I have given up keeping it a secret.
__________________
Help support a Pattaya orphanage
www.OrphanKids.COM
Reply With Quote
  #11  
Old 17-06-2007, 03:51
ub2yoo's Avatar
ub2yoo ub2yoo is offline
Registered User [14467]
Senior Elite Member
 
Join Date: Jun 2006
Location: Dubai
Age: 37
Posts: 3,696
Quote:
Originally Posted by Coolhand View Post
keep a text file with your user names and passwords on a memory stick. Plug memory stick into computer and open text file. Copy and paste user names and passwords if you have to.
Of course to make it harder the textfile should be full of different user names and passwords.
Dont forget to close the text file and taake your memory stick with you when you leave.

Doesn't solve the problem. There are Trojans i.e. Beast, which have the capability to capture what you copy into memory.
__________________

...life's good
Reply With Quote
  #12  
Old 17-06-2007, 06:06
crazyswede's Avatar
crazyswede crazyswede is offline
Registered User [947]
Senior Elite Member
 
Join Date: Nov 2003
Location: The BackYards Of Bangkok but heart in Bhan Kam/Chom Pra/Surin!
Age: 44
Posts: 3,390
Send a message via MSN to crazyswede Send a message via Yahoo to crazyswede
Cool

Have had simular e-mail´s but i never used PayPal in all my life .. they must have picked the wrong guy i gue´s!


Quote:
Originally Posted by landofsmiles View Post

2 hours later I get emails from Paypal saying my password and security questions/answers have been changed and also that I have authorised a payment to someone!
__________________
CS//
Reply With Quote
  #13  
Old 17-06-2007, 07:51
Crazy_Matt's Avatar
Crazy_Matt Crazy_Matt is offline
Registered User [12506]
Junior Member - Bronze
 
Join Date: Mar 2006
Location: BrisVegas
Age: 31
Posts: 119
Send a message via MSN to Crazy_Matt
Good thread this one!

All should be careful when using internet cafe's for banking and such.

Quote:

Also when typing passwords, do it in a random order. So if your password was phuket123, type it as uket123 then go back and add the 2 letters at the beginning. To a keylogger it would look like uket123ph

Top Idea!

Any Geeky types on the boards know the answer to this one, what about clearing Cookies - Cache and brower windows at end of session ?

When your finished you could even Download a Registry Cleaner and clean the whole bastard out when your finished ... ?? Get a free one that will take all entries out from download.com or something like that.
Reply With Quote
  #14  
Old 17-06-2007, 08:20
LivinLOS's Avatar
LivinLOS LivinLOS is offline
Registered User [2776]
Senior Elite Member
 
Join Date: Jun 2004
Location: Phuket
Age: 35
Posts: 19,861
Quote:
Originally Posted by SiamGecko View Post
There's a few easy things to do to give yourself some more protection.

Use MobileFirefox as your browser running on a usb stick. No history will be left on the cafe's PC and no passwords will be cached. It's also a great way of keeping your own custom browser with you when you are travelling, so your fav's, cookies etc.. are all available.

Also when typing passwords, do it in a random order. So if your password was phuket123, type it as uket123 then go back and add the 2 letters at the beginning. To a keylogger it would look like uket123ph

Sorry but any good keylogger will record uket123 [back][back][back][back][back][back]ph If you use the mouse thats a better implementation but many good keylogging and monitoring systems will also record all inputs and video.. Even more than a decade ago this was being done with backorifice and butt trumpet etc..

Your only semi safe solutions are your own machine or using a boot from a USB or live CD operating system.. Linux now boots from USB prety easily (and is getting leaps and bounds better as a desktop OS.. KDE4 may really be a watershed point) but even then hardware keyloggers can exist.

Simple rule is never access anything important on a public machine.

My predicition is this Eee PC (a 199 USD asus mini laptop) will sell like hot cakes... I think a huge % of laptop owners only use thier mobile machine for net connections and net applications and this machine fits that need so well.
__________________
Men have only 2 emotional states, hungry and horny.. So ladies, if you see me without an erection, make me a sandwich.
Reply With Quote
  #15  
Old 17-06-2007, 10:45
landofsmiles's Avatar
landofsmiles landofsmiles is offline
Registered User [7931]
Senior Elite Member
 
Join Date: Jun 2005
Location: Patong
Age: 52
Posts: 3,944
Pretty p#ssed off now. Have found that other sites I accessed while in that shop that required passwords...my passwords don't work now.
Reply With Quote
  #16  
Old 17-06-2007, 12:02
LivinLOS's Avatar
LivinLOS LivinLOS is offline
Registered User [2776]
Senior Elite Member
 
Join Date: Jun 2004
Location: Phuket
Age: 35
Posts: 19,861
Name and shame the shop IMO..

Its obvious its one where they are tracking users.
__________________
Men have only 2 emotional states, hungry and horny.. So ladies, if you see me without an erection, make me a sandwich.
Reply With Quote
  #17  
Old 17-06-2007, 12:27
landofsmiles's Avatar
landofsmiles landofsmiles is offline
Registered User [7931]
Senior Elite Member
 
Join Date: Jun 2005
Location: Patong
Age: 52
Posts: 3,944
Isn't it more likely that the shop owner/staff know nothing about it and that it's a farang going in and plugging in some gadget?

From my Paypal account I have the name (Italian sounding) that my money was heading for. I wonder if the guy would be stupid enough to use his real name?
Reply With Quote
  #18  
Old 17-06-2007, 12:38
LivinLOS's Avatar
LivinLOS LivinLOS is offline
Registered User [2776]
Senior Elite Member
 
Join Date: Jun 2004
Location: Phuket
Age: 35
Posts: 19,861
Doubt it.. Possible of course but most publically released keyloggers (not self written or VERY new literally 0 day stuff) will be caught by AV software.. So the AV soft needs to be set up to make exceptions on the keylogger running. Thats more a thing set up by the admin.
__________________
Men have only 2 emotional states, hungry and horny.. So ladies, if you see me without an erection, make me a sandwich.
Reply With Quote
  #19  
Old 17-06-2007, 16:42
SiamGecko's Avatar
SiamGecko SiamGecko is offline
Registered User [21394]
Junior Member - Bronze
 
Join Date: Mar 2007
Location: Rawai, Phuket
Posts: 136
Quote:
Originally Posted by LivinLOS View Post
Sorry but any good keylogger will record uket123 [back][back][back][back][back][back]ph If you use the mouse thats a better implementation but many good keylogging and monitoring systems will also record all inputs and video.. Even more than a decade ago this was being done with backorifice and butt trumpet etc..

Your only semi safe solutions are your own machine or using a boot from a USB or live CD operating system.. Linux now boots from USB prety easily (and is getting leaps and bounds better as a desktop OS.. KDE4 may really be a watershed point) but even then hardware keyloggers can exist.

Simple rule is never access anything important on a public machine.

Not suggesting using the keyboard to go [back]... but it's certainly better than just entering straight passwords....especially if they are dictionary based, which should be a no-no for everyone's passwords anyway.

There's no way to be 100% on a public machine, and as has been said - don't use internet cafe's for anything remotely important
Reply With Quote
  #20  
Old 17-06-2007, 17:05
Nicke's Avatar
Nicke Nicke is offline
Administrator [1]
Senior Elite Member
 
Join Date: May 2002
Location: Patong beach, Thailand
Age: 37
Posts: 9,910
Send a message via ICQ to Nicke
Why not report this to police?
__________________
PhuketThailand PhotosMai Thai Bar
Reply With Quote
  #21  
Old 17-06-2007, 20:14
landofsmiles's Avatar
landofsmiles landofsmiles is offline
Registered User [7931]
Senior Elite Member
 
Join Date: Jun 2005
Location: Patong
Age: 52
Posts: 3,944
Because more than likely they will want to know what accounts and sites have been compromised and I don't really want them looking into that.

All my email accounts have been hacked too and the passwords changed :-(
Reply With Quote
  #22  
Old 18-06-2007, 16:23
Entrep Entrep is offline
Registered User [21045]
Junior Member
 
Join Date: Mar 2007
Location: Phuket
Posts: 41
How do you know it is the shop and not someone who installed software on the PC there?
Reply With Quote
  #23  
Old 18-06-2007, 16:31
LivinLOS's Avatar
LivinLOS LivinLOS is offline
Registered User [2776]
Senior Elite Member
 
Join Date: Jun 2004
Location: Phuket
Age: 35
Posts: 19,861
See post 18
__________________
Men have only 2 emotional states, hungry and horny.. So ladies, if you see me without an erection, make me a sandwich.
Reply With Quote
  #24  
Old 18-06-2007, 21:26