View Single Post
Old 09-07-2008, 06:35 PM  
After Shock Media
It's coming look busy
 
After Shock Media's Avatar
 
Join Date: Mar 2001
Location: "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn".
Posts: 35,299
Quote:
Originally Posted by ladida View Post
I never said they actually sent them in, but this is the first part in the scam. Im quite sure they know how the verifications at epassporte go, so if they have offered to send in the docs, im sure they would have sent something. You cought it fast enough so it won't work, but if you did not catch it in time, epass did the first move, reset all your info. Next part was them sending in the documents so they can take control of the account. So either they got your docs from somewhere, or know enough of your personal info to forge docs that look legit, and match with what you have on epass.

Here's one scenario from the top of my head.
You run a porn site. They hack in there, get your personal info from the database, maybe even personal pictures and shit if you keep it on server (many people keep personal things), find out your epass username, and the game begins...

You can be sure they have something, what, i dont know, but they have some info that they were gona use to persuade epass to send them the new login (after it got reset).
I am of course not rulling anything at all out until I get the info back from epass.

As for your scenario, again highly unlikely. I know what info I have outside and what I do not. For instance aside from maybe 5-10 pictures on Fubar that have me in them, or silly fucking general pictures of crap, I do not keep anything online. Hell I do not even email friend and family pictures.

Databases should just contain business info which is different than what epass has.

I really am leaning more towards it just being pure human error with client services and the proper protocols were not followed, but we shall see. Even if I have to eat crow and say yes indeed something was compromised of mine and what it was I will keep this updated as I feel it could effect others and is the only reason I am doing this thread along with private communications with epassporte. If it can happen to someone who is as careful about security as I am, then it is very important to find out the how's and whys as I know many if not most people are not as tight with their security.
__________________

[email protected] ICQ:135982156 AIM: Aftershockmed1a MSN: [email protected]
After Shock Media is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote