Topic Wiki

Please email dan@dansdeals.com for help accessing your account if you can't reset your password.
« Last edited by Dan on August 30, 2023, 07:51:46 PM »

Author Topic: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!  (Read 12754 times)

Offline Yo ssi

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Aug 2019
  • Posts: 6975
  • Total likes: 2745
  • DansDeals.com Hat Tips 60
  • Gender: Male
    • View Profile
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #80 on: August 27, 2023, 03:13:11 PM »
There should be a 2FA badge so a user can have a bit more security
_    ,
' )  /
 /  / __   _   _   o
(__/_(_)  /_)_/_)_<_
 //
(/

Offline Essen est zich

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Apr 2017
  • Posts: 2225
  • Total likes: 749
  • DansDeals.com Hat Tips 31
    • View Profile
  • Programs: Nichoach Vol 2
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #81 on: August 27, 2023, 04:02:31 PM »
There should be a 2FA badge so a user can have a bit more security
Or a user verified badge which would require more personal info when creating a account...
Shloffen Shloft Zich

Offline yitzyul

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Jul 2011
  • Posts: 2988
  • Total likes: 142
  • DansDeals.com Hat Tips 70
    • View Profile
  • Location: Monsey
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #82 on: August 27, 2023, 04:45:40 PM »
Yes my acct was hacked.
What was interesting is that
1)they never changed my password (which is usually the 1st step) or email address (then I wouldnt have known) so I suspect that the hacker didn't actually have the password (as you need the password to change it) or had a computer program that just tried numerous variations..
2) or they purposely didnt change the password as they thought that it might send me an email that it was changed...but didn't realize that all DM's send an email to my email address.
3) Another factor the DM they sent people where pretty similar to legit emails, as usually scams will lowball to try to get a deal as fast as possible. Here they didnt do that so I suspect that the hacker has been around DDF for a while and "knew" how to post or send DM's


Regardless I noticed at approx. 10 AM that I had some 20 emails in my account about people interested in gift cards so I knew that it was hacked. I immediately changed my password & emailed everyone (or almost) and told that I was hacked do not send any codes. I couldn't delete all the posts. The annoying part is that they deleted my inbox which I have messages saved for some 10+ years.

I didnt get a chance to read this thread, so could be was mentioned , but an email notification of a password reset is a must ASAP!
TY

« Last Edit: August 27, 2023, 04:50:15 PM by yitzyul »

Offline Alexsei

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Sep 2011
  • Posts: 5963
  • Total likes: 1520
  • DansDeals.com Hat Tips 5
    • View Profile
    • Travel & Kivrei Zadikim
  • Location: Truckistan
  • Programs: COVID-23
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #83 on: August 27, 2023, 05:09:01 PM »
Jews ≠ Zionists
Palestinians ≠ Hamas
Satmar ≠ SatmarHQ

Offline Definitions2

  • Dansdeals Platinum Elite
  • ****
  • Join Date: Aug 2023
  • Posts: 262
  • Total likes: 185
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: Lakewood
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #84 on: August 27, 2023, 05:10:30 PM »
I changed my password but for some reason I can't login. I dont have the email used to register my account. I'm not sure what happened. Likely forgot the new password

I'm not selling anything in case anybody gets a message from me.

Offline lcm

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Jul 2019
  • Posts: 1707
  • Total likes: 670
  • DansDeals.com Hat Tips 6
    • View Profile
  • Location: 5th paragraph of https://www.dansdeals.com/sms/
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #85 on: August 27, 2023, 05:58:59 PM »
Even after resetting my password, still able to access via tapa

Offline CountValentine

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Mar 2013
  • Posts: 17342
  • Total likes: 7841
  • DansDeals.com Hat Tips -1
  • Gender: Female
    • View Profile
  • Location: Poland - Exiled
  • Programs: DAOTYA, DDF Level 3, 5K Lounge
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #86 on: August 27, 2023, 06:14:21 PM »
Tried email and username and no email with instructions was received.
Same for a friend.  :)
Only on DDF does 24/6 mean 24/5/half/half
Dow Jones Industrial Average Tops 40000 for the First Time

Offline AviationAtom

  • DansDeals Copper Elite
  • *
  • Join Date: Dec 2013
  • Posts: 6
  • Total likes: 9
  • DansDeals.com Hat Tips 0
    • View Profile
Re: DDF Account Hackers Buying/Selling Gift Cards From Existing Accounts
« Reply #87 on: August 27, 2023, 06:23:52 PM »
How do they hack? Data breach or vulnerability?

I work in cybersecurity, so I can tell you how it often goes:
Hackers find a site that could be of some value to them, they then use a list of passwords from database breaches on other sites that have been cracked. They feed in email and password pairs with their automated bruteforcing script until the script hits. Once they find a hit they login with it and utilize that account in whatever form or fashion they can.

The best way to defeat this is always going to first and foremost be enabling two factor authentication, followed by a secure AND unique password (never used elsewhere), random security questions and answers, and lastly a unique email address per site.

A good unique password always hinges on length. Longer is better. It needn't be crazy, but it's helpful to incorporate uppers, lowers, numbers, and special characters. Password managers can often do this for you automatically, as well as keeping track of each password for each site. LastPass was mentioned as one, but I would highly recommend against it. 1Password or Bitwarden are probably two of the better and more recommended ones. A good password might look like this: garden6CAT-tortila. Easy to remember, but not super easy to crack.

1Password can also store your multifactor "Google Authenticator" tokens, and keep track of random security questions and answers.

As for unique email addresses the functionality is built into Gmail and some other providers. If your Gmail address is bob123@gmail.com then you can make your DansDeals email bob123+dansdeals@gmail.com and it will still reach the inbox of bob123@gmail.com.

If you want to check if your email and/or password has ever been in a breach then check haveibeenpwned.com to see. More than likely it has. When testing password the guy who designed the site (Troy Hunt) made it so only part of your password is hashed and is tested against the breached password database.

Offline biobook

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Apr 2020
  • Posts: 1409
  • Total likes: 1711
  • DansDeals.com Hat Tips 0
    • View Profile
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #88 on: August 27, 2023, 06:24:13 PM »
Tried email and username and no email with instructions was received.
Same for a friend.  :)
Did you click on Forgot your password

Offline CountValentine

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Mar 2013
  • Posts: 17342
  • Total likes: 7841
  • DansDeals.com Hat Tips -1
  • Gender: Female
    • View Profile
  • Location: Poland - Exiled
  • Programs: DAOTYA, DDF Level 3, 5K Lounge
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #89 on: August 27, 2023, 06:30:38 PM »
Did you click on Forgot your password
Yes for both.
Only on DDF does 24/6 mean 24/5/half/half
Dow Jones Industrial Average Tops 40000 for the First Time

Offline CountValentine

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Mar 2013
  • Posts: 17342
  • Total likes: 7841
  • DansDeals.com Hat Tips -1
  • Gender: Female
    • View Profile
  • Location: Poland - Exiled
  • Programs: DAOTYA, DDF Level 3, 5K Lounge
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #90 on: August 27, 2023, 06:31:49 PM »
Wouldn't a simple fix be blocking login on the third failed attempt? @AviationAtom
Only on DDF does 24/6 mean 24/5/half/half
Dow Jones Industrial Average Tops 40000 for the First Time

Offline AviationAtom

  • DansDeals Copper Elite
  • *
  • Join Date: Dec 2013
  • Posts: 6
  • Total likes: 9
  • DansDeals.com Hat Tips 0
    • View Profile
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #91 on: August 27, 2023, 06:36:20 PM »
Wouldn't a simple fix be blocking login on the third failed attempt? @AviationAtom

You're always trying to balance security and convenience/usability. Yes, you could block too many attempts from a single IP, but the hackers test for this. They have armies of available IP addresses from compromised hosts and can easily rotate in-between them all. You don't want to accidentally block legitimate users by saying they can't login for a long while if they accidentally have their cap locks on, or enter the wrong password a few times before recalling their correct one. It's frustrating trying to find a balance.

Offline CountValentine

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Mar 2013
  • Posts: 17342
  • Total likes: 7841
  • DansDeals.com Hat Tips -1
  • Gender: Female
    • View Profile
  • Location: Poland - Exiled
  • Programs: DAOTYA, DDF Level 3, 5K Lounge
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #92 on: August 27, 2023, 06:41:18 PM »
You're always trying to balance security and convenience/usability. Yes, you could block too many attempts from a single IP, but the hackers test for this. They have armies of available IP addresses from compromised hosts and can easily rotate in-between them all. You don't want to accidentally block legitimate users by saying they can't login for a long while if they accidentally have their cap locks on, or enter the wrong password a few times before recalling their correct one. It's frustrating trying to find a balance.
So make it ten tries as brute force will take many more tries, no?
Only on DDF does 24/6 mean 24/5/half/half
Dow Jones Industrial Average Tops 40000 for the First Time

Offline AviationAtom

  • DansDeals Copper Elite
  • *
  • Join Date: Dec 2013
  • Posts: 6
  • Total likes: 9
  • DansDeals.com Hat Tips 0
    • View Profile
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #93 on: August 27, 2023, 07:04:54 PM »
So make it ten tries as brute force will take many more tries, no?

It generally comes down to them trying each email address only once and having a seemingly infinite amount of IP addresses to try each new email address with. It becomes hard to attach all those unique login attempts to a single "user." You could lockdown overall logins if logins exceed a total threshold, but then you will lock out legitimate users again.

Really the best thing to do is get users to use strong and unique passwords per site. If they're old and can't figure out password managers then they should go back to the trust old password book.

AI is getting better at being able to recognize strange login patterns, but there is still a big disparity in who such technology is accessible to right now. One day it will likely be baked into most web applications though.

Offline Alexsei

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Sep 2011
  • Posts: 5963
  • Total likes: 1520
  • DansDeals.com Hat Tips 5
    • View Profile
    • Travel & Kivrei Zadikim
  • Location: Truckistan
  • Programs: COVID-23
Re: DDF Account Hackers Buying/Selling Gift Cards From Existing Accounts
« Reply #94 on: August 27, 2023, 07:08:34 PM »
I work in cybersecurity, so I can tell you how it often goes:
Hackers find a site that could be of some value to them, they then use a list of passwords from database breaches on other sites that have been cracked. They feed in email and password pairs with their automated bruteforcing script until the script hits. Once they find a hit they login with it and utilize that account in whatever form or fashion they can.

The best way to defeat this is always going to first and foremost be enabling two factor authentication, followed by a secure AND unique password (never used elsewhere), random security questions and answers, and lastly a unique email address per site.

A good unique password always hinges on length. Longer is better. It needn't be crazy, but it's helpful to incorporate uppers, lowers, numbers, and special characters. Password managers can often do this for you automatically, as well as keeping track of each password for each site. LastPass was mentioned as one, but I would highly recommend against it. 1Password or Bitwarden are probably two of the better and more recommended ones. A good password might look like this: garden6CAT-tortila. Easy to remember, but not super easy to crack.

1Password can also store your multifactor "Google Authenticator" tokens, and keep track of random security questions and answers.

As for unique email addresses the functionality is built into Gmail and some other providers. If your Gmail address is bob123@gmail.com then you can make your DansDeals email bob123+dansdeals@gmail.com and it will still reach the inbox of bob123@gmail.com.

If you want to check if your email and/or password has ever been in a breach then check haveibeenpwned.com to see. More than likely it has. When testing password the guy who designed the site (Troy Hunt) made it so only part of your password is hashed and is tested against the breached password database.

Wouldn't it be a good idea to put the entire site under cloudflare firewall? Free and easy.
« Last Edit: August 27, 2023, 07:13:50 PM by Alexsei »
Jews ≠ Zionists
Palestinians ≠ Hamas
Satmar ≠ SatmarHQ

Offline CountValentine

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Mar 2013
  • Posts: 17342
  • Total likes: 7841
  • DansDeals.com Hat Tips -1
  • Gender: Female
    • View Profile
  • Location: Poland - Exiled
  • Programs: DAOTYA, DDF Level 3, 5K Lounge
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #95 on: August 27, 2023, 07:10:42 PM »
I should clarify. By locking them out I mean they would then have to reset their password. Not really a big deal. I have a CU that constantly locks me out.
Only on DDF does 24/6 mean 24/5/half/half
Dow Jones Industrial Average Tops 40000 for the First Time

Offline Yo ssi

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Aug 2019
  • Posts: 6975
  • Total likes: 2745
  • DansDeals.com Hat Tips 60
  • Gender: Male
    • View Profile
_    ,
' )  /
 /  / __   _   _   o
(__/_(_)  /_)_/_)_<_
 //
(/

Offline shlomoandtam

  • Dansdeals Gold Elite
  • ***
  • Join Date: Mar 2022
  • Posts: 149
  • Total likes: 139
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: lakewood
  • Programs: SNAP, WIC, Jersey Care, HUD. ;)
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #97 on: August 27, 2023, 08:43:10 PM »
The other concerning element of this attack is that it's an indication DDF is on the radar of scammers. It's going to make doing business/trades with newer members riskier IMO. (And the honesty / general lack of scams is one of the nicer elements of DDF).
very good point

Offline Alexsei

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Sep 2011
  • Posts: 5963
  • Total likes: 1520
  • DansDeals.com Hat Tips 5
    • View Profile
    • Travel & Kivrei Zadikim
  • Location: Truckistan
  • Programs: COVID-23
Jews ≠ Zionists
Palestinians ≠ Hamas
Satmar ≠ SatmarHQ

Offline S209

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2016
  • Posts: 7559
  • Total likes: 3985
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
    • Gowns By Shevy
  • Location: Lakewood
  • Programs: Marriott Gold, Star Alliance Gold, Hyatt Explorist, Hertz PC, National EE, Rock Royalty Wild Card, Wyndham Diamond, MLife Gold, Caesars Diamond, Hilton Diamond, Uber VIP, IHG Platinum Elite, ANA Platinum, DDF Lifetime Prez Platinum Elite, AmEx Platinum
Re: CHANGE YOUR PASSWORD! DDF Account Hackers Buying/Selling Gift Cards!
« Reply #99 on: August 27, 2023, 09:51:31 PM »
AI is getting better at being able to recognize strange login patterns
And with nearly identical precision, AI is learning how to beat that algorithm.
Quote from: YitzyS
Quotes in a signature is annoying, as it comes across as an independent post.