MAC address and stealth ebay/paypal

http://www.codeproject.com/Questions/352061/How-to-get-mac-address-of-pc-via-cplusplus-functio

[h=1](SOLVED) How to get mac address of pc via c++ function?[/h]
 
and so far none of the things you suggested would work on linux...
 
Here's proof:
http://www.mkyong.com/java/how-to-get-mac-address-in-java/

It's a simple Java script. If Java script will do it, anything will do it. Any kind of custom code you can't possibly imagine will deliver your MAC address anytime anyone that has the ability to ask for it wants it. It's like a $3.00 whore, only they don't have to pay the $3.00. It's free. It's available. It's right there, just waiting for the right person to come along and ask for it. Easy. Simple. Cheap. Free, even. Free MAC Address, just there for the asking. It would be less obvious if you wrote your MAC Address in 6" letters and wore them on your forehead, like a sign. You could even decorate that MAC Address sign on your forehead with Christmas Tree lights, and even then it would be less obvious than the availability of your MAC address to anyone that wants it online. Just there, waiting to hand it over to anyone that asks. Like a free whore, as I said earlier. Your computer is a free whore, and hands out your MAC address to just anyone.

Have you all got this yet, or do I need to continue?



Pay attention, kiddies. This is the only person in the whole thread that knows anything. Every single other person is wrong in some way or another. I deleted most of my post because it wasn't "friendly" enough. Just too much wrongness in this thread for me to handle; like a loud discussion on the short bus, there are too many 'tards and not enough time.


So you tell me they can get my MAC address any time they want to , so why don't they link my old paypal and ebay accounts to my new stealth? I do not cover or change my MAC address at all.
Also another question is if they can actually track you down from the MAC address to our real residence , i mean like to find out this computer number and by contacting the manufacturer to retrieve my real personal information.
 
haki_master, your MAC address is actually the serial number of your networking card, the thing that makes internet possible.

When looking at the MAC you can determine the vendor and for the really motivated you can be traced that way. This is impossible without the cooperation of the vendor btw. But in theory, you can be traced.

There could be any number of reason why you didn't run into any problems, one reason I can think of is that it's so incredibly easy to spoof a MAC it turns useless as a way to identify someone in court.
Also, getting the MAC via a browser seems to only work in explorer without any notifications so why bother when there are so many other ways to identify a person?
 
Here's proof:
http://www.mkyong.com/java/how-to-get-mac-address-in-java/

It's a simple Java script. If Java script will do it, anything will do it.

That's java, not javascript. They are two completely different languages, although they do share some syntax. Getting the MAC address using java requires java execution to be enabled in the browser. There's no way that I know of to get the MAC address with javascript.

You can also get the MAC address using ActiveX and some versions of IE, so don't use IE for any sensitive activities.
 
So you tell me they can get my MAC address any time they want to , so why don't they link my old paypal and ebay accounts to my new stealth? I do not cover or change my MAC address at all. Also another question is if they can actually track you down from the MAC address to our real residence , i mean like to find out this computer number and by contacting the manufacturer to retrieve my real personal information.
Your ISP gateway will drop your mac address and replace it with the mac address of next router. In case they have some real evidence against you they will just use your ip to track you down. If they manage to get court order your ISP will reveal not only your mac address but also your real name and home address. If you are doing something illegal just use some public computer in library or somewhere. Also it's very clear that you should not allow your browser to run any activex or java applets that you do not trust.
 
Your ISP gateway will drop your mac address and replace it with the mac address of next router. In case they have some real evidence against you they will just use your ip to track you down. If they manage to get court order your ISP will reveal not only your mac address but also your real name and home address. If you are doing something illegal just use some public computer in library or somewhere. Also it's very clear that you should not allow your browser to run any activex or java applets that you do not trust.

Who said im doing something illegal , no.I was just wondering if they could track you down or link by the MAC address , and there are some opinions that differ in this thread but overall i get the point.Thanks for your replies.
 
It's not something you could implement through a web page.

Malware & custom made software can deliver full control of an infected/target computer to another computer via the browser. Full control includes delivering the MAC Address. Therefore the MAC Address is deliverable, it's just a question of how.

They find new exploits every day. People install untested software every day. Sony installed a rootkit. The government has the best computer talent in the world. They found malware active in the BIOS that runs the battery on a laptop.

It's interesting you attempt to use social pressure to get me to back down on what should be a technical discussion. I think you've invested too much of your identity as being some kind of authority figure to a group of people that know very little and/or are incapable of critical thinking. "Short Bus Leader" lol. It's a very small pond you live in, and even funnier, you aren't even a very big fish.
 
blah blah blah

OK first off this thread is about Paypal and Ebay, and neither of them (nor any other legitimate company) are going to be dropping exploits.

Second, web based malware is virtually non-existent on *nix because of the number of disparate distros out there. The differing layouts of the filesystem and utilities on the different distros makes it hard to write *nix malware. In order to get a *nix user to install malware you need to get them to both run your install and, in the case of getting the MAC address using ifconfig, you also need them to type in the root password because you need root access to use that command. Most *nix users are fairly clued up and unlikely to do either. While it's not completely inconceivable that you could get a MAC address somehow on *nix by using a web based rootkit, as far as this discussion is concerned it's so absurdly unlikely that it's not worth discussing. If someone does root your *nix box you have got bigger problems than them having your MAC address!

Thirdly, you have quite clearly put your foot in your mouth by adopting a haughty tone and ranting about other people not contributing anything of value to the thread, whilst posting misinformation and spewing a bunch of links that you obviously haven't even looked at. You didn't even know the difference between java and javascript FFS! Sorry if it hurts your ego, but that makes you technically unqualified to contribute to the discussion. You're just confusing the discourse and generating noise.
 
I also meant to add to this thread that instead of worrying about MAC addresses, it would probably pay for the OP to pay more attention to browser fingerprinting which is a much more likely way to be uniquely identified on the web.
 
I also meant to add to this thread that instead of worrying about MAC addresses, it would probably pay for the OP to pay more attention to browser fingerprinting which is a much more likely way to be uniquely identified on the web.

Thanks Autumn for your contribution on this thread about ebay/paypal stealth and mac address.Regarding B._Friendly i would suggest him to go play in another playground as the topic here is about whether paypal/ebay can track you down to your real identity through mac address and i think the valuable posts already made by several members here clarified that issue already.
As for the browser fingerprinting , what is that site exactly , they collect data and tell you based on how unique is your browser setup how easy it is for you get tracked to your real identity , i mean how exactly they can track you down to your real identity when you are stealth [dont wanna mention what exactly this means as i assume you understand] , from what kind of source ?
 
That site just demonstrates how easy it is to build a fingerprint of a person's browser using information that is easily available from the browser using the useragent, javascript and flash. Unlike trying to get the MAC address (which is technically possible but unlikely), all that info is right there for the taking in any modern browser, and unlike dropping exploits to get the MAC address, none of it is illegal. The more customizations you have to your browser and OS (e.g. non-default fonts installed, a non standard screen resolution, an old particular old Flash version etc.) then the easier it is to uniquely identify you.

When you look at your fingerprint in Panopticlick, you will probably see that your fingerprint matches something like 1 in 8 million unique users on the internet or whatever. Paypal has a much lower member base than the total population of the internet. When you signup, they could theoretically fingerprint you and compare that to their database of existing bans. If, say, out of their millions of users they only have 10 other existing users with fingerprints that match yours, and 5 of them are banned, then they know to keep an eye on your account because it has a higher likelihood of bad behaviour.

Google already has a number of patents for stuff like identifying unique users behind the same IP address, using these kinds of techniques. You can be sure that a financial company like Paypal that is militant about fraud will be doing something similar.

The solution if you feel it is necessary is to use VMWare to install default versions of multiple versions of Windows and use those OSs to signup and do your stuff. You have to keep the settings as close to default as possible so your fingerprint matches the largest number of other potential fingerprints. Some people already do this for running multiple Adwords accounts.
 
Please B. Friendly, stop posting.


Related to a problem in IE using ActiveX. The user also has to explicitly allow it.


Same as above.


Requires .exe download and is not web based.


Requires .exe download and is not web based

Here's proof:
http://www.mkyong.com/java/how-to-get-mac-address-in-java/

It's a simple Java script. If Java script will do it, anything will do it. Any kind of custom code you can't possibly imagine will deliver your MAC address anytime anyone that has the ability to ask for it wants it. It's like a $3.00 whore, only they don't have to pay the $3.00. It's free. It's available. It's right there, just waiting for the right person to come along and ask for it. Easy. Simple. Cheap. Free, even. Free MAC Address, just there for the asking. It would be less obvious if you wrote your MAC Address in 6" letters and wore them on your forehead, like a sign. You could even decorate that MAC Address sign on your forehead with Christmas Tree lights, and even then it would be less obvious than the availability of your MAC address to anyone that wants it online. Just there, waiting to hand it over to anyone that asks. Like a free whore, as I said earlier. Your computer is a free whore, and hands out your MAC address to just anyone.

Have you all got this yet, or do I need to continue?



Pay attention, kiddies. This is the only person in the whole thread that knows anything. Every single other person is wrong in some way or another. I deleted most of my post because it wasn't "friendly" enough. Just too much wrongness in this thread for me to handle; like a loud discussion on the short bus, there are too many 'tards and not enough time.

Java is not javascript. If you're calling other people tards you should atleast know the difference. Tard.




Not web based.

--

Congrats on knowing how to google but not comprehending what is being talked about and being cocky about it. Neg repped as well.
 
Here's yet another example of how readily available MAC Addresses are. Google can sniff them out of your wireless network while driving down the road:

http://www.theregister.co.uk/2010/04/22/google_streetview_logs_wlans/

Google's roving Street View spycam may blur your face, but it's got your number. The Street View service is under fire in Germany for scanning private WLAN networks, and recording users' unique Mac (Media Access Control) addresses, as the car trundles along.

And also, other BHW members have discussed this topic.

http://www.blackhatworld.com/blackhat-seo/blackhat-lounge/197659-does-google-track-your-mac-address-somehow.html

Several members there believe that Google Toolbar, Google Earth and Google Chrome will deliver your MAC Address.
 
I would actually be more worried about flash cookies. What I recommend is using a live cd/ USB stick of the Linux variety, like Fedora. It doesn't come with Adobe flash or anything Adobe installed. Boot with that, install Firefox along with Ghostery, adblock plus, and noscript and you should be good to go. If you want to get rid of anything that you think might be there, simply re-boot the computer.
 
Last edited:
OK first off this thread is about Paypal and Ebay, and neither of them (nor any other legitimate company) are going to be dropping exploits.

I already addressed this. Sony installed a rootkit. You've heard about this, yes? I don't have to understand the difference between java and java script to know that some people attempt to use a small bit of technical knowledge for a "Halo Effect" and attempt to have authority on subjects they are not qualified to address. I could pick apart the flaws in your reasoning, but they are obvious to anyone that has the ability to think critically and I'm only talking to them and not unqualified posers and people that want to be spoon-fed.

And it's those flaws that case me to doubt whether you are qualified to have an opinion, even on the narrowly defined topic of eBay and PayPal only, and even with all the exceptions that you expect everyone to ignore (ActiveX, Java installed) based only because "you say so". Sorry pal, but it ain't working for me. I've been around technical forums for years and I know what someone that pretends to know more than they do sound like, and they sound just like you. Which, wouldn't be that big of a deal except your influence in this thread might wind up 1st getting someone into some trouble and 2nd would then have new transmitters of bad information creating more ignorance.


And, there is no reason to limit the scope of this thread to just eBay and PayPal. There are a lot of people that take false comfort in their supposed anonymity, and it's based to a great extent on the false assurances of people that assume that a dab of knowledge qualifies them to make sweeping statements about larger areas. All this stuff earlier in the thread about how Linux won't deliver the MAC Address, and this is safe and it can't be done that way and it turns out that they all do and they all will.

The larger issues have to do with the level of anonymity people have online for any purpose, whether it be eBay, PayPal or whatever, and the means by which people can be identified. What the subject is NOT is how smart you are, how much you know, how much authority your opinions have and how little effort you are required to put into substantiating them.
 
BFriendly, you're going way off topic. If you read the OP again, he's specifically talking about Paypal and Ebay. I am not going to respond to your personal attacks because I don't know who you are and don't really care, but if you have specific issues with anything I have posted then I would be willing to respond with counter arguments on a point by point basis as time allows.

However in general you're showing a lack of understanding about how browsers and networking works, both at the http level and the lower levels of OSI model. Modern browsers and their javascript implentations are heavily sandboxed to specifically disallow direct interaction with system utilities and thus with hardware. The attack surface of a web page is much lower than if an attacker either has access to your router or to your computer (either physically or by getting you to install an exe) - they are completely different attack vectors.

Yes it is possible to get someone's MAC address if you drop an exploit on a web page that silently escalates to administrator access, or you have direct physical or network access to their PC or router, or you can get them to install an exe - no one is denying this. However none of those things are relevant to Ebay and Paypal, or any case where you are not dealing with an illegally malicious web page. In general :

* Don't use IE / ActiveX
* Don't use Java
* Disable signed Javascripts (disabled by default in Firefox)
* Don't install any exes from dubious sources (I would definitely count Google as a dubious source if you are doing Adwords, multiple Adsense accounts etc.) or Adobe AIR applications (you can't get the MAC address using the FlashPlayer browser plugin, but Flash cookies are still a privacy concern). Edit: It looks like I may be wrong about Flash and it appears to be possible to get a MAC address using at least some proprietary Actionscript extensions. So enable Flash at your own risk.

No legitimate web company in 2012 that deals with people's financial information is going to be dropping illegal rootkits via their web site. Not only would it quickly be found out with a huge PR backlash, but it's totally illegal. The Sony rootkit (which happened 5+ years ago from memory) is in fact a good example of why companies won't do this: because of the PR backlash that it caused, and the fact that Sony was both sued by justice departments of several states and was also the subject of several class action lawsuits, incurring both big legal costs and the wrath of their shareholders. With browser fingerprinting, Flash cookies etc. web companies already have plenty of simple and legal methods for uniquely identifying users without resorting to illegal means which will ultimately lose them market share and cost them money.

Zapdos has already done a good job of refuting your previous Google copypastas, so unless you actually have some useful technical information to add to the thread please refrain from personal attacks.
 
Last edited:
Back
Top