MAC address and stealth ebay/paypal

All I know is I have worked with a site that had 'BlueCava' installed and what it does is get a machine fingerprint instead of just a browser fingerprint. When their javascript runs I see my MAC address correctly displayed in a flash file that is hidden. There are ways that they can get around everything and it's all legal, even if it's a grey area.

Best way to get around this is to use a Virtual Machine and a different IP for separate accounts.

Download Virtual Box and use a windows iso that you can get from PirateBay.
 
All I know is I have worked with a site that had 'BlueCava' installed and what it does is get a machine fingerprint instead of just a browser fingerprint. When their javascript runs I see my MAC address correctly displayed in a flash file that is hidden. There are ways that they can get around everything and it's all legal, even if it's a grey area.

That's pretty interesting. You mean the Flash file is hidden on the page by the javascript? I just had a brief look at some of the Bluecava javascript and from what I can tell it looks like they use a combo of ActiveX and Flash to get the MAC address, and they use Flash cookies for local storage.

The takeaway is that browser or device fingerprinting is much more of a threat than just a leaky MAC address. I stumbled upon this interesting patent too, although implementing it would be a lot harder than just using VMs...
 
That's pretty interesting. You mean the Flash file is hidden on the page by the javascript? I just had a brief look at some of the Bluecava javascript and from what I can tell it looks like they use a combo of ActiveX and Flash to get the MAC address, and they use Flash cookies for local storage.

The takeaway is that browser or device fingerprinting is much more of a threat than just a leaky MAC address. I stumbled upon this interesting patent too, although implementing it would be a lot harder than just using VMs...

Yeah sorry I didn't explain it well. The file itself isn't hidden but the MAC Address is in the one of the files in the Flash folders deep within some other code. And you're right on the money saying that this is more of a threat than just detecting your MAC address because they also store your information into a database supposedly for the use of targeting ads from the websites you have visited. But god knows what else they're doing with it, rumors are that they're teaming up with Facebook.
 
Dude, please stop talking, you're making a fool of yourself.

Zapdos has already done a good job of refuting your previous Google copypastas, so unless you actually have some useful technical information to add to the thread please refrain from personal attacks.

The "personal attacks" started here, and they were initiated by you. You conveniently fail to mention this, and many other things that are actually relevant to the thread, it's this intellectual weakness that I am aiming my comments at. You could apologize for this, and I might forgive you, but I still don't think you have the critical thinking ability to have an honest role in a technical discussion. You attempt to "win" discussions by using social pressure, and that makes you WEAK. If anyone should step back from this thread, it is you. You've initiated personal conflict, have attempted to narrowly define the topic so that your opinions look "right" and despite having been confronted with this several times, still insist on trying to use social pressure to "win" an argument. And, as it turns out, there's something you didn't know after all, which is that at least in one case, the MAC Address can be used in a composite score to create a "machine fingerprint". Turns out, I was right, you DON'T know everything there is to know, my role in this thread has been useful after all and in fact it is YOU that has been non-constructive and distracting.

And also, stop calling me "dude", you sound like a dumbass.

The takeaway is that browser or device fingerprinting is much more of a threat than just a leaky MAC address...

No, the "takeaway" is that if you weren't such an arrogant and obnoxious ass, I wouldn't have had to push so hard in keeping this thread going until someone that knew something interesting showed up and posted it. Now go to your room; I want you to sit there for a while and think about what you've done before you can come back.
 
Err my initial comment was a friendly warning that you were indeed making yourself look like an idiot by posting a whole bunch of irrelevant copypastas that you obviously didn't understand, and at the same time calling everyone else in the thread a retard. That's not social pressure, because like I said before, I don't know you, I don't know anyone who knows you, and I don't really care if you make a fool of yourself or not - but it irritates me when people muddy up a perfectly good thread with irrelevant nonsense. However a quick skim of your posts reveals that you spend a lot of time abusing other posters, like to regurgitate "truths" that people who do robust testing know actually aren't true, and thus probably don't push real volume.

There are a bunch of posts over on stackoverflow from one of the developers of BlueCava where he talks about how the MAC address is basically useless for device identification because it's easily changed, unreliable to obtain (because it requires vectors like ActiveX and Java which we have already discussed) and a large chunk of devices don't use it (e.g. devices on dial up and 3G connections).

The facts remain that: this is a thread specifically about Paypal, Ebay and perhaps web browser usage in general; and you are generally safe from MAC address discovery via the web if you avoid IE / ActiveX, Java and possibly Flash. Methods to avoid fingerprinting have already been enumerated by myself and other people in this thread, i.e. use VMs.

I fully admit that I may have been wrong about Flash, but from what my brief research today indicates, the MAC address is only accessible from Flashplayer if you are using Flash Lite (the mobile version of Flash) with some device-specific proprietary Actionscript extensions and a network interface that requires a MAC address (i.e. wifi). I am not a Flash programmer and I turn off Flash if I'm doing anything dodgy (as everyone should) so I'm not going to investigate it further.

No, the "takeaway" is that if you weren't such an arrogant and obnoxious ass, I wouldn't have had to push so hard in keeping this thread going until someone that knew something interesting showed up and posted it.

I'm not quite sure what you're dribbling about here, but if you are talking about fingerprinting (which I did, in fact, mention first, rather than your misguided dwelling on MAC addresses), browser fingerprinting and device fingerprinting are essentially the same thing, because they identify individual users based on installed plugins and fonts, browser headers, latencies in http responses etc. Device fingerprinting just takes it one step further and is designed to defeat the user from changing their browser to defeat the fingerprint. You could actually spend some time learning about this stuff instead of posting a whole bunch of crap, but I'm not going to hold my breath. Way to ruin a thread... Dude. ;)
 
Just pointing this out...
I don't have to understand the difference between java and java script[snip]
but I still don't think you have the critical thinking ability to have an honest role in a technical discussion.
You do?


Also
I've been around technical forums for years and I know what someone that pretends to know more than they do sound like, and they sound just like you.
If you've been around technical forums, then you would understand the fundamentals of browser security, programming/scripting and general security models.

What is your technical background? Are you a programmer and if so, what do you do? Are you a network engineer? OS engineer? Skiddie? Right now you're just looking like a poser who googles problems and tries to pass off the first 10 results as facts.

--

All I know is I have worked with a site that had 'BlueCava' installed and what it does is get a machine fingerprint instead of just a browser fingerprint.
Could you perhaps send me the link to the website that uses it? I'd like to see what their app does to fingerprint a machine and what is affected.
 
I have a question about MAC address and stealth ebay/paypal. Can paypal/ebay find you from mac address and how to cover it so they do not see it? I never did anything to cover mac address , i can find it through cmd command line , i use ebay and paypal regularly in stealth mode and i never been linked so far.

Help me out please, i got suspended from ebay and the following day i got suspended from paypal indefinitely which means i can no longer use ebay or paypal, i have pleaded with them several times but they wont listen to me. You said you use stealth ebay and paypal. Could you tell me how to do this please. I will really appreciate, i need to get back on ebay asap because every account i open gets detected and suspended.
Thanks
 
Help me out please, i got suspended from ebay and the following day i got suspended from paypal indefinitely which means i can no longer use ebay or paypal, i have pleaded with them several times but they wont listen to me. You said you use stealth ebay and paypal. Could you tell me how to do this please. I will really appreciate, i need to get back on ebay asap because every account i open gets detected and suspended.
Thanks

Do you know the basics to open and operate stealth accounts?
What exactly you did during the procedure that you opened new accounts and they linked you to your old one and suspended you?
I am sending you a pm maybe we can talk on skype
 
No, they CAN NOT read your MAC address
I have a question about MAC address and stealth ebay/paypal. Can paypal/ebay find you from mac address and how to cover it so they do not see it? I never did anything to cover mac address , i can find it through cmd command line , i use ebay and paypal regularly in stealth mode and i never been linked so far.
 
MAC Address spoofing is not required to run stealth accounts. I run multiple accounts for my business and never
had any issues whatsoever.

Cheers
Unclemike
 
I or my clients have never experienced any trouble with a MAC address.
 
Personally i have gone through dozens of ebay and amazon accounts learning that MAC address are tracked somehow. Once i figured out that all i had to do was replace my network card, i never had a problem since, obviously you still have to run cc cleaner and flash cookie cleaner, or something similar, but if you do both those steps it will work perfect. You can buy a card for $5. I bumped amazon out of $2000, then 2 days later i opened a new account, never had a problem since and that was 2 years ago.
 
Buddy! Instead of buying card you can use mac address changer.
 
You can delete flash cookies with Ccleaner and wipe them out. Just open up separate windows user accounts to divide them
for your selling purposes.
 
Personally i have gone through dozens of ebay and amazon accounts learning that MAC address are tracked somehow. Once i figured out that all i had to do was replace my network card, i never had a problem since, obviously you still have to run cc cleaner and flash cookie cleaner, or something similar, but if you do both those steps it will work perfect. You can buy a card for $5. I bumped amazon out of $2000, then 2 days later i opened a new account, never had a problem since and that was 2 years ago.

Read the thread, I explain why a MAC address is not available to websites. You just happened to do something else that avoided detection.
 
Back
Top