{"id":14262,"date":"2019-01-08T07:17:10","date_gmt":"2019-01-08T15:17:10","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/01\/08\/news-8014\/"},"modified":"2019-01-08T07:17:10","modified_gmt":"2019-01-08T15:17:10","slug":"news-8014","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/01\/08\/news-8014\/","title":{"rendered":"Dirt-Cheap, Legit, Windows Software: Pick Two"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Tue, 08 Jan 2019 15:00:33 +0000<\/strong><\/p>\n<p>Buying heavily discounted, popular software from second-hand sources online has always been something of an iffy security proposition. But purchasing steeply discounted licenses for cloud-based subscription products like recent versions of <strong>Microsoft Office<\/strong>\u00a0can be an extremely risky transaction, mainly because you may not have full control over who has access to your data.<\/p>\n<p>Last week, KrebsOnSecurity heard from a reader who&#8217;d just purchased a copy of <strong>Microsoft Office 2016 Professional Plus<\/strong>\u00a0from a seller on <strong>eBay<\/strong> <em>for less than $4<\/em>. Let&#8217;s call this Red Flag #1, as a legitimately purchased license of Microsoft Office 2016 is still going to cost between $70 and $100.\u00a0Nevertheless, almost 350 other people had made the same purchase from this seller over the past year, according to eBay, and there appear to be many auctioneers just like this one.<\/p>\n<p><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/350ebay.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-46074\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/350ebay.jpg\" alt=\"\" width=\"597\" height=\"302\" \/><\/a><\/p>\n<p>After purchasing the item, the buyer said he received the following explanatory (exclamatory?) email from the seller &#8212; &#8220;<a href=\"https:\/\/feedback.ebay.com\/ws\/eBayISAPI.dll?ViewFeedback2&amp;userid=newhotsale68&amp;&amp;_trksid=p2047675.l2560&amp;rt=nc&amp;iid=292830187444&amp;sspagename=VIP%3Afeedback&amp;ftab=FeedbackAsSeller\" target=\"_blank\" rel=\"noopener\">Newhotsale68<\/a>&#8221; from Vietnam:<\/p>\n<blockquote>\n<p>Hello my friend!<br \/> Thank you for your purchase:)<\/p>\n<p>Very important! Office365 is a subscription product and does not require any KEY activation. Account + password = free lifetime use<\/p>\n<p>1. Log in with the original password and the official website will ask you to change your password!<\/p>\n<p>2. Be sure to remember the modified new password. Once you forget your password, you will lose Office365!<\/p>\n<p>3. After you change your password, log on to the official website to start downloading and installing Office365!<\/p>\n<p>Your account information:<\/p>\n<p>* USERMANE : (sent username)<br \/> Password Initial: (sent password)<br \/> Microsoft Office 365 access link:<\/p>\n<p>Http:\/\/portal.office.com\/<\/p>\n<\/blockquote>\n<p>Sounds legit, right?<\/p>\n<p>This merchant appears to be reselling access to existing Microsoft Office accounts, because in order to use this purchase the buyer must log in to Microsoft&#8217;s site <em>using someone else&#8217;s username and password!<\/em> Let&#8217;s call this Red Flag #2.<\/p>\n<p>More importantly, the buyer can&#8217;t change the email address associated with the license, which means whoever owns that address can likely still assume control over any licenses tied to it. We&#8217;ll call this Ginormous Red Flag #3.<span id=\"more-46036\"><\/span><\/p>\n<p>&#8220;The username that you use to register and activate Office is one that they provide to you in their email when you buy the license on eBay,&#8221;\u00a0wrote the reader who alerted me about this dodgy transaction. &#8220;You never use your own email account to register, you have to log in with theirs. Once you&#8217;re inside the account you can&#8217;t change the username to your email account because the admin locked it down.&#8221;<\/p>\n<p>Here&#8217;s what the profile looked like when the reader tried to change details tied to the license.<\/p>\n<p><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/tik207.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-46073 size-full\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/tik207.jpg\" alt=\"\" width=\"430\" height=\"619\" \/><\/a><\/p>\n<p>This version of Office prompts the user to sync all data and documents over to a 5TB Microsoft OneDrive account. What could go wrong?<\/p>\n<p>&#8220;You can sign out of their Microsoft account to break the connection to the OneDrive account,&#8221; the reader said. &#8220;By default it had me signed in and I bet most people installing this just click next and stay signed in.&#8221;<\/p>\n<p>That&#8217;s not all: The account was set up so that the administrator (seller) maintained control over specific apps on the Office installation, including <strong>OneNote<\/strong> and <strong>Class Notebook<\/strong>.<\/p>\n<p><a class=\"lightbox\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/apppermissions.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-46080\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/apppermissions.jpg\" alt=\"\" width=\"591\" height=\"244\" \/><\/a><\/p>\n<p>&#8220;I guess maybe the end result of all of this are the old adages, &#8216;you get what you pay for&#8217; and, &#8216;if it sounds too good to be true than it probably is,&#8217;&#8221; the reader said at the conclusion of his email.<\/p>\n<p>Couldn&#8217;t have said it better myself.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2019\/01\/dirt-cheap-legit-windows-software-pick-two\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2018\/12\/350ebay.jpg\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Tue, 08 Jan 2019 15:00:33 +0000<\/strong><\/p>\n<p>Buying heavily discounted, popular software from second-hand sources online has always been something of an iffy security proposition. But purchasing steeply discounted licenses for cloud-based subscription products like recent versions of Microsoft Office\u00a0can be an extremely risky transaction, mainly because you may not have full control over who has access to your data.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16740,12058,16888,20601,20602,17006],"class_list":["post-14262","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-a-little-sunshine","tag-ebay","tag-latest-warnings","tag-microsoft-office-2016-professional-plus","tag-newhotsale68","tag-web-fraud-2-0"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14262"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14262\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}