Need Help!!!! I think I was Almost DNS Scammed while shoping at newegg?

Shaker8

Member
Jan 6, 2006
57
0
0
Hey guys,

I posted this in the DNS in the Wild Thread, but I am really worried so asking for help here

I was just searching these forums for help on gaming headphones and found a link in a thread for a new egg set of Sen HD555....they were out of stock. So I clicked on the Auto Notify.

Thats when I got this warning (had to type it out since can't get it to copy paste)

You Have attempted to establish a connection with "cm.newegg.com". However, the security certificate presented belongs to "a248.e.akami.net". It is possible though unlikely that someone may be trying to intercept you communication with this website.

If you suspect the certificate shown does not belong to "cm.newegg.com", Please cancel the connection and notify the site administrator.

I of course just hit cancel

Both link in the DNS in the wild thread say I am safe, but this happened and is still hapening to me on newegg even after closing out Firefox. I am using firefox so lucky enough it warned me.

I have two questions.

1) since I hit cancel do I have anything to worry about? i.e. what was it sending to newegg
2) how do I make myself safe now? since even though those site say I am....obviously I am not?

Thanks in advance for your help.

update merged in from other thread
Hey Guys,


Last night I had a little scare while shopping on newegg. You can read about here in this thread

Thread from last night

Amazingly despite the time that morning alot of Anandtech people helped me out and belayed my fears.....and I listened, I thank them for there help but it appears they were wrong.

This afternoon I returned home form work to find the shopping cart that I had selected from newegg was empty, also the headphones in the thread above were not on auto notify as I had set them to be.

My suspicions aroused I called Newegg.

I talked to a representative called Ileana who checked up on my concern about the certificate from "a248.e.akami.net" with her supervisor and the IT department.

After a very long time waiting I was told that Newegg does not use Akima and that the only certificate valid was from VERISIGN!!!!!!

After being told this I immediately checked to see if I had any orders placed using my credit card. Luckily for me it has been awhile since my last bill and the credit card on file with newegg is not valid anymore. Since my cart was empty I only assume that they had unsuccessfully tried to make a purchase since Ileana couldn't tell me.

I have changed my password for my newegg account and will definitely check the certificate in the future.

Ileana assured me that the IT department would be looking into the other site and that Newegg might put a warning up on there homepage.

Beware guys whether this was DNS Poisoning or a bad link in the forums I don't know(not going to hit that headphone link in the thread referenced in my first thread about this to check it) According to the link in the DNS in the wild thread I am safe from DNS Posioning but this happened anyways so beware!!!

This was what I was told buy the newegg rep if I am in any way wrong then I apologize but she told me not to trust any Akima certificate only ones that said Newegg and were from VERISIGN!!!!

Hope this helps you all


I've merged the two threads together. Knock it off with the name calling. - Anandtech Moderator DrPizza
 

Shaker8

Member
Jan 6, 2006
57
0
0
Originally posted by: keeleysam
Akamai is legit, it's probably good.

Not that I doubt you but how do you know that?

My last post in the DNS in the wild thread I typed the certificate if that helps you figure if it is legit
 

apac

Diamond Member
Apr 12, 2003
6,212
0
71
Originally posted by: aphex
Originally posted by: Shaker8
Originally posted by: keeleysam
Akamai is legit, it's probably good.

Not that I doubt you but how do you know that?

http://www.akamai.com/

Also, google "akamai"
Results 1 - 10 of about 8,140,000 for akamai. (0.03 seconds)

Out of curiousity, why would Newegg be using akamai as a signing authority? I was under the impression that Verisign was the only "trusted" entity out there.
 

EightySix Four

Diamond Member
Jul 17, 2004
5,121
49
91
yeah, akamai hosts content for TONS of websites. Those sites redirect you to a Akamai server whenever theirs are overloaded.
 

OdiN

Banned
Mar 1, 2000
16,431
3
0
Originally posted by: Shaker8
Originally posted by: keeleysam
Akamai is legit, it's probably good.

Not that I doubt you but how do you know that?

My last post in the DNS in the wild thread I typed the certificate if that helps you figure if it is legit

Akamai handles web media/application distribution for lots of companies - basically they pipe stuff in from places close to you which makes your web experience faster. Apple used them for quicktime movie trailers - might still.
 

Shaker8

Member
Jan 6, 2006
57
0
0
Originally posted by: crazySOB297
yeah, akamai hosts content for TONS of websites. Those sites redirect you to a Akamai server whenever theirs are overloaded.

So this is normal then? Whew sorry to get everyone worked up but still its a little scary when you read that DNS in the wild thread

After auto-notify for the headphones the next thing i was going to do was purchase my new build at 1800 dollars worth of stuff.

I hope you can see why I was a little paranoid

Sorry for the false alarm guys
 

KingGheedora

Diamond Member
Jun 24, 2006
3,248
1
81
Originally posted by: crazySOB297
yeah, akamai hosts content for TONS of websites. Those sites redirect you to a Akamai server whenever theirs are overloaded.

Akamai caches its clients' content. Peoples' requests either go to Akamai, if that content is Akamai cached, or to the original server hsoting the content. I don't think it is served by Akamai based on load, it's served by Akamai to prevent servers from overloading.
 

apac

Diamond Member
Apr 12, 2003
6,212
0
71
Originally posted by: Shaker8
Should I contact newegg to see if they do actually use AKamai?

Whatever helps you sleep at night . Odds are you'll figure it out on your own before they email you back.
 

Cdubneeddeal

Diamond Member
Oct 22, 2003
7,476
3
81
Originally posted by: Shaker8
Should I contact newegg to see if they do actually use AKamai?

I wouldn't worry about it. After I did the auto notify I could see the data being routed through Akamai.
 

Shaker8

Member
Jan 6, 2006
57
0
0
Well I will trust you guys more than somebody at newegg who is a customer service rep and has no idea what I am talking about. Thanks guys once again sorry to bother you all.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |