📜 ⬆️ ⬇️

How to take my money from the Yandex wallet. Part 1

Just yesterday, my Yandex.Money account removed all the money that was there, namely, 9500 pv. Very annoying, very sad, I want to cry. How to take away my passwords - the question for me is still interesting - I use antivirus software, I only store passwords in encrypted form. I did not have a strong authorization (I confess, I confess, I am guilty).

The money went through 3 payments in WebMoney through Robokassa. A call to Robokassa did not give anything - they said that the money was transferred to the account (which one they did not give out) and could not help them. They told to contact Yandex.Money and Webmoney technical support. At their request, they will provide all the information if required. Applied to the technical support service of both companies. Yandex responded, but how! .. About this below.


')
The first thing that caught my eye was that these 3 translations were missing on the Yandex.Money main page:
image

I go into the history of transfers and see when the money went and to what extent:
image

So-with. Interesting. I go to the history of entering the wallet and see the following picture:
image

It killed me instantly. First, the hysterics of losing money, then hysteria about how this could happen. There were 3 options:
a) someone from Yandex employees urgently needed Web money
b) Yandex was not bad divorced by circumventing the check for an IP address ...
c) UFO took my money

Tech support for Yandex was asked about the IP address:
I: Please read carefully. The history of calls includes the ip-address 127.0.0.1 - this is the internal address within your company. I attach a screenshot to the letter and ask you to explain how you can access Yandex.Money from this ip address and make a transfer. Thanks in advance for your reply.
Yandex: The IP address 127.0.0.1 is the own address of your computer.

Well, all the guys are great! I did not expect such an answer from them!

Is it difficult to check for the IP address from which the wallet is entered and exclude the service IP addresses? Why have not yet entered the 2nd authorization with a one-time password, which comes to the mobile phone number every time you try to log into your account?!

And what do you think about this,% username%?

PS My first post on Habré, so please do not pin much ...

PPS I still do not blame anyone!

UPD. Transferred to Yandex blog

UPD 2. Response from Yandex about the IP-address 127.0.0.1 in the history of entering the wallet:
Please pay attention to the information indicated on our website:
money.yandex.ru/doc.xml?id=522713#qu22
information in the “History of visits” section may be incomplete.

In this case, the intruder’s ip call was incorrectly displayed in your call history. When logging in via an anonymous proxy server, the address shown in the haul history is taken from the Forwarded-for header. The script that determines the incoming ip address was redirected to itself and therefore determined its address. However, we keep information about all IP addresses from which payments are made (of course, in the case of a proxy, this will be the proxy address). Upon request from the police, we will provide this information. The proxy server itself also stores information about the addresses from which calls were made to it, and the police can also receive this information.

In our very first letter, we recommended that you contact the police and gave you quite detailed instructions on how to do this. Please use this instruction. Upon request, law enforcement agencies, we will report absolutely all the information that is at our disposal.


UPD 3. Part 2.1 of this story is available for reading here: How to take my money from the Yandex wallet. Part 2.1. Running

Source: https://habr.com/ru/post/74263/


All Articles