Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 19th, 2006, 10:35 GMT · By

Phishing on PayPal

SHARE:

Adjust text size:


PayPal officials have announced the release of a permanent fix meant to prevent future phishing attempts after its users were the target of a successful attack. A cross-site scripting
vulnerability in the PayPal site allowed a phishing scheme that harvested credit card information and other personal data belonging to the users of the online payment portal PayPal.

Users were directed to a trap site in South Korea that had a real PayPal URL, were they were informed that their accounts with the service had been compromised, and were redirected to a phishing site that asked for PayPal login information and for the data r5egarding the credit cards used for online transactions.

Experts from the online monitoring an security firm Netcraft have revealed that the phishing site was not only hosted on a real site of the online payment service but was also transmitting a valid 256-bit SSL certificate to confirm that it belonged to PayPal.

"As soon as we became aware of this scheme, we changed some of the code on the PayPal Web site. So this scheme, or any scheme like it, can no longer be effective," said Amanda Pires, a PayPal spokeswoman.

TELL US WHAT YOU THINK:

1,321 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


eBay Turns Ten. Happy Birthday!

Yahoo! and eBay Alliance Puts Microsoft in a Tough Position

McAfee's Falcon Now Has Four Targets

Internet Explorer 7+, the IE Version Included in Vista

Gbuy - The Alternative to PayPal Coming Very Soon

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM