Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

October 6th, 2010, 17:26 GMT · By

PayPal and eBay XSSed Again

SHARE:

Adjust text size:

Cross-site scripting vulnerabilities found on eBay and PayPal
Enlarge picture
New cross-site scripting (XSS) vulnerabilities, that can be leveraged to create very credible phishing attacks, have been identified on PayPal and eBay.

The PayPal XSS weakness was discovered by a Romanian security enthusiast using the online handle of d3v1l, who disclosed it on his blog.

Cross-site scripting vulnerabilities are the result of poor input validation into Web forms and allow attackers to generate pages containing unauthorized code.

There are several types of XSS bugs. Persistent ones are the most dangerous and can be exploited to inject code into pages permanently.

Meanwhile, reflected XSS flaws can only be exploited by tricking users into opening specially crafted URLs, which causes the injection to reoccur on every page load.

The cross-site scripting weakness found by d3v1l is of the reflected type, but it can be used to create very credible phishing emails.

It's already common knowledge that PayPal is amongst the most phished brands on the Internet and that PayPal accounts are valuable for attackers, because they can be used for financial fraud directly.

Most phishing-aware users are thought to always check the destination of links received via email before clicking on them.

Unfortunately, this XSS vulnerability allows crafting paypal.com URLs, which redirect users to phishing pages hosted on external domains.

A lot of users are likely to miss that they are on a different website, because they already made sure the clicked URL pointed to paypal.com.

The eBay XSS weakness was discovered and reported to the XSSed Project by a user calling himself Side3ffects.

This flaw is even more dangerous than the PayPal one because it allows for persistent attacks. It is located in the form used by account owners to edit their profile information.

The bug allows attackers to create rogue profile pages, that can prompt alerts, load external sites inside iframes or perform other unauthorized actions.



2,090 hits · 1 comment
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


XSS Flaw Found on Secure American Express Site

Researchers Find Wormable CSRF and XSS Flaws on Facebook

Persistent XSS Bug Found on Amazon

Vodafone Websites Riddled with XSS and SQL Injection Vulnerabilities

Two XSS Vulnerabilities Found on PayPal Websites

READER COMMENTS:


Comment #1 by: Prefect on 07 Oct 2010, 03:43 UTC reply to this comment

"This flaw is even more dangerous than the PayPal..."

The worst I can do on ebay after taking over an account is submit fraudulent bids, and try to get people to send me things without paying.

The worst I can do on PayPal is send myself money from your account.

PayPal = worst.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM