BleepingComputer.com: Paypal Security Flaw Allows Identity Theft

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Paypal Security Flaw Allows Identity Theft

#1 User is offline   no one 

  • Distinguished Member
  • PipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 843
  • Joined: 09-May 06
  • Gender:Male
  • Location:PCLinuxOS Land

Posted 16 June 2006 - 11:31 AM

Quote

A security flaw in the PayPal web site is being actively exploited by fraudsters to steal credit card numbers and other personal information belonging to PayPal users. The issue was reported to Netcraft today via our anti-phishing toolbar.

The scam works quite convincingly, by tricking users into accessing a URL hosted on the genuine PayPal web site. The URL uses SSL to encrypt information transmitted to and from the site, and a valid 256-bit SSL certificate is presented to confirm that the site does indeed belong to PayPal; however, some of the content on the page has been modified by the fraudsters via a cross-site scripting technique (XSS).
http://news.netcraft.com/archives/2006/06/...tity_theft.html

"Not everything that counts can be counted, and not everything that can be counted counts." "Whoever fights monsters should see to it that in the process he does not become a monster"Posted Image

#2 User is offline   jfirestorm44 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 49
  • Joined: 11-June 06

Posted 17 June 2006 - 02:48 PM

Well that's no good. I just used Paypal the other day to donate $20 dollar to this site and now you tell me this. So do you recommend closing my paypal account or can they only access my information when I'm actually using it?

#3 User is offline   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,603
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 17 June 2006 - 04:00 PM

This hole has been fixed. THis would only have affected you if you clicked on a specially crafted link and logged into your paypal account. if you clicked on the the buttons here or went directly to paypal you would not be affected.

http://news.com.com/PayPal+fixes+phishing+..._3-6084974.html

#4 User is offline   jfirestorm44 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 49
  • Joined: 11-June 06

Posted 17 June 2006 - 11:26 PM

okay that's good to know

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users