A simple, yet effective flaw discovered on eBay's website exposed hundreds of millions of its custom

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
An Independent Security Researcher reported a critical vulnerability to eBay last month that had the capability to allow hackers to host a fake login page, i.e. phishing page, on eBay website in an effort to steal users' password and harvest credentials from millions of its users.

The researchers, nicknamed MLT, said anyone could have exploited the vulnerability to target eBay users in order to take over their accounts or harvest thousands, or even millions, of eBay customers credentials by sending phishing emails to them.


MLT published a blog post about the eBay flaw on Monday, demonstrating how easy it is to exploit the flaw like this and steal customers' passwords.


Here's How ebay Hack Works

The flaw actually resided in the URL parameter that allowed the hacker to inject his iFrame on the legitimate eBay website.

This is a common web bug, technically known as a Cross-Site Scripting (XSS) vulnerability, in which attackers can exploit the vulnerability to inject malicious lines of code into a legitimate website.

Full article. Simple Yet Effective eBay Bug Allows Hackers to Steal Passwords - The Hacker News
 

DracusNarcrym

Level 20
Verified
Top Poster
Well-known
Oct 16, 2015
970
An Independent Security Researcher reported a critical vulnerability to eBay last month that had the capability to allow hackers to host a fake login page, i.e. phishing page, on eBay website in an effort to steal users' password and harvest credentials from millions of its users.

The researchers, nicknamed MLT, said anyone could have exploited the vulnerability to target eBay users in order to take over their accounts or harvest thousands, or even millions, of eBay customers credentials by sending phishing emails to them.


MLT published a blog post about the eBay flaw on Monday, demonstrating how easy it is to exploit the flaw like this and steal customers' passwords.


Here's How ebay Hack Works

The flaw actually resided in the URL parameter that allowed the hacker to inject his iFrame on the legitimate eBay website.

This is a common web bug, technically known as a Cross-Site Scripting (XSS) vulnerability, in which attackers can exploit the vulnerability to inject malicious lines of code into a legitimate website.

Full article. Simple Yet Effective eBay Bug Allows Hackers to Steal Passwords - The Hacker News
I can verify that this can actually work - it's not just some crazy, impossible and rare exploit which only theoretically poses a risk to users.
eBay had better act up against this or there might be trouble...
 
  • Like
Reactions: frogboy

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
I can verify that this can actually work - it's not just some crazy, impossible and rare exploit which only theoretically poses a risk to users.
eBay had better act up against this or there might be trouble...
That is a scary thought that you can confirm this. :D
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top