Full Disclosure mailing list archives

Small vulnerability in Canadian Pay Pal Secret Question


From: j tole <jtole2003 () yahoo com>
Date: Fri, 9 Jan 2004 11:00:59 -0800 (PST)

This vulnerability isn't a huge one and isn't even so
much technical but I thought it was at least worth
addressing.

This problem arises from the Secret Questions
seciotion of the pay pal account, and as far as I know
this only affects canadian members.

One of the secret questions you can select when
setting up your pay pal account is to enter the last 4
digits of your drivers license. The problem here, is
that the last 4 digits of most any canadian drivers
license are the month and day that you were born. For
example of the last 7 digits of my drivers license
were 8-40726 then I would be born on july 26th, 1984.
Canada uses this as a secondary measure to ensure
validity of age against people modify their license (I
used to work in a bar).

So anyone who wanted to know the answer to the last 4
digits of your drivers license secret question would
only need to know the day and month you were born to
know the answer.

Seeing as how the other 3 possible secret choice
questions are kinda weak anyways, it doesn't provide
much security against someone who has done their
homework from stealing your money. 

Also it is my guess that this question was just left
over from the secret question on the american paypal,
which american licenses don't use the same method, I
think.

Anyways, have fun.

J. Tole a.k.a. ph1zzle
jtole2003 () yahoo com


__________________________________
Do you Yahoo!?
Yahoo! Hotjobs: Enter the "Signing Bonus" Sweepstakes
http://hotjobs.sweepstakes.yahoo.com/signingbonus

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: