Full Disclosure mailing list archives
Ebay seller information feedback can be forged with Javascript
From: Tobias Weisserth <tobias () weisserth de>
Date: Fri, 23 Jan 2004 13:19:45 +0100
Hi FD, The German news channel ARD reports [1] that Ebay's seller information feedback feature can be modified at will by sellers to influence their credentials. According to the ARD a seller uploads a Javascript along with his description that replaces any real feedback information with faked feedback inside the viewers browser. The ARD recommends to deactivate Javascript when doing business at Ebay. According to the ARD, Ebay knows about this problem but hasn't acted yet. regards, Tobias W. [1] http://www.tagesschau.de/aktuell/meldungen/0,1185,OID2858696_REF1,00.html (German language) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Ebay seller information feedback can be forged with Javascript Tobias Weisserth (Jan 23)