Interesting People mailing list archives

IP: Security Flaw Opens Ebay Accounts To Hijack


From: Dave Farber <dave () farber net>
Date: Tue, 02 Apr 2002 18:22:59 -0500


------ Forwarded Message
From: Brian McWilliams <brian () pc-radio com>
Date: Tue, 02 Apr 2002 18:20:58 -0500
To: farber () cis upenn edu
Subject: Security Flaw Opens Ebay Accounts To Hijack

Dave,

A security expert in Canada has found a serious flaw in the password system
at Ebay. Using a simple HTML cut-and-paste technique, it's possible to
steal the account of almost any Ebay user.

Ebay has confirmed the problem but said it won't be able to fix it for
several months. The expert hasn't publicly released details on the
technique yet, but he said it's likely that less ethical people have also
stumbled upon it.

More here:

http://www.newsbytes.com/news/02/175608.html

Brian






------ End of Forwarded Message

For archives see:
http://www.interesting-people.org/archives/interesting-people/


Current thread: