eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
|
12-22-2005, 12:55 PM,
Post: #11
|
|||
|
|||
Re: eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hij
Quote:Corporate bureaucracy is to blame for their not fixing the software. The programming guys probably need approval from 50 supervisors just to take a piss. laughing7 Hmm, well that could explain all the outages and screwups on eBay.. I mean, if they're sneaking back behind a rack of servers and hanging a quick leak on the sly, well, you know us guys, terrible aim and all, they're shorting the damn things out.
Riotz Swimwear on eBay - Brazilian Bikinis on eBay
Brazilian Bikinis - Off-eBay site now open! Thomas the Tank Engine [url=http://ecommerce-info.ca]http://ecommerce-info |
|||
12-22-2005, 02:01 PM,
Post: #12
|
|||
|
|||
Re: eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
Quote:Hmm, well that could explain all the outages and screwups on eBay.. What's real funny (but pathetic at the same time) is that they treat their employees they pay at ebay HQ just like they treat their employees that pay them. The feebay sellers. Like little children.
.
|
|||
12-26-2005, 11:22 PM,
Post: #13
|
|||
|
|||
Re: eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks
[quote author=bargainbloodhound link=topic=1668.msg6424#msg6424 date=1135222936]
eBay shares equal blame for account hijackings because it knew about and ignored warnings that a security hole existed on its site through which a user could place malicious code in a listing on the ebay site or on an about me page that would redirect them from the eBay site to an off ebay phishing site. Almost 1 year after this vulnerability was pointed out to eBay, hackers did in fact take advantage of this hole in December 2005 to phish users on the ebay site . The GulfTech warning and article below were issued in January 2005...eBay did nothing despite the warnings. The full article: http://www.gulftech.org/?node=research&article_id=00064-01042005 [/quote] They deserve full blame if they didn't fix a known problem. Bunch of s |
|||
01-03-2006, 01:40 PM,
Post: #14
|
|||
|
|||
eBay Security Holes Continue to Put Viewers of Its Auctions At Risk
One month later, eBay has yet to fix the security hole that allows phishers to put malicious javascript in listings.
from today's issue of Auctionbites (an eBay-orientated email newsletter that rehashes press releases and provides friendly editorial coverage to advertisers): Quote:An eBay auction for a Rolls-Royce Phantom contained a Java Applet designed to install malicious code on viewer's computers. The auction was listed on eBay.com by a seller located in the UK on December 28, 2005...A hit counter showed the auction had been viewed nearly 3,000 times before the auction was removed Monday full article: http://auctionbytes.com/cab/abn/y06/m01/i03/s01 |
|||
01-04-2006, 06:35 PM,
Post: #15
|
|||
|
|||
Re: eBay Security Holes Continue to Put Viewers of Its Auctions At Risk
[quote author=mandy link=topic=1668.msg7027#msg7027 date=1136295605]
One month later, eBay has yet to fix the security hole that allows phishers to put malicious javascript in listings. Quote:An eBay auction for a Rolls-Royce Phantom contained a Java Applet designed to install malicious code on viewer's computers. The auction was listed on eBay.com by a seller located in the UK on December 28, 2005...A hit counter showed the auction had been viewed nearly 3,000 times before the auction was removed Monday full article: http://auctionbytes.com/cab/abn/y06/m01/i03/s01 [/quote] Amazing. Why didn't they just say no to java scripts after the incident last month? |
|||
04-01-2006, 09:15 AM,
Post: #16
|
|||
|
|||
eBay refuses to fix Security Holes On Its Listing Pages that Lead to ID Theft
1 1/2 years after eBay was warned about this security flaw on its web site it has yet to fix the problem. More reports of phishers placing malware directly on eBay listing pages:
Quote:Phishers set hidden traps on eBay full article: http://news.com.com/Phishers+set+hidden+...56687.html |
|||
04-01-2006, 04:40 PM,
Post: #17
|
|||
|
|||
eBay refuses to fix Security Holes On Its Listing Pages that Lead to ID Theft
Quote:eBay is aware of such abuse of its service for trickery by cybercrooks, Catherine England, an eBay spokeswoman, said Friday. Try telling people who have had their identities/personal data stolen that allowing sellers to have scrolling galleries and other javascript-driven tools in auction listings outweighs the identity theft that has taken place as a result of eBay's refusal to fix this problem...I don't think many of the people who have been victimized as a result of this problem would agree with England that the benefits outweigh the negatives. mileyazwipe:
"Well, Jay was so giddy that someone named Jay was involved with this site we posted our first non-eBay listing in 3 years here at Lunarbid (we tried two items at Yahoo once upon a time, they bombed)" -Marie posting in a LunarBid thread at OTWA in 2005 wins the award for 'most moronic reason ever given for choosing a venue"
"thanks twat u must have nothing better 2 do. do u talk to all your members like that. will not be recomending your site. best way to put it is TULIPTOOLS.COM IS REALLY SHIT. DONT JOIN." -pubescent owner of rinky dink off2auction.com in 2011 |
|||
04-04-2006, 07:35 AM,
(This post was last modified: 04-04-2006, 07:37 AM by mandy.)
Post: #18
|
|||
|
|||
SECURITY WARNING: eBay Web Site Contains Cross Site Scripting Vulnerability
Using the eBay web site may leave you at the risk of having your personal information stolen. US-CERT (run by the US Dept. of Homeland Security) issued an advisory on April 3rd warning that the eBay web site contains a cross site scripting vulnerability.
Quote:Vulnerability Note VU#808921 the full security advisory: http://www.kb.cert.org/vuls/id/808921 related topic: eBay Knew For 1 Yr.That Security Holes On Its Site Could Lead to Account Hijacks http://community.tuliptools.com/index.ph...668.0.html |
|||
04-04-2006, 04:26 PM,
Post: #19
|
|||
|
|||
SECURITY WARNING: eBay Web Site Contains Cross Site Scripting Vulnerability
Quote: US-CERT (run by the US Dept. of Homeland Security) issued an advisory on April 3rd warning that the eBay web site contains a cross site scripting vulnerability. eBay's spokesperson said the benefits of not fixing the problem outweigh the security risks? I hope she said that on April Fool's Day intending it to be a joke. |
|||
04-05-2006, 03:19 AM,
Post: #20
|
|||
|
|||
SECURITY WARNING: eBay Web Site Contains Cross Site Scripting Vulnerability
Companies need to be fined heavily when they refuse to fix security problems. :
|
|||
« Next Oldest | Next Newest »
|
Users browsing this thread: 2 Guest(s)