SCforum.info - Security CENTRAL Forum
08. August 2008., 01:48:54 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security CENTRAL Forum

? Grab this Headline Animator

News: Discuss the #1 Sport in the World at Football442.com
 
  Home   Forum   Help Chess Links Login Register   *

SCforum.info




SCF Recent Posts
[07. August 2008., 09:03:22]

[07. August 2008., 08:59:25]

[07. August 2008., 08:55:52]

[06. August 2008., 08:47:18]

[06. August 2008., 08:34:50]

[06. August 2008., 08:33:18]

[05. August 2008., 08:41:38]

[04. August 2008., 18:06:16]

[04. August 2008., 18:03:35]

[04. August 2008., 09:19:41]
SCF Translate


Members
Total Members: 1332
Latest: Khalili
Stats
Total Posts: 2335
Total Topics: 1471
Online Today: 326
Online Ever: 692
(07. June 2008., 01:24:07)
Users Online
Users: 2
Guests: 594
Total: 596

@MEMBER OF PROJECT HONEY POT
Spam Harvester Protection Network
provided by Unspam



eXTReMe Tracker




Pages: 1
  Reply  |  Send this topic  |  Print  
Author Topic: PayPal XSS vulnerability affects EV SSL  (Read 123 times)
0 Members and 1 Guest are viewing this topic.
Samker
Administrator
*****

KARMA 6
Gender: Male
Age: 30
Location: BiH
Posts: 815



WWW
« on: 17. May 2008., 09:16:47 »
Reply with quoteQuote



A new attack on PayPal could have allowed users who thought they were on a trusted page to access a fraudulent page and possibly expose personal information. On Friday, Finnish researcher Harry Sintonen reported the vulnerability on an IRC chat room.

In an interview with Netcraft, Sintonen said the issue was critical. "You could easily steal credentials." He added that in this case you can't trust the URL http://www.paypal.com.

A few weeks ago PayPal announced it would block users whose browsers did not support EV SSL. Sintonen, who is credited with finding an XSS attack on Barack Obama's Web site in April, said his vulnerability also affected EV SSL pages.

In response, a PayPal representative said: "At PayPal, we take safety and security very seriously. As soon as we were informed of this exploit, we began working very quickly to shut it down. To our knowledge, this exploit was not used in any phishing attacks.

"However, as in any phishing incident, we encourage our customers to contact us immediately if they believe they have given out any personal or financial information that would jeopardize the security of their accounts or lead to unauthorized account access. If an unauthorized withdrawal or purchase is made on a PayPal account, PayPal will reimburse that customer 100 percent. We encourage all of our customers to frequently check the status of their accounts to ensure security."

News Source: CNet

Logged

Secure your PC -> $ $ $  SCshop  $ $ $

Discuss the #1 Sport -> Football442.com
SCforum.info - Security CENTRAL Forum
« on: 17. May 2008., 09:16:47 »
Reply with quoteQuote


 Logged
Pages: 1
  Reply  |  Send this topic  |  Print  
 
Jump to:  

+ Quick Reply
With a Quick-Reply you can use bulletin board code and smileys as you would in a normal post, but much more conveniently.

Lo-Fi Version
Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 29. July 2008., 00:50:09