View Single Post
Old 17-09-14, 15:59   #1
Ladybbird
 
Ladybbird's Avatar
 
Join Date: Feb 2011
Posts: 50,610
Thanks: 28,767
Thanked 14,428 Times in 10,234 Posts
Ladybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond repute

Awards Showcase
Best Admin Best Admin Gold Medal Gold Medal 
Total Awards: 8

Important WARNING=EBay Attack-You & Your Info at Risk

BBC, 17 September 2014

eBay Redirect Attack Puts Buyers' Credentials at risk


EBay has been compromised so that people who clicked on some of its links were automatically diverted to a site designed to steal their credentials.
The spoof site had been set up to look like the online marketplace's welcome page.


The US firm was alerted to the hack on Wednesday night but removed the listings only after a follow-up call from the BBC more than 12 hours later.

One security expert said he was surprised by the length of time taken.
"EBay is a large company and it should have a 24/7 response team to deal with this - and this case is unambiguously bad," said Dr Steven Murdoch from University College London's Information Security Research Group.

The security researcher was able to analyse the listing involved before eBay removed it.
He said that the technique used was known as a cross-site scripting (XSS) attack.
It involved the attackers placing malicious Javascript code within product listing pages. This code in turn automatically redirected affected users through a series of other websites, so that they ended up at the page asking for their eBay log-in and password.

Users only had to click the original listing to have their browser hijacked.

"The websites the user is being redirected to are almost certainly compromised by the attacker to hide his or her traces," Dr Murdoch explained.
__________________
AMERICA WAS ONCE AN INNOVATED & RESPECTED COUNTRY and THEN ALONG CAME TRUMP.....





That buzz you hear is George Washington spinning in his grave

Ladybbird is online now   Reply With Quote
The Following User Says Thank You to Ladybbird For This Useful Post:
BaZZa101 (19-09-14)