Forgot your password?
typodupeerror

Submission + - eBay redirect attack puts buyers' credentials at risk

mrspoonsi writes: EBay has been compromised so that people who clicked on some of its links were automatically diverted to a site designed to steal their credentials. The spoof site had been set up to look like the online marketplace's welcome page. The firm was alerted to the hack on Wednesday night but removed the listings only after a follow-up call from the BBC more than 12 hours later. One security expert said he was surprised by the length of time taken. "EBay is a large company and it should have a 24/7 response team to deal with this — and this case is unambiguously bad," said Dr Steven Murdoch from University College London's Information Security Research Group. The security researcher was able to analyse the listing involved before eBay removed it. He said that the technique used was known as a cross-site scripting (XSS) attack.
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

eBay redirect attack puts buyers' credentials at risk

Comments Filter:

Nothing makes a person more productive than the last minute.

Working...