Security blogger Joshua Rogers of Melbourne wrote a piece about PayPal’s two -factor authorization system at the beginning of June and discovered a pretty concerning bug in it. Anyone with it enabled, would be able to access the PayPal account by using a special login page designed for eBay.
Like any responsible person, he informed PayPal about the issue right away instead of publishing it. The exploit still works 2 month later despite his warnings, so he decided to go public with it now.
eBay’s function to link a PayPal account is the culprit here. When you’re setting up this service and are entering your login details, a cookie is set with your details and you’re redirected to confirm it. Once logged in that way, just go to the main PayPal page and you’re also logged in there. eBay’s special login page completely ignores any two-way factor authorization settings.
Joshua wrote that he could repeat the process unlimited times and even created a YouTube video demonstrating it.
Thank you Just Another Security Blog for providing us with this information
Image courtesy of PayPal
Electronic Arts (EA) announced today that its games were played for over 11 billion hours…
Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…
GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…
Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…
Ubisoft is not having the best of times, but despite recent flops, the company still…
If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…