Security blogger Joshua Rogers of Melbourne wrote a piece about PayPal’s two -factor authorization system at the beginning of June and discovered a pretty concerning bug in it. Anyone with it enabled, would be able to access the PayPal account by using a special login page designed for eBay.
Like any responsible person, he informed PayPal about the issue right away instead of publishing it. The exploit still works 2 month later despite his warnings, so he decided to go public with it now.
eBay’s function to link a PayPal account is the culprit here. When you’re setting up this service and are entering your login details, a cookie is set with your details and you’re redirected to confirm it. Once logged in that way, just go to the main PayPal page and you’re also logged in there. eBay’s special login page completely ignores any two-way factor authorization settings.
Joshua wrote that he could repeat the process unlimited times and even created a YouTube video demonstrating it.
Thank you Just Another Security Blog for providing us with this information
Image courtesy of PayPal
LIVE THE HORROR: An immersive disaster story aboard a stunningly realised North Sea oil rig,…
The Philips VA LED display uses an advanced multi-domain vertical alignment technology that gives you…
【TFT Screen: The Interactive Interface】This 75% mechanical keyboard comes equipped with a TFT Screen, serving…
FANDOM FUSION Play as your favorite characters and wield their unique weapons and skills. Team…
The Definitive Version of Shin Megami Tensei V - Fully evolved with stunning visuals for…
【Unique Split Design】5200mAh hand warmers rechargeable together with double-sided heating function, split snap swivel design,…