News

Bug in PayPal Renders Two-Factor Authorization Useless

Security blogger Joshua Rogers of Melbourne wrote a piece about PayPal’s two -factor authorization system at the beginning of June and discovered a pretty concerning bug in it. Anyone with it enabled, would be able to access the PayPal account by using a special login page designed for eBay.

Like any responsible person, he informed PayPal about the issue right away instead of publishing it. The exploit still works 2 month later despite his warnings, so he decided to go public with it now.

eBay’s function to link a PayPal account is the culprit here. When you’re setting up this service and are entering your login details, a cookie is set with your details and you’re redirected to confirm it. Once logged in that way, just go to the main PayPal page and you’re also logged in there. eBay’s special login page completely ignores any two-way factor authorization settings.

Joshua wrote that he could repeat the process unlimited times and even created a YouTube video demonstrating it.

Thank you Just Another Security Blog for providing us with this information

Image courtesy of PayPal

Bohs Hansen

Disqus Comments Loading...

Recent Posts

Electronic Arts Titles Played for Over 11 Billion Hours in 2024

Electronic Arts (EA) announced today that its games were played for over 11 billion hours…

2 weeks ago

Just 15% of Steam Gaming Time in 2024 Was Spent on New Releases

Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…

2 weeks ago

STALKER 2 Gets Massive 110GB Patch With 1800+ Fixes

GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…

2 weeks ago

Intel Unveils Core 200H Processors Based on the Previous Raptor Lake Refresh

Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…

2 weeks ago

Ubisoft Reportedly Developing a New Quadruple A Game

Ubisoft is not having the best of times, but despite recent flops, the company still…

2 weeks ago

STALKER 2: Heart of Chornobyl Update 1.1 Fixes 1,800 Issues and Revamps A-Life 2.0

If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…

2 weeks ago