Coin Community Family of Web Sites Join Thousands of Coin, Bullion, & Money Collectors
Coin, Banknote and Medal Collectors's Online Mall Royal Canadian Mint products, Canadian, Polish, American, and world coins and banknotes. Specializing in Modern Numismatics Vancouvers #1 Coin and Paper Money Dealer Royal Estate Auctions - $1 Coin AuctionsJoin Thousands of Coin, Bullion, & Money Collectors 300,000 items to help build your collection!








Username:
Password:
Save Password
Forgot your Password?


This page may contain links that result in small commissions to keep this free site up and running.

Welcome Guest! Registering and/or logging in will remove the anchor (bottom) ads. It's Free!

Ebay Hacked Again

To participate in the forum you must log in or register.
Author Previous TopicReplies: 2 / Views: 2,413Next Topic  
Valued Member

Australia
301 Posts
 Posted 09/18/2014  7:26 pm Show Profile   Bookmark this topic Add sweetap to your friends list Get a Link to this Message Number of Subscribers
Thought I would share this I just read on eBays forums.




Heading FYI - ebay hacked again ... not good for business

Nice of them to let us know which they haven't again.

copied article from BBC News (business news)



17 September 2014 Last updated at 14:32

.

ebay redirect attack puts buyers' credentials at risk



ebay has been compromised so that people who clicked on some of its links were automatically diverted to a site designed to steal their credentials. The spoof site had been set up to look like the online marketplace's welcome page.

The US firm was alerted to the hack on Wednesday night but removed the listings only after a follow-up call from the BBC more than 12 hours later. One security expert said he was surprised by the length of time taken.

" ebay is a large company and it should have a 24/7 response team to deal with this - and this case is unambiguously bad," said Dr Steven Murdoch from University College London's Information Security Research Group.

The security researcher was able to analyse the listing involved before ebay removed it.

He said that the technique used was known as a cross-site scripting (XSS) attack.

It involved the attackers placing malicious Javascript code within product listing pages. This code in turn automatically redirected affected users through a series of other websites, so that they ended up at the page asking for their ebay log-in and password.

Users only had to click the original listing to have their browser hijacked.

"The websites the user is being redirected to are almost certainly compromised by the attacker to hide his or her traces," Dr Murdoch explained. (read fully story at BBC)

This copy and pasted from there sellers forums and was posted yesterday.

May need to change passwords AGAIN.
Pillar of the Community
TypeCoin971793's Avatar
United States
6370 Posts
 Posted 09/20/2014  06:24 am  Show Profile   Bookmark this reply Add TypeCoin971793 to your friends list Get a Link to this Reply
I'm becoming more and more leery about getting an ebay account. You can get just as good stuff from here, and the service is much better.
Moderator
Learn More...
SsuperDdave's Avatar
United States
23522 Posts
 Posted 09/20/2014  4:51 pm  Show Profile   Bookmark this reply Add SsuperDdave to your friends list Get a Link to this Reply
ebay allows Javascript in listings? Why am I not surprised?
  Previous TopicReplies: 2 / Views: 2,413Next Topic  

To participate in the forum you must log in or register.



    




Disclaimer: While a tremendous amount of effort goes into ensuring the accuracy of the information contained in this site, Coin Community assumes no liability for errors. Copyright 2005 - 2026 Coin Community Family- all rights reserved worldwide. Use of any images or content on this website without prior written permission of Coin Community or the original lender is strictly prohibited.
Contact Us  |  Advertise Here  |  Privacy Policy / Terms of Use

Coin Community Forum © 2005 - 2026 Coin Community Forums
It took 0.21 seconds to rattle this change. Forums