May 16, 2008 1:15 PM PDT

PayPal XSS vulnerability affects EV SSL

A new attack on PayPal could have allowed users who thought they were on a trusted page to access a fraudulent page and possibly expose personal information. On Friday, Finnish researcher Harry Sintonen reported the vulnerability on an IRC chat room.

In an interview with Netcraft, Sintonen said the issue was critical. "You could easily steal credentials." He added that in this case you can't trust the URL http://www.paypal.com.

A few weeks ago PayPal announced it would block users whose browsers did not support EV SSL. Sintonen, who is credited with finding an XSS attack on Barack Obama's Web site in April, said his vulnerability also affected EV SSL pages.

In response, a PayPal representative said: "At PayPal, we take safety and security very seriously. As soon as we were informed of this exploit, we began working very quickly to shut it down. To our knowledge, this exploit was not used in any phishing attacks.

"However, as in any phishing incident, we encourage our customers to contact us immediately if they believe they have given out any personal or financial information that would jeopardize the security of their accounts or lead to unauthorized account access. If an unauthorized withdrawal or purchase is made on a PayPal account, PayPal will reimburse that customer 100 percent. We encourage all of our customers to frequently check the status of their accounts to ensure security."

Recent posts from Defense in Depth
Researcher faults Apple iPhone on security updates
Google RatProxy looks for cross-site flaws
Hundreds of Lithuanian Web sites defaced
Mozilla and Opera fix security flaws
Four security bulletins expected on Patch Tuesday
Powered by Jive Software
advertisement
  • About Defense in Depth

  • With over eight years at CNET covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews with the top security researchers making the news as well as offering the hands-on, non-technical advice you'll need to stay safe online.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Photos: Army designates year's best inventions

  2. Photos: Cracking Open the Apple Macintosh Classic

  3. Photos: Top 10 reviews of the week

  4. Photos: Top 10 newly discovered species

  5. Source: Protective order will keep Viacom out of sensitive YouTube user data

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

advertisement
On TV.com: Heroes' KIRSTEN BELL - looking good!
Advanced
search
Advanced
search
Visit other CBS Interactive sites