HomeineteBay Bug Allows Hackers to Steal User Passwords

eBay bug lets hackers steal user passwords

ebay

An XSS bug (cross-site scripting) in the main area of eBay would have made the lives of phishing actors much easier if they knew of its existence.

The bug, discovered by a hacker known as MLT, is an XSS attack that could allow an attacker to add special parameters to the end of the ULR and cause the eBay site to execute malicious code in the user's browser.

MLT reports that, because the “HttpOnly” is on the ebay.com domain, attackers will not be able to steal the user's cookies via this flaw, but this does not protect users from other types of more complex attacks.

The XSS flaw could be very useful in phishing attacks

In a detailed blog post, the hacker showed readers step-by-step instructions on how to create a phishing page for the site's login screen. Once this HTML clone was created, he also added a PHP file that would receive data from the fake website and then wrote it to a log.txt file. When finished, he hosted this fake eBay login page on his server so it could be available on the internet.

Using the XSS bug he first discovered, he created a fake ebay.com URL, which uses parameters that load an iframe on top of the real page.

This iframe was set to load the fake MLT login. Because the XSS flaw allowed the intruder to use the official area of the site, users would never suspect it.

eBay fixed the issue before it became a problem

Sending this malicious link in email or social media would allow the hacker to collect passwords from all users who logged in.

Of course, to cover up the fake login, using JavaScript code for the fake login page, it could automatically redirect users to a real page on the site, and disappear the phishing page once the credentials had been stolen.

MLT says he reported the issue to eBay, which fixed it in the meantime.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS