
An XSS bug (cross-site scripting) in the main area of eBay would have made the lives of phishing actors much easier if they knew of its existence.
The bug, discovered by a hacker known as MLT, is an XSS attack that could allow an attacker to add special parameters to the end of the ULR and cause the eBay site to execute malicious code in the user's browser.
MLT reports that, because the “HttpOnly” is on the ebay.com domain, attackers will not be able to steal the user's cookies via this flaw, but this does not protect users from other types of more complex attacks.
The XSS flaw could be very useful in phishing attacks
In a detailed blog post, the hacker showed readers step-by-step instructions on how to create a phishing page for the site's login screen. Once this HTML clone was created, he also added a PHP file that would receive data from the fake website and then wrote it to a log.txt file. When finished, he hosted this fake eBay login page on his server so it could be available on the internet.
Using the XSS bug he first discovered, he created a fake ebay.com URL, which uses parameters that load an iframe on top of the real page.
This iframe was set to load the fake MLT login. Because the XSS flaw allowed the intruder to use the official area of the site, users would never suspect it.
eBay fixed the issue before it became a problem
Sending this malicious link in email or social media would allow the hacker to collect passwords from all users who logged in.
Of course, to cover up the fake login, using JavaScript code for the fake login page, it could automatically redirect users to a real page on the site, and disappear the phishing page once the credentials had been stolen.
MLT says he reported the issue to eBay, which fixed it in the meantime.
