Michael “Artsploit” Stepankin, an independent security researcher, discovered a critical security flaw in PayPal that allowed him to execute malicious code on the company’s servers. This allowed him to gain complete control of PayPal’s infrastructure.
The security flaw originates from various open source Java libraries.
The researchers who discovered this flaw, first in Java (before Stepankin implemented it in Paypal) also published a tool that automatically generates the malicious code needed to exploit this vulnerability through the Apache Commons Collections Java library.
Mr. Stepankin used this tool to create a malicious Java serialized object, which he then used on PayPal. This is how he discovered that the company's IT failed to protect it.
“I realized that this unsigned Java serialized object could be managed by the application,” said Mr. Stepankin.
“This means you can send the Java serialized object to the server as readObject or as readResolve.”.
The first Java malware that the researcher managed to upload to PayPal's servers was just a simple test.
After finding the evidence, Mr. Stepankin created a second exploit, much more intrusive. This exploit contained shell commands and was able to gain access to the /etc/passwd file.
Stepankin contacted PayPal and informed them of his discovery. Despite the fact that the company was already aware of the vulnerability from another security researcher, it thanked the researcher for his discovery and rewarded him with cash.
As Mr. Stepankin reports, the issue was reported to the company in mid-December and has now been fixed.
See the PoC
