HomeinetPaypal Hacked

Paypal hacked

Michael “Artsploit” Stepankin, an independent security researcher, discovered a critical security flaw in PayPal that allowed him to execute malicious code on the company’s servers. This allowed him to gain complete control of PayPal’s infrastructure.paypal

The security flaw originates from various open source Java libraries.

The researchers who discovered this flaw, first in Java (before Stepankin implemented it in Paypal) also published a tool that automatically generates the malicious code needed to exploit this vulnerability through the Apache Commons Collections Java library.

Mr. Stepankin used this tool to create a malicious Java serialized object, which he then used on PayPal. This is how he discovered that the company's IT failed to protect it.

“I realized that this unsigned Java serialized object could be managed by the application,” said Mr. Stepankin.

“This means you can send the Java serialized object to the server as readObject or as readResolve.”.

The first Java malware that the researcher managed to upload to PayPal's servers was just a simple test.

After finding the evidence, Mr. Stepankin created a second exploit, much more intrusive. This exploit contained shell commands and was able to gain access to the /etc/passwd file.

Stepankin contacted PayPal and informed them of his discovery. Despite the fact that the company was already aware of the vulnerability from another security researcher, it thanked the researcher for his discovery and rewarded him with cash.

As Mr. Stepankin reports, the issue was reported to the company in mid-December and has now been fixed.

See the PoC

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS