Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

ebay HACKED! Flash Redirect XSS ID Theft Flaw Alive & Well

Loading...

Sign in or sign up now!
1,187
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Nov 3, 2009

Found on the ebay site:
Flash manipulation xss flaw alive and well!
Cappnonymous gives live visual demonstration of the exploit's danger.
Ebay is still a dangerous website!
Stay safe this holiday season! Avoid ebay and IT's long uncorrected critical safety flaws!


Urls seen here:
http://cgi.ebay.com/ebaymotors/ws/eBayISAPI.dll?ViewItem&item=22048549006...

US C.E.R.T.
Vulnerability Note VU#808921
http://www.kb.cert.org/vuls/id/808921

National Cyber Alert System
Cyber Security Alert SA06-117A
http://www.us-cert.gov/cas/alerts/SA06-117A.html

EBay blames users for fraud
http://news.bbc.co.uk/2/hi/business/4533154.stm

Viewers can look here, at the www.firejohndonahoe.com public blog, where Doc, from www.ebaymotorssucks.com has captured images of the source code of the phake login phishing page and more info.
http://tinyurl.com/y9yf93e


There is also another variant of the flash manipulation exploit where the hackers can actually pop right up into your "My ebaY" page.
Again, the uncorrected critical safety flaw has existed a looooong time & to the best of my knowledge still possible/and/or in use

Learn more about that by searching-reading
"Watchdog Group Gives Live Demo of eBay Security Vulnerability"
article on the auctionbytes site, March 2008. "Watchdog Group Gives Live Demo of eBay Security Vulnerability"
article on the auctionbytes site, March 2008.
http://tinyurl.com/yhsj9wa

  • likes, 0 dislikes

Link to this comment:

Share to:

Uploader Comments (cappnonymous)

  • Where are the FEDS and The SEC?

  • Hello gmajorspresents.

    Good question?

    Asleep maybe? With a dubious bedfellow perhaps? lol.

    People whom have fallen victim to, or are concerned about this issue should file complaints to any & all appropriate agencies, & spread the word that ebay is neither safe, honest, reliable, prompt or timely correcting critical safety flaws.

    And although ebay claims enhancement of user experience outweighs the need for safety, they should walk in the shoes of the victims.

    Avoid KKKbay like the plague!

  • Good video!

    Nothing says fun for the Holidays like having your ID stolen, bank accounts cleaned out and your credit ruined all while being lied to and abused by some fly by night outfit that can't or won't even secure their own fraud infested site.

    HAhahahahaha!

    The odds are overwhelming this is all an inside job btw.

    They must be making money on this otherwise they would fix it. Look how fast they act upon anything like, like truthful forum posts for instance

  • Hello Geezer.

    Yes, inside job you say?

    Whether by overt act, by pure indifference, arrogance or complacency, I believe you are correct.

    No reason to correct it when they can just blame the user and brush them aside, count the cash.

    Go have a look at the firejohndonahoe public blog, where you will see the source code. (link in more info area) Apparently the flash snippet was somehow placed into the non ebay description area. Outside the iframe which contains the UGC .... Internal hackers?

see all

All Comments (14)

Sign In or Sign Up now to post a comment!
  • Watch for upcoming vid showing how ebay has shirked the responsibility & refused to correct this now since before this millennium began, since long before the US-CERT warnings came out., Indeed since before the term xss was coined.

  • HOLY COW !

    That's an Eye Opener !

    Thanks so Much Cap !

  • LOL @ KKKbay

Loading...
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more