• $ 1.7
  • € 1.7533
  • ₽ 1.7526
  • ₺ 0.0472
  • £ 2.1077

eBay under pressure as hacks continue

eBay under pressure as hacks continue
29.05.2020 10:47
Leading security researchers have called on eBay to take immediate action over dangerous listings, as the problem continues to put users at risk.

The BBC has now identified more than 100 listings that had been exploited to trick customers into handing over personal data.Over the weekend, readers got in touch with the BBC, saying they had attempted to warn eBay about the problem.The company said it would "continue to review all site features and content".The BBC has found that:Innocent user accounts were hijacked in order to place the fake listings. Many of the accounts had 100% positive feedback, and had sold hundreds of items.One victim who had his account hijacked told the BBC he was locked out of his account - and later billed "around £35" by eBay to cover seller's fees for items he had not auctioned.When customers clicked on a listing that had been compromised, they were brought to a sophisticated, official-looking site that asked victims to log in and share bank account details.The types of items used to target victims ranged from smartphones and televisions to hot tubs and clothing.The vulnerability centres around users' ability to place custom javascript and Flash content into their listings pages.Often sellers will use this method to make their pages look more exciting, with animations or other eye-catching techniques.But use of javascript and Flash, eBay acknowledged, significantly raised the likelihood that malicious code could be included within the site's pages - due to a hacking technique known as cross-site scripting (XSS).It meant users clicking on eBay listings that appeared legitimate were being automatically re-directed to harmful websites designed to steal user information, including credit card details."The summary is that it is exceptionally dodgy and redirecting the user to a nasty web page with some really suspect scripts," said James Lyne from the security firm Sophos."At present we can't get our hands on the end payload, so can't be sure of the attackers complete motive, but it is clear there are still nasty malicious redirects on the eBay site."The problem has affected the site since at least February, the BBC has confirmed - although some experts say it has been an issue for more than a year.Screen shot of fake eBay page(BBC)Bakudaily.Az

Similar news
Similar news
China sent 280 container trains to Europe via Middle Corridor since early 2024
Business 16:09
China sent 280 container trains to Europe via Middle Corridor since early 2024
Azerbaijan and Ukraine explore avenues for deepening economic ties
Business 17:30
Azerbaijan and Ukraine explore avenues for deepening economic ties
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
Business 13:30
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
35 projects implemented in liberated territories of Azerbaijan in 2023
Business 16:00
35 projects implemented in liberated territories of Azerbaijan in 2023
Israeli companies invited to investment projects in Karabakh’s industrial parks
Business 18:30
Israeli companies invited to investment projects in Karabakh’s industrial parks
Italian firms interested in participating in projects to be implemented in Karabakh
Business 14:00
Italian firms interested in participating in projects to be implemented in Karabakh
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Business 15:00
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Business 10:00
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Azerbaijan to increase value of non-oil exports to $5B by 2026
Business 14:00
Azerbaijan to increase value of non-oil exports to $5B by 2026
Anews TV

Our official Youtube channel

Subscribe