• $
  • £

eBay redirect attack puts buyers' credentials at risk

eBay redirect attack puts buyers' credentials at risk
18.09.2014 23:00

EBay has been compromised so that people who clicked on some of its links were automatically diverted to a site designed to steal their credentials.

The spoof site had been set up to look like the online marketplace's welcome page.

The US firm was alerted to the hack on Wednesday night but removed the listings only after a follow-up call from the BBC more than 12 hours later.

One security expert said he was surprised by the length of time taken.

"EBay is a large company and it should have a 24/7 response team to deal with this - and this case is unambiguously bad," said Dr Steven Murdoch from University College London's Information Security Research Group.

The security researcher was able to analyse the listing involved before eBay removed it.

He said that the technique used was known as a cross-site scripting (XSS) attack.

It involved the attackers placing malicious javascript code within product listing pages. This code in turn automatically redirected affected users through a series of other websites, so that they ended up at the page asking for their eBay log-in and password.

Users only had to click the original listing to have their browser hijacked.

"The websites the user is being redirected to are almost certainly compromised by the attacker to hide his or her traces," Dr Murdoch explained.

He added that the fake page the users were ultimately delivered to contained code that had the potential to carry out further malicious actions.

"EBay is pretty competent, but obviously it has been caught out here," he said.

"Cross-site scripting is well within the top 10 vulnerabilities that website owners should be concerned about."

A spokesman for eBay played down the scope of the attack.

"This report relates only to a 'single item listing' on eBay.co.uk whereby the user has included a link which redirects users away from the listing page," he said.

"We take the safety of our marketplace very seriously and are removing the listing as it is in violation of our policy on third-party links."

However, the BBC identified that a total of three listings had been posted by the same account involved.

At least two of them produced the same redirect behaviour. The third was removed by eBay, along with the other two, before it could be checked.

Delayed reaction

The issue was originally identified by Paul Kerr, an IT worker from Alloa in Clackmannanshire who is also an "eBay PowerSeller".

He called the firm shortly after he had clicked on a listing for an iPhone and been redirected.

(BBC)

Bakudaily.Az

Similar news
Similar news
China sent 280 container trains to Europe via Middle Corridor since early 2024
Business 16:09
China sent 280 container trains to Europe via Middle Corridor since early 2024
Azerbaijan and Ukraine explore avenues for deepening economic ties
Business 17:30
Azerbaijan and Ukraine explore avenues for deepening economic ties
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
Business 13:30
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
35 projects implemented in liberated territories of Azerbaijan in 2023
Business 16:00
35 projects implemented in liberated territories of Azerbaijan in 2023
Israeli companies invited to investment projects in Karabakh’s industrial parks
Business 18:30
Israeli companies invited to investment projects in Karabakh’s industrial parks
Italian firms interested in participating in projects to be implemented in Karabakh
Business 14:00
Italian firms interested in participating in projects to be implemented in Karabakh
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Business 15:00
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Business 10:00
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Azerbaijan to increase value of non-oil exports to $5B by 2026
Business 14:00
Azerbaijan to increase value of non-oil exports to $5B by 2026
Anews TV

Our official Youtube channel

Subscribe