Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
By goldenmean (Reporter)
Contributor profile | More stories
Story Views
Now:
Last hour:
Last 24 hours:
Total:

PayPal Vulnerability Allows Hackers to Steal All Your Money

% of readers think this story is Fact. Add your two cents.


This post was originally published on this site

A critical security vulnerability has been discovered in the eBay owned global e-commerce business PayPal that could allow attackers to steal your login credentials, and even your credit card details in unencrypted format.

Egypt-based researcher Ebrahim Hegazy discovered a Stored Cross Site Scripting (XSS) vulnerability in the Paypal’s Secure Payments domain.
As it sounds, the domain is used to conduct secure online payments when purchasing from any online shopping website. It enables buyers to pay with their payment cards or PayPal accounts, eliminating the need to store sensitive payment information.
However, it is possible for an attacker to set up a rogue online store or hijacked a legitimate shopping website, to trick users into handing over their personal and financial details.

How the Stored XSS Attack Works?

Hegazy explains a step by step process in his blog post, which gives a detailed explanation of the attack.
Here’s what the researcher calls the worst attack scenario:
  • An attacker need to set up a rogue shopping site or hijack any legitimate shopping site
  • Now modify the “CheckOut” button with a URL designed to exploit the XSS vulnerability
  • Whenever Paypal users browse the malformed shopping website, and click on “CheckOut” button to Pay with their Paypal account, they’ll be redirected to the Secure Payments page
  • The page actually displays a phishing page where the victims are asked to enter their payment card information to complete the purchasing
  • Now on clicking the Submit Payment Button, instead of paying the product price (let’s say $100), the Paypal user will pay the attacker amount of attacker’s choice
Video Demonstration
The researcher has also provided a proof-of-concept (PoC) video that shows attack in work. You can watch the video here.
Hegazy reported this serious security vulnerability to the PayPal team on June 19th, and the team confirmed the security hole, which was fixed on August 25 – just over two months later.
PayPal has also rewarded Hegazy with a bug bounty of $750 for his findings, which is the company’s maximum bug bounty payout for XSS vulnerabilities.

About the author

Senior Technical Writer at Hacker News. Social Media Lover and Gadgets Girl. Speaker, Cyber Security Expert and Technical Writer.




Subscribe for Updates

Want more Interesting News like this? Sign up here to receive the best of ‘The Hacker News’ delivered daily straight to your inbox.

Latest Stories

The post PayPal Vulnerability Allows Hackers to Steal All Your Money appeared first on Middle East Post.


Source: http://middleastpost.com/paypal-vulnerability-allows-hackers-to-steal-all-your-money/


Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Please Help Support BeforeitsNews by trying our Natural Health Products below!


Order by Phone at 888-809-8385 or online at https://mitocopper.com M - F 9am to 5pm EST

Order by Phone at 866-388-7003 or online at https://www.herbanomic.com M - F 9am to 5pm EST

Order by Phone at 866-388-7003 or online at https://www.herbanomics.com M - F 9am to 5pm EST


Humic & Fulvic Trace Minerals Complex - Nature's most important supplement! Vivid Dreams again!

HNEX HydroNano EXtracellular Water - Improve immune system health and reduce inflammation.

Ultimate Clinical Potency Curcumin - Natural pain relief, reduce inflammation and so much more.

MitoCopper - Bioavailable Copper destroys pathogens and gives you more energy. (See Blood Video)

Oxy Powder - Natural Colon Cleanser!  Cleans out toxic buildup with oxygen!

Nascent Iodine - Promotes detoxification, mental focus and thyroid health.

Smart Meter Cover -  Reduces Smart Meter radiation by 96%! (See Video).

Report abuse

    Comments

    Your Comments
    Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

    MOST RECENT
    Load more ...

    SignUp

    Login

    Newsletter

    Email this story
    Email this story

    If you really want to ban this commenter, please write down the reason:

    If you really want to disable all recommended stories, click on OK button. After that, you will be redirect to your options page.