Technology, Discovery & Innovation
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Computing Digital Life Discovery Space More Topics...
Network Security
Average Rating:
Rate this article:  
PayPal Fixes URL Used for Fraud PayPal Fixes URL Used for Fraud
By Barry Levine
June 19, 2006 11:55AM

Bookmark and Share
"It's pretty awful, actually," said Gartner analyst Avivah Litan. "There's not much consumers can do except monitor their account and watch for visual cues, or download something like the eBay toolbar which warns you about [phishing] sites."
 



According to Internet-monitoring company Netcraft, a security flaw on PayPal's site allowed hackers to steal credit card information from PayPal users.

The vulnerability, first publicly announced on Friday, involved what is known as a cross-scripting attack. Those targeted by the attack received an e-mail, purporting to be from PayPal, that directed them to a special URL on the PayPal servers.

At that page, they encountered an official-sounding notice. "Your account is currently disabled," it reportedly read, "because we think it has been accessed by a third party. You will now be redirected to the Resolution Center."

Users were then taken to a non-PayPal server Relevant Products/Services in South Korea, with a fake log-in page designed to capture private information -- including credit card and Social Security numbers. Users were requested at that site to remove any limits on funds being removed from their accounts.

PayPal said that it has fixed the flaw and has gotten the Korean server shut down. PayPal also said that it was not clear how many people -- if any at all -- had been duped.

"It's pretty awful, actually," said Gartner analyst Avivah Litan. "There's not much consumers can do except monitor their account and watch for visual cues, or download something like the eBay toolbar which warns you about [phishing] sites."

Litan noted that new Web browsers, when they are released, might be able to offer some protection against scams like this. "The next versions of the Internet Explorer and Mozilla browsers have site ID built in," she said. "If a site is on a black list, the browser is bordered in red. If it's on a white list, the border is green, and if it's on neither, the border is yellow."

PayPal, a popular service Relevant Products/Services for making and receiving online financial transactions, was purchased in 2002 by auction site eBay for a reported $1.5 billion.

It has been a frequent target for phishing scams designed to lure victims with authentic-looking e-mails, often directing users to fake pages where they are enticed to enter their confidential information.

PayPal does warn its users to enter their user names and passwords only on PayPal pages that begin with the following URL: https://www.paypal.com/. It also says that its users should never log in to PayPal from a link in an e-mail.
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Mobile Enterprise Spotlight
To Love or Not To Love: Apple iPad Pros and Cons
Now that the iPad has officially been announced, opinions are rolling in on this device that combines the features of an iPod, e-reader, and tablet PC. Will the iPad turn fewer heads than the iPhone?
 
Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?
 
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
Sci-Tech Today
Home/Top News | Computing | Digital Life | Discovery | Space | Innovation | Health | Science News
Environment
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.