Share

eBay flaw a 'security risk' to customers

Cape Town – A security company has identified a vulnerability in e-commerce site eBay which could leave customers exposed to phishing attacks.

Check Point on Friday announced that it had discovered a flaw that allows attackers to bypass the trading site’s validation and control. This could leave customer computers exposed to malicious Java code.

“If this flaw is left unpatched, eBay’s customers will continue to be exposed to potential phishing attacks and data theft. An attacker could target eBay users by sending them a legitimate page that contains malicious code,” Check Point said in a statement.

“Customers can be tricked into opening the page, and the code will then be executed by the user’s browser or mobile app, leading to multiple ominous scenarios that range from phishing to binary download.”

READ: 6 tips to prevent whaling cyber attacks

The company had reported the flaw to eBay in December 2015, but said that the exploit is still live on the platform.

Multiple media reports indicate that the company has no plans to repair the vulnerability.

The massive online trading site had around 164 million users at the end of 2015 and the malicious attack dubbed “JSF**k” allows cyber crooks to use the platform as a phishing and malware distribution platform, said Check Point.

“The eBay attack flow provides cyber criminals with a very easy way to target users: Sending a link to a very attractive product to execute the attack,” said Oded Vanunu, Security Research Group manager at Check Point.

“The main threat is spreading malware and stealing private information. Another threat is that an attacker could have an alternate login option pop up via Gmail or Facebook and hijack the user’s account.”


- Follow Duncan on Twitter

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.24
-0.7%
Rand - Pound
23.93
-0.6%
Rand - Euro
20.56
-0.5%
Rand - Aus dollar
12.48
-0.7%
Rand - Yen
0.12
-0.5%
Platinum
914.50
-0.6%
Palladium
1,010.50
-1.5%
Gold
2,322.56
+0.0%
Silver
27.20
-0.4%
Brent-ruolie
88.42
+1.6%
Top 40
68,574
+0.8%
All Share
74,514
+0.7%
Resource 10
60,444
+1.4%
Industrial 25
104,013
+1.2%
Financial 15
15,837
-0.4%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders