Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Reply
 
LinkBack Thread Tools Display Modes
Old 16-06-2011, 10:48 AM   #1 (permalink)
Mozilla Rep
 
sygeek's Avatar
 
Join Date: Apr 2011
Location: Lucknow
Posts: 1,471
Default PayPal vulnerability allows access to any account within 30 seconds




A security vulnerability in PayPal’s systems makes it possible to gain full, unrestricted access to any account within 30 seconds, we’ve heard from Matt Langley of Integrated Computer Enterprises Limited.

The vulnerability lies in PayPal’s forgotten password recovery features. Says Langley:
Quote:
PayPal sends Password Forgotten Change tokens to unauthorized email addresses instead of the email address on the account. Once you follow the link they email, and change the password, you are given total access to that account. No trickery or sophisticated hacking is required. It’s a bug in their email system that corrupts email addresses.
Once the attacker has access, there’s nothing restricting their ability to siphon money out of the account.

The exploit is, of course, a direct violation of PayPal’s privacy policy and a laundry list of laws, so don’t try this at home — but PayPal needs to act as thieves aren’t particularly concerned with such things.

After a range of high profile attacks this year, use of this vulnerability would easily topple the Sony PlayStation Network attack as the most significant and damaging of the year. PayPal is used by millions of Internet users to transfer money.

Our source says that PayPal has been warned previously but ignored his emails. We’ve contacted PayPal on this matter and are awaiting a response.

[I'm not sharing any hack tricks, just a bug. Don't try to use this method to gain access to any account, you're bound to be caught.]


The weird fact about this bug is, you can't avoid this on your personal level, it's all upto the company. Looks like I need to hide my email.
sygeek is offline   Reply With Quote
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 16-06-2011, 11:28 AM   #2 (permalink)
Are you dead yet?
 
deathwish's Avatar
 
Join Date: May 2008
Location: Recesses of your mind
Posts: 57
Default Re: PayPal vulnerability allows access to any account within 30 seconds

Wow!! Now this takes the security issues, or rather security blunders, to a whole new level! If this news breaks out in a big way, it could make most casual users wary of using internet banking, which would push us back a few years in this domain.
__________________
Living out of a box.
deathwish is offline   Reply With Quote
Old 16-06-2011, 11:35 AM   #3 (permalink)
Stuck in Time...
 
Vyom's Avatar
 
Join Date: May 2009
Location: Land of Logic
Posts: 2,278
Default Re: PayPal vulnerability allows access to any account within 30 seconds

Scary stuff.
Hoping PayPal responds soon.
It's good that, I don't have a PayPal account, for now.
__________________
Marty: Hey, Doc, we better back up. We don't have enough road to get up to 88.
Doc Brown: Roads? Where we're going, we don't need, "roads!" :)

──── On the Internet you can be Anything you want. It's Strange that, so many people choose to be Stupid! ────
Vyom is online now   Reply With Quote
Old 16-06-2011, 11:51 AM   #4 (permalink)
Uhu, Not Gonna Happen!
 
gagan007's Avatar
 
Join Date: Nov 2005
Location: Bangalore
Posts: 1,160
Default Re: PayPal vulnerability allows access to any account within 30 seconds

Thanks, I am removing my credit card now!
Unbelievable!
__________________
My personal blog - http://gagan.scholarguru.com
gagan007 is offline   Reply With Quote
Old 16-06-2011, 11:53 AM   #5 (permalink)
Manchester United <3
 
Ishu Gupta's Avatar
 
Join Date: Oct 2010
Location: Noida
Posts: 2,122
Default Re: PayPal vulnerability allows access to any account within 30 seconds

Paypal in India sucks anyways.
You can't buy anything and you have to withdraw your balance within 1 week (iirc) or it'll get reset.
__________________
i5 2500k 4.4GHz @ 1.25v | CM Hyper 212 Evo | HD 3000 @ 1.5GHz | Asus P8Z68-V Gen 3
2x4GB DDR3 1600MHz CL9 | 160GB 7200rpm + 160GB 5400rpm | W7 x64
CM690 II USB3 | Corsair TX750W V2 | APC 1.1KVa | Dell U2312HM + Sansui V8 19"
Razer DA Black + Razer Goliathus | XBox360 wired x2
Senns HD201 | PSP Slim 8GB MSPD | N5800XM 8GB MSD | Speedtest
Ishu Gupta is offline   Reply With Quote
Old 16-06-2011, 12:04 PM   #6 (permalink)
Stuck in Time...
 
Vyom's Avatar
 
Join Date: May 2009
Location: Land of Logic
Posts: 2,278
Default Re: PayPal vulnerability allows access to any account within 30 seconds

I thought in India it's PaisaPay, the substitute of PayPal!
__________________
Marty: Hey, Doc, we better back up. We don't have enough road to get up to 88.
Doc Brown: Roads? Where we're going, we don't need, "roads!" :)

──── On the Internet you can be Anything you want. It's Strange that, so many people choose to be Stupid! ────
Vyom is online now   Reply With Quote
Old 16-06-2011, 12:11 PM   #7 (permalink)
Manchester United <3
 
Ishu Gupta's Avatar
 
Join Date: Oct 2010
Location: Noida
Posts: 2,122
Default Re: PayPal vulnerability allows access to any account within 30 seconds

Quote:
Originally Posted by vineet369 View Post
I thought in India it's PaisaPay, the substitute of PayPal!
That's from eBay.
You can make a Paypal account in India.
__________________
i5 2500k 4.4GHz @ 1.25v | CM Hyper 212 Evo | HD 3000 @ 1.5GHz | Asus P8Z68-V Gen 3
2x4GB DDR3 1600MHz CL9 | 160GB 7200rpm + 160GB 5400rpm | W7 x64
CM690 II USB3 | Corsair TX750W V2 | APC 1.1KVa | Dell U2312HM + Sansui V8 19"
Razer DA Black + Razer Goliathus | XBox360 wired x2
Senns HD201 | PSP Slim 8GB MSPD | N5800XM 8GB MSD | Speedtest
Ishu Gupta is offline   Reply With Quote
Old 16-06-2011, 12:16 PM   #8 (permalink)
Mozilla Rep
 
sygeek's Avatar
 
Join Date: Apr 2011
Location: Lucknow
Posts: 1,471
Default Re: PayPal vulnerability allows access to any account within 30 seconds

Paypal in India is close to DEAD! *f word* you RBI.
sygeek is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by Who
- by clmlbx
- by Charan
- by abhidev

Advertisement




All times are GMT +5.5. The time now is 08:18 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2