PayPal XSS Vulnerability Undermines EV SSL Security

PayPal XSS Vulnerability Undermines EV SSL Security

NewsGroups | Search | Tools
 comp.dcom.telecom  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
PayPal XSS Vulnerability Undermines EV SSL Security Monty Solomon 05-17-2008
Posted by Monty Solomon on May 17, 2008, 4:55 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

PayPal XSS Vulnerability Undermines EV SSL Security
Posted by Paul Mutton at 16 May 2008

A security researcher in Finland has discovered a cross-site
scripting vulnerability on paypal.com that would allow hackers to
carry out highly plausible attacks, adding their own content to the
site and stealing credentials from users.

The vulnerability is made worse by the fact that the affected page
uses an Extended Validation SSL certificate, which causes the
browser's address bar to turn green, assuring visitors that the site
- and its content - belongs to PayPal. Two years ago, a similar
vulnerability was discovered on a different page of the PayPal site,
which also used an SSL certificate.

...

http://news.netcraft.com/archives/2008/05/16/paypal_xss_vulnerability_undermines_ev_ssl_security.html


Similar ThreadsPosted
Debian OpenSSL Vulnerability May 16, 2008, 10:31 am
For Some, Online Persona Undermines a Resume June 10, 2006, 11:28 pm
When PayPal Becomes the Back Office, Too December 19, 2005, 1:47 am
Spam and Scam: E-mail From PayPal and Ebay May 4, 2005, 6:26 pm
Re: Spam and Scam: E-mail From PayPal and Ebay May 5, 2005, 9:10 am
California Regulators, PayPal Reach Settlement July 12, 2005, 12:46 pm
PayPal Makes Settlement Deal With 28 States September 28, 2006, 2:27 pm
McAfee Targets Wi-Fi Security June 3, 2005, 12:58 pm
Sony BMG Urges Security Fix for CDs December 7, 2005, 12:24 am
Using VPN to Provide Some Basic Security February 10, 2006, 9:46 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map