eBay Scrambles to Fix Phishing Bug
Paul Laudanski writes "c|net is reporting that eBay is scrambling to fix a software glitch which opens doors to phishing attacks via one of its own valid URLs. "The flaw may have already allowed individuals to use one of eBay's URLs to trick unsuspecting parties into visiting malicious sites, the company representative said.""
In other news, ex-hacker warns that social engineering (aka end-user profound dumbness) is the most serious security flaw of computer systems.
This is not the first time this has happend to a huge company, in the summer of 2002 amazon had a similarly large security hole. Can consumers trust large companies anymore? I think so, but you are always taking your chances with security. Sometimes companies become so large that things get easily overlooked.
Want to learn about anything sexual? Check out the sex wiki:
It should be a text-only medium, period. No attachments, no graphics, no opportunity to get someone to click before they think.
Try not. Do or do not, there is no try.
-- Dr. Spock, stardate 2822-3.
Lots of people use the same password for everything. If i were to net a bunch of Ebay account passwords, i could stand a decent chance of getting into the paypal accounts of at least a few of them.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
Bookmark all the financial sites you use, and whenever you receive emails with such "friendly" links, use your bookmark instead, to log in to the site. If it was important, you will see it on the next page there.
I never click on the links even when I know they are legit (to avoid forming a habit).
It would take literally 2 minutes for them to fix this.
Seems that they're only 'scrambling' now there is media attention.
"Physics is to math as sex is to masturbation." -R. Feynman
In otherwords don't be stupid and just randomly enter your password in sites asking for "updates"...
For some phishes, I take the time to login with fake
id's and passwords making sure to insult the scumsucking bastards.
Then I do a network lookup on them and try to
email the corresponding isp. Very easy to do
and protects others.
Vigalantism at its best! Everyone do the same.