Slashdot Mirror


PayPal Security Flaw Allows Identity Theft

miller60 writes "Phishing scammers are actively exploiting a security flaw in the PayPal web site to steal credit card numbers belonging to PayPal users. The scam tricks users into accessing a URL hosted on the genuine PayPal site, which presents a valid 256-bit SSL certificate confirming that the site belongs to PayPal. However, some of the content on the page has been modified by the fraudsters via a cross-site scripting technique, and victims are redirected to a spoof site that requests their account details."

1 of 212 comments (clear)

  1. Re:No signature = No liability by Mick+Ohrberg · · Score: 5, Insightful

    It's still a hassle and a violation of privacy.

    --

    Quidquid latine dictum sit, altum sonatur.