CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Tuesday, February 9th 
Home
Enterprise Software
Enterprise Hardware
Network Security
Compliance
CRM Systems
Data Storage
Chips & Processors
Operating Systems
Communications
World Wide Web
Wireless Tech
Small Business
CIO Issues
Business Briefing
After Hours
Press Releases
 

Advertisement
Network Security

PayPal Fixes URL Used for Fraud

PayPal Fixes URL Used for Fraud
June 19, 2006 11:55AM

Bookmark and Share
"It's pretty awful, actually," said Gartner analyst Avivah Litan. "There's not much consumers can do except monitor their account and watch for visual cues, or download something like the eBay toolbar which warns you about [phishing] sites."


According to Internet-monitoring company Netcraft, a security flaw on PayPal's site allowed hackers to steal credit card information from PayPal users.

The vulnerability, first publicly announced on Friday, involved what is known as a cross-scripting attack. Those targeted by the attack received an e-mail, purporting to be from PayPal, that directed them to a special URL on the PayPal servers.

At that page, they encountered an official-sounding notice. "Your account is currently disabled," it reportedly read, "because we think it has been accessed by a third party. You will now be redirected to the Resolution Center."

Users were then taken to a non-PayPal server Relevant Products/Services in South Korea, with a fake log-in page designed to capture private information -- including credit card and Social Security numbers. Users were requested at that site to remove any limits on funds being removed from their accounts.

PayPal said that it has fixed the flaw and has gotten the Korean server shut down. PayPal also said that it was not clear how many people -- if any at all -- had been duped.

"It's pretty awful, actually," said Gartner analyst Avivah Litan. "There's not much consumers can do except monitor their account and watch for visual cues, or download something like the eBay toolbar which warns you about [phishing] sites."

Litan noted that new Web browsers, when they are released, might be able to offer some protection against scams like this. "The next versions of the Internet Explorer and Mozilla browsers have site ID built in," she said. "If a site is on a black list, the browser is bordered in red. If it's on a white list, the border is green, and if it's on neither, the border is yellow."

PayPal, a popular service Relevant Products/Services for making and receiving online financial transactions, was purchased in 2002 by auction site eBay for a reported $1.5 billion.

It has been a frequent target for phishing scams designed to lure victims with authentic-looking e-mails, often directing users to fake pages where they are enticed to enter their confidential information.

PayPal does warn its users to enter their user names and passwords only on PayPal pages that begin with the following URL: https://www.paypal.com/. It also says that its users should never log in to PayPal from a link in an e-mail.

Advertisement



 Network Security
1. China Cyberattacks: Pervasive Threat
2. Patch Tuesday Will Tie MS Record
3. Cybersecurity Appears Hot for 2010
4. EPIC Objects To Google-NSA Ties
5. Torrent Traps Used To Harvest Logins


advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Google May Make Gmail More Social
  Analysts Expect iPad Price To Drop
  China Busted Hacker-Training Site
  Nook E-Reader Heads to Retail Stores
  Veteran SAP CEO Abruptly Resigns

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with Léo Apotheker resigning as CEO, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Network Security | Compliance | CRM Systems | Data Storage
Chips & Processors | Operating Systems | Communications | World Wide Web | Wireless Tech | Small Business | CIO Issues
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 CIO Today. All rights reserved. Article rating technology by Blogowogo.