Portal IT :: News, download, directory


Search: Tuesday 16 March 2010





HVACR News






Add to Google Add to My Yahoo!


  Add to Favorites   Set Home Page





« march 2010
s m t w t f s
28 1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31 1 2 3
4 5 6 7 8 9 10







Phishing alert: PayPal Hit With XSS Exploit
Published on Security  |  February 10, 2009, 14:20

The online payments site has been crippled thanks to another cross-site scripting (XSS) bug that would enable hackers to get away with user passwords.

Even worse, it appears that the bug would also allow the theft of authentication cookies, The Register reports.

Soon-to-be victims arrive on a malicious page designed to open a javascript window. The message in the window reads the following: "Fugitif was here another time."

PayPal si aware of the problem but the company has yet to announce a solution.

This is not the first time that PayPal falls victim to an XSS bug that allowed the injection of unauthorized code. The online payments site had to patch a similar vulnerability in May 2008, after being informed by Finnish researcher Harry Sintonen.

At present time, critics only wonder when will the XSS disaster strike next...




Rate this       Low   High
Curent Rating: 4.0/5 by 1 user
 Print       Email      IM 




 
More Security News
 
Daily News Alert

 
Advertising
 
Top Rated Security News This Month