eBay Hackers Exploit IE, Firefox Vulnerabilities
eBay buyers are being asked to take extra precautions when conducting their online shopping after security specialists warned that a string of hackers had infiltrated the popular auction site. The hackers exploited several unpatched vulnerabilities in Firefox and Internet Explorer browsers to create false listings and entice people to bid on fraudulent items.
Details of the Stealth Attack
Analysts believe that it was an XSS (cross-site scripting) attack that implemented unauthorized java script elements stored on third-party websites. This allowed eBay pages to contain outside email links and other unauthorized codes, while still evading toolbars designed to detect these fraudulent items. (Source: theregister.co.uk)
The hackers implemented other elements to make their listings appear real, including an "email the seller" link which activated an aol.com address, and a random number generator which changed the item number each time the page was loaded, making the page appear as if it were "live."
The attacks targeted Firefox by exploiting the way the browser implements XBL (XML binding language). After the hacker had created an infected CSS (cascade-style sheet) on a third-party site, Firefox was tricked into allowing forbidden codes that led to fraudulent content in the listings.
All of this, of course, went on unnoticed by the security teams at Mozilla, Microsoft, and eBay.
Mozilla, MS, eBay all play The Blame Game
While the attack was done externally by hackers, all three of the major players involved in the security breach have pointed their fingers at each other.
eBay downplayed the severity of the attack, claiming that "online security experts are already aware of the breach and have identified it as a known bug in Firefox. eBay utilizes sophisticated security technologies to protect our customers against attacks such as this." (Source: techchuck.com)
While claiming to have taken down all known hoax listings on their domain, eBay warns that listings found on other websites that accept user-generated content may still be vulnerable.
Microsoft also weighed in on the situation, claiming that the security breach was not the result of unpatched vulnerabilities in Internet Explorer, but rather because of external websites that fail to properly protect themselves and others against such attacks.
Mozilla claimed to be in the process of patching all known Firefox vulnerabilities as well.
In any event, all three parties urge consumers to be extra cautious when purchasing items over the Internet.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.