ChannelX Logo
Search
Close this search box.

eBay fixes redirect phishing flaw

According to The Register, eBay have plugged a hole in the eBay sign in page which allowed phishers to capture user’s data. Unlike most phishing scams this one actually directed the user to the official eBay sign in page prior to redirecting them to the scammers site. Once at the scammers site you were presented with a page which looked like the authentic eBay page, but with a failed logon as if you’d mistyped your eBay password. jjncj.com points out two issues:

1) if you had checked the URL and the security certificate before you signed in, you might not check the second time and enter your information again
2) it was using E-Bay’s own sign-in procedure to redirect you to a phishing page.

jjncj.com provides an example of a hacked (but in this case fairly harmless!) URL which would previously have redirected back to their blog, it now produces an eBay page stating the site is unable to redirect proving that eBay have closed the loophole

eBay redirect fixed

The Register points out that this isn’t the first time eBay have had security flaws where hackers made use of redirects from the site, although this one was fixed considerably quicker than the last.

RELATED POSTS..

TikTok launches Well-being Missions & new trust and safety tools

TikTok launches Well-being Missions & new trust and safety tools

Temu Joins International Trademark Association to Strengthen Global IP Protection

Temu Joins International Trademark Association to Strengthen Global IP Protection

Walmart's Vision for a Stronger Marketplace

Walmart’s Vision for a Stronger Marketplace

eBay 3PM Shield acquisition bolsters ability to identify fakes

eBay 3PM Shield acquisition bolsters ability to identify fakes

New,York,City,,Ny/,Usa-,10-25-20:,Customer,Order,Delivery,Amazon

Amazon Counterfeit Crimes Unit calls for government and businesses to work together

Latest

Take a look through a selection of the latest articles on ChannelX

Register for Newsletter

Receive 5 newsletters per week

Gain access to all research

Be notified of upcoming events and webinars