IT Safety News - Your source for network security news, opinion, product comparisons and reviews. Virus, Worms, Antivirus and Security Information.
Showing posts with label PayPal vulnerability. Show all posts
Showing posts with label PayPal vulnerability. Show all posts
Sunday, March 17, 2013
The expert identified a serious vulnerability in the PayPal subdomain
Expert in the field of information security Prakhar Prasad revealed a serious vulnerability in the PayPal subdomain - BillMeLater.com.
Using this vulnerability, an attacker could upload different file server PayPal formatov.Istochnikom vulnerability became an old version of CMS DotNetNuke, which allows you to upload files to the sites of the following formats: docx, xlsx, pptx, swf, jpg, jpeg, jpe, gif, bmp, png, doc, xls, ppt, pdf, txt, xml, xsl, css, zip and spin.
According to the expert, using the vulnerability by cybercriminals to upload malicious files. For example, downloading a malicious swf-file, they can create online XSS-vulnerability, with the infected files: docx, pptx, xls or pdf - upload BillMeLater client exploits, and in a file format hackers could download txt message letting deface site.
Experts argue that tried to load the shell, which would enable it to execute arbitrary code. However, his attempts were unsuccessful, as the server software has been updated in a timely manner.
Monday, February 4, 2013
The expert identified a serious vulnerability in the PayPal website
Expert in the field of information security Prakhar Prasad revealed a serious vulnerability on the site notices PayPal (paypal-notify.com).
According to experts, the identified errors (blind introduction of SQL-code) has allowed him to have access to the database notification system PayPal.
Prakhar Prasad immediately got in touch with the Paypal Security Team, reported the detection of vulnerabilities. The researcher points out, PayPal responded very promptly. Prasad says that he revealed the vulnerability was closed the next day after he went to the Paypal Security Team. We know that for vulnerability information from Paypal expert was $ 3,000 (2,250 euros).
Subscribe to:
Posts (Atom)
