Home / Software & Gaming / Security / eBay fails to fix security flaw despite consistent reports since February

eBay fails to fix security flaw despite consistent reports since February

eBay hasn't been entirely upfront with its users this year when it comes to site attacks and information being stolen. Some eBay listings have been found to automatically redirect users to malicious websites via cross-site scripting on listing pages using Javascript, a problem that has existed and been consistently reported to the company since February, yet, nothing has been done about it so far.

The BBC managed to get its hands on a chat transcript from February, showing eBay user, Paul Castle, explaining the issue: “I was just browsing in Digital Cameras and came across a password-harvesting scam”, he explained. However, upon clicking the listing he found that it “transfers immediately to a password harvest scam page.”

At the time, he stressed that this is a big problem as there could be hundreds of listings doing the same thing. The eBay staff told Castle that the issue had been flagged up with “higher authorities”.

ebay

Upon further investigation, the BBC found a total of 64 malicious listings from the past two weeks alone. An eBay spokesperson gave the following statement on Friday:

“This is not a new type of vulnerability on sites such as eBay. This is related to the fact that we allow sellers to use active content like Javascript and Flash on our site. Many of our sellers use active content like Javascript and Flash to make their eBay listings more attractive. However, we are aware that active content may also be used in abusive ways.”

According to the spokesperson, eBay has a range of security measures in place to detect malicious code and remove listings. However, the company has yet to explain why these measures are failing to catch so many listings out and why it hasn't been upfront about the issue with its users, having known about the security flaw since the start of this year.

As you would expect, security experts have since criticized eBay for not responding to the issue fast enough. Ilia Kolochenko, XSS expert and chief executive of security firm High-Tech Bridge, has noted that while it is difficult for large sites to be completely free of XSS vulnerabilities, companies must do more to plug the security hole, rather than covering up the issue by removing offending posts every so often.

This isn't the first time eBay has had issues with security this year, it had to force all users to change their passwords a few months back after user information was compromised.

Discuss on our Facebook page, HERE.

KitGuru Says: The fact that eBay has failed to fix this security issue, despite having known about it since February is alarming. It may very well have automated systems in place to stop malicious code but 64 listings have been posted in the last two weeks, these weren't stopped by the site's automated measures and could have affected hundreds of users. Hopefully now that the word is out, eBay will forced to tighten up its security.

Source: The BBC

Become a Patron!

Check Also

Game Freak confirms data breach following massive Pokémon leak

Following a massive number of Pokémon leaks, including source code, Game Freak has confirmed a data breach. The leak includes Game Freak employee information.

One comment

  1. ebay are such liars! Consistently documented and reported since 2006 or 7. Search youtube for ebay xss. There’s even proof the actual flaw goes all the way back to 1999, search ebayla virus