Feeds

eBay redirection ruse reloaded

18 month-old security flaw still remains unfixed

Secure remote control for conventional and virtual desktops

A redirection script error on eBay's site remains open to abuse 18 months after The Register first reported it.

The flaw - actively exploited in phishing scams since February 2005 - creates a means to make fraudulent emails look more convincing.

Shortly after publishing a report on the problem, eBay assured us that it had plugged the hole. Despite this the site remains open to abuse through the same back door, as an email from Reg reader Adrien this week reminds us.

He notes that URLs such as this example are being bounced off eBay site onto other domains. In this case the surfer is redirected to Google, but sending people to less savory destinations is equally possible.

"I'm holding out for the second anniversary of the backdoor. I might bake a birthday cake and send it to them. A nice phish cake," Adrian said.

We are yet to hear back from the online auction house on whether it has any plans to address the problem. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
DRUPAL-OPCALYPSE! Devs say best assume your CMS is owned
SQLi hole was hit hard, fast, and before most admins knew it needed patching
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
How to simplify SSL certificate management
Simple steps to take control of SSL certificates across the enterprise, and recommendations centralizing certificate management throughout their lifecycle.