Feeds

Vuln exposes eBay developer accounts

Password changes ordered

Intelligent flash storage arrays

eBay security officials are requiring members of its developer program to change their passwords following the discovery of a vulnerability that could allow attackers to intercept sensitive account details.

"eBay has recently identified a means by which someone could gain access to eBay Developers Program account information," Kumar Kandaswamy, manager of the eBay Developers Program, wrote in an advisory posted on the auctioneer's website. "Out of an abundance of caution and to help ensure the security of the eBay Developers Program, we are requiring that all developers" change their passwords.

The vulnerability doesn't allow attackers to capture financial data such as credit card numbers and so far there are no known exploits targeting it. Kandaswamy didn't elaborate on on the weakness.

Over a several-month span in 2007, a hacker who called himself Vladuz was able to penetrate some eBay defenses and gain unauthorized access to parts of its network reserved for employees. The online miscreant, who was fond of bragging about his exploits on eBay chat boards, was later arrested in Romania, where he is believed to have resided.

eBay's developer program helps developers use its API to write applications for the site. The site recently imposed stricter standards on members when creating passwords. Just last week, security guru Bruce Schneier issued this refresher on the secure creation of passwords. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.