Feeds

PayPal post-checkout cash slurp a FEATURE not a BUG

Would you like a super-sized shipping charge with that?

Choosing a cloud hosting partner with confidence

An apparent flaw that lets users add any amount of money onto already processed PayPal transactions is a feature, not a bug, according to the payments giant.

The function was designed to allow sellers to add additional costs for services like shipping on the top of transaction totals which customers had approved through the PayPal website.

Sellers would be expected to add small amounts but TU-Berlin IT student Jan Kechel found PayPal had not limited the amount of cash that could be swindled and sent the company a proof of concept script.

"In PayPal Express Checkout the online shop can transfer any amount, no matter which amount the client actual confirmed at the PayPal website," Kechel said.

"This proof of concept transfers only one Euro more than the confirmed amount, but I also tried with 200 Euros and it works just the same."

PayPal told Vulture South Kechel's bug was more of a shiny button.

"We can confirm that through our Bug Bounty Program a researcher reported a suspected vulnerability with our PayPal Express Checkout," a spokesperson said.

"After looking into the issue, we communicated this is not in fact a vulnerability. We work closely with our merchants who use Express Checkout to provide them the flexibility they need to complete their transactions in a timely manner so they can offer excellent payments experiences to their customers."

The company did not say if it plans to cap the rate or otherwise reduce the potential impact of the fraud. Defrauded customers do have the option of seeking reimbursements from PayPal, which like many banks shells out for fraudulent transactions in the name of consumer confidence.

Customers would be alerted to the scam if they opted for email verification and further bothered to open them as the payment details were contained in the body of the messages.

Last month, former NASA hacker turned white hat Razvan Cernaianu, aka Tinkode, reported a flaw to PayPal's bug bounty team which he said allowed fraudsters to double their money.

The payment giant brushed off the report but did not say how it could prevent one off instances of the scam which involved the funneling of cash to a mule account prior to a dispute claim being lodged. ®

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.