Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Popular Web Sites Highly Vulnerable to Attack


Top Poster

Status: Offline
Posts: 3757
Date:
Popular Web Sites Highly Vulnerable to Attack


Popular Web Sites Highly Vulnerable to Attack


A report finds that banking, shopping, and other sites are likely to contain flaws that allow phishing or expose customer data.

Erik Larkin, PC World
Thursday, April 19, 2007 03:00 PM PDT

Eight out of ten Web sites contain common flaws that can allow attackers to steal customer data, create phishing exploits, or craft a variety of other attacks, a security company reported today.

WhiteHat Security regularly scans hundreds of "very popular, very high-traffic sites" for its online business customers, says Jeremiah Grossman, the company's founder. "More than likely, you have shopped there, or bank there," he says. Thirty percent of scanned sites contain an urgent vulnerability, such as one that allows direct access to a company database with customer information, he says.

Two out of three scanned sites have one or more cross-site scripting (XSS) flaws, which take advantage of problems with sites' programming and are increasingly used in phishing attacks. A recent eBay scam used a now-fixed XSS hole on the auction site to direct anyone who clicked on a phony car auction to a phishing site.
Other Risks

About a third of scanned sites are at risk for some sort of information leakage, which often means the providing of programming data about the site that can facilitate an attack. And about one out of four sites allows content spoofing, another potential phishing risk, according to WhiteHat's vulnerability report.

A type of database vulnerability that allows SQL injection attacks--"one of the nastier issues out there"--is becoming less common, Grossman says. Fewer than one out of five sites contain this type of vulnerability, but a successful incident can give a sophisticated attacker access to everything in a company's database, he says.

WhiteHat's report echoes an increasingly common theme, says Ken Dunham, director of VeriSign's iDefense rapid response team. "Web-based attacks are some of the most prevalent attacks in the last two years," he says.
Web 2.0 More Vulnerable

Like any type of software, as Web programming grows more sophisticated and complex, allowing for desktop-like Web 2.0 applications, it also becomes more vulnerable. With Ajax, a common Web 2.0 type of programming, "you can have CSS taking place on a more invisible layer, behind the scenes," Dunham says.

The good news is that site vulnerabilities can be fixed in one central spot, in contrast to desktop software flaws, which persist until every user of the affected software updates it with a fix. And companies are becoming more nimble at identifying and closing risks that can cost them customers, Grossman says.

WhiteHat's report, which is available for download (with site registration), is based on scans performed between January 1, 2006, and March 31, 2007. The company scans those areas of Web sites reached after a customer logs in.


__________________

Exposing the sleazery of ebaY and PayPal

 



Top Poster

Status: Offline
Posts: 3757
Date:

Just posting some related stories here, to show how long ebay has left their issues unresolved.

eBay redirection ruse reloaded

eBay provides backdoor for phishers (February 2005)

Vulnerability Note VU#808921
eBay contains a cross-site scripting vulnerability


And also look at at least one blatant FALSEHOOD

eBay plugs hole in sign-on page

(these screencaps were taken just a few days ago, on Friday the 13th of April, 2007), and posted here originally

Free Image Hosting at www.ImageShack.us



Free Image Hosting at www.ImageShack.us


Free Image Hosting at www.ImageShack.us


How many folks are aware of these serious issue?

Not nearly enough...

Of course the problem is compounded by the LIES, denial, and the ATTEMPTED cover-up.


Should an outfit like this be trusted?

__________________

Exposing the sleazery of ebaY and PayPal

 



Top Poster

Status: Offline
Posts: 745
Date:

I took some preemptive measures long ago to stop this.
Sad we have to go "underground" so as not to telegraph our every move to
Meg Whitman and crew, who love to just "throw it out there on a fly and see if it works"

__________________


Top Poster

Status: Offline
Posts: 3757
Date:

I just wonder how any site can get away with being unsafe for soooo long, without some authoritaive body taking action to protect consumers/surfers.

At some point that must be crime. Negligence. Willful ignorance, whatever...

  But that is OK with me. I have been scammed for the last nickle from ebay, and I am all the much more happy doing whatever I can to alert consumers to the many hazards present there,
in a sworn to fun, loyal to... (nunya) manner!

BWHAHAHAHAHAHA!!!
(insert smileduck pic)

Furthermore, did you catch this abject falsehood in the above article?

"A recent eBay scam used a now-fixed XSS hole on the auction site to direct anyone who clicked on a phony car auction to a phishing site."

Note the date at the very bottom of the article.  They still have holes big enough to drive a Mac truck, (loaded with 263 hookers) through, and I would bet my life on it.

I doubt *anyone* from ebay would do the same for their belief, or rather to back up that statement, because they KNOW it is FALSE.

The proof is right here in screencaps, and all over. Go to Docs ebaymotorssucks.com and companyexposed.com and look around.
 Go over to firemeg.blogspot and read about the crappola they pull.

And it looks to me like maybe Vladuz is a being made a scapegoat. (in hindsight)
Maybe he was trying to warn the world with that captcha extension, ebay  villainized him.
Then they silenced him. 

I wish he would speak out about whatever was going to be revealed via CNN on the Ides of March



__________________

Exposing the sleazery of ebaY and PayPal

 

Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard