TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

EBay Platform Exposed to Severe Vulnerability

21 pointsby cyptusover 9 years ago

3 comments

Lazareover 9 years ago
Something about the writing rubbed me the wrong way; seemed very self-promoting and I was prepared to find out the vulnerability was nonsense.<p>...nope. Ebay literally lets you paste arbitrary JS into your item descriptions (suitably mangled, but that&#x27;s not a barrier when there are tools to do it for you), which is then actually executed on client devices. It&#x27;s exactly what it says on the tin; a perfect vector for phishing attacks, malware distribution, etc.
评论 #11024721 未加载
jcrover 9 years ago
There are a few previous discussions on JSFuck:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=3279078" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=3279078</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=6379732" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=6379732</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9479834" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9479834</a>
amar-singhover 9 years ago
Ebay&#x27;s product quality is very good but not customer service. I never noticed this before like JS in item description....