TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

EBay under pressure as hacks continue

57 pointsby GotAnyMegadethover 10 years ago

6 comments

ufmaceover 10 years ago
&gt; The vulnerability centres around users&#x27; ability to place custom Javascript and Flash content into their listings pages.<p>Wait, what? Is that true? If so, how could anybody think that allowing the user to place custom Javascript in their listing pages is a good idea in this day and age?
评论 #8354394 未加载
评论 #8351301 未加载
评论 #8353696 未加载
DanBlakeover 10 years ago
Why is eBay not using sandboxed iframes for the auction description&#x2F;content?<p>You dont need JS to make amazing looking listings. Just look at all the customized subreddits with crazy stuff going on utilizing just CSS&#x2F;HTML. All the &#x27;tracking&#x27; needed for ebay listings could easily be done with a pixel as well.
评论 #8351310 未加载
roywigginsover 10 years ago
Does anyone else remember when Flash could execute arbitrary Javascript in the containing page? That was super fun.<p>Attempting to sandbox user-supplied Javascript just seems like an exercise in futility.
评论 #8351588 未加载
Robadobover 10 years ago
The previous bbc article regarding this never stated that ebay allows users to embed javascript and flash into listings. No wonder they are having issues with xss.
评论 #8351289 未加载
yuhongover 10 years ago
Yea, it is funny that PayPal has a security bug bounty program but eBay don&#x27;t. I think you can thank David Marcus and Bill Scott of PayPal for that.
Kenjiover 10 years ago
&quot;When customers clicked on a listing that had been compromised, they were brought to a sophisticated, official-looking site that asked victims to log in and share bank account details.&quot; Please. One glance at the URL (&quot;vip-ohota.com.ua&quot;) and the fact that it&#x27;s not SSL reveals that something fishy is going on. This is very, very basic, even non-tech people should look at the URL when they enter their information. You wouldn&#x27;t tell a stranger your credit card number, you&#x27;d make sure you&#x27;re talking to the right person.
评论 #8351153 未加载
评论 #8351119 未加载
评论 #8350993 未加载