728_header.jpg (23748 bytes)
Google  Web AuctionBytes  

Home
Subscribe
Blog
Podcasts
Forums
AuctionBytes TV
ABU Back Issues

Sponsor

COOL TOOLS

Calendar
eBay Fee Calculator
Collectors' Links
eBay Promo History
Bookshelf
Fraud Resources
Auction Site Fees
Auction Management
Payment Services
Storefronts Chart
Sniping Chart
Email List Hosting
Consignment Services
Drop-Off Store Laws
Ecommerce Resources
Photo Tips
Marketing Inserts
Yellow Pages
Classifieds

AUCTIONBYTES

Our Writers
Write For Us
Partners
Press
Advertising
About Us
Link To Us

Auctionbytes-NewsFlash, Number 861 - October 04, 2004 - ISSN 1539-5065      | Next Story

eBay Germany Reacts to Security Flaw Report
By Ina Steiner
AuctionBytes.com
October 04, 2004
AddThis Social Bookmark Button

eBay Germany modified its policy on the use of Javascript after a German TV news show reported a security flaw on the site. Sat1 reported in late September that a computer hacker found and reported the security flaw to eBay over a year ago.

AuctionBytes contacted eBay on September 28 after the show aired. eBay spokesperson Hani Durzy said there have been no hacks into the eBay database, and believed the reports referenced a Javascript or active content vulnerability.

Durzy said that theoretically someone could place Javascript in an eBay listing so when a visitor clicks on the bid button, they are taken to a non-eBay site without their knowledge. Durzy said "while technically it is possible to do, we rarely, if ever, see it in the site."

"We have developed technology to let us look at the site for malicious code," Durzy said, "although it's not 100 percent perfect. The potential has always been there, but we've not heard of it affecting any eBay users."

Durzy advised eBay members to use the eBay Toolbar, which has a feature that indicates whether users are on the eBay site or not, and to use up-to-date anti-virus software.

The U.S. Computer Emergency Readiness Team Web site explains that "A popular type of attack that relies on JavaScript involves redirecting users from a legitimate web site to a malicious one that may download viruses or collect personal information." (http://www.us-cert.gov/cas/tips/ST04-012.html)

eBay Germany changed its policy surrounding the use of Javascript in auction listings on Friday, October 1. eBay Germany recently made headlines regarding security issues when a German teenager allegedly redirected certain parts of the eBay Germany site to a different domain name server.

German-language Heise On-Line has also been following the story (http://www.heise.de/security/news/meldung/51511).

http://www2.ebay.com/aw/de/20041001143658.html

Mark O'Neill contributed to this article.


Email this story to a friend.

| Next Story

Related Stories
  • eBay Begins Rollout of New Sign-In Function - December 11, 2003, Issue #664



  • Discuss this story in our forums.

    Ecommerce Podcasts

    Site Index
    Copyright 1999-2008. Steiner Associates LLC. All rights reserved