728_header.jpg (23748 bytes)
Google  Web AuctionBytes  

Home
Subscribe
Blog
Letters to Editor
EcommerceBytes
Podcasts
Forums
Merchant Directory
PR Service  
AuctionBytes TV
ABU Back Issues

Sponsor

COOL TOOLS

Calendar
eBay Fee Calculator
Collectors' Links
eBay Promo History
Bookshelf
Fraud Resources
Auction Site Fees
Auction Management
Payment Services
Storefronts Chart
Sniping Chart
Email List Hosting
Consignment Services
Drop-Off Store Laws
Ecommerce Resources
Photo Tips
Marketing Inserts
Yellow Pages
Classifieds

AUCTIONBYTES

Our Writers
Write For Us
Partners
Press
Advertising
About Us
Link To Us

150ab1.jpg 150ab2.jpg 150ab3.jpg

Auctionbytes-NewsFlash, Number 1170 - December 12, 2005 - ISSN 1539-5065      Previous Story | | Next Story

Mercury News Reports Security Vulnerability in eBay Listings
By Ina Steiner
AuctionBytes.com
December 12, 2005
Reading AuctionBytes: Mercury News Reports Security Vulnerability in eBay Listings

The San Jose Mercury News newspaper reported Saturday that scammers are using eBay listings to redirect people to hoax sites and install viruses on their computers (http://www.mercurynews.com/mld/mercurynews/business/technology/13376864.htm).

Reporter Michael Bazeley said when eBay users clicked on the listing titles, their Web browser was immediately redirected to the fraudulent log-in page and appeared to download a virus onto users' computers.

The technique apparently works using malicious JavaScript code in listings, something that eBay said it automatically scans for, but may have "sneaked past the screening process" in these cases.

It's similar to a problem reported by an AuctionBytes reader in November involving a member-to-member email. The seller logged in to her "My eBay" account to read a "Question from eBay Member" email. She said, "When I opened the message in My Messages in My eBay, it launched/triggered a script that created a phony eBay login page (like the kind you get when you have been idle too long). The font and layout was off just enough to make me look at the URL and see that it was a phish."

At the time, eBay spokesperson said that Member to Member emails, including Question from eBay Member, do not allow people to put either html or javascript into emails, but had not addressed the specific case (http://auctionbytes.com/cab/abu/y205/m11/abu0155/s06).


You may quote up to 200 words of any article on the condition that you attribute the article to AuctionBytes.com and either link to the original article or to www.AuctionBytes.com.
All other use is prohibited.
Email this story to a friend.


AddThis Social Bookmark Button
Previous Story | | Next Story

Related Stories



Discuss this story in our forums.

Site Index
Copyright 1999-2009. Steiner Associates LLC. All rights reserved. Privacy Policy.