Jun 20, 2006 : PayPal Deals with Security Flaw
📅 - E-commerce site PayPal (paypal.com) faced a security flaw on Friday as the Web site was exploited by fraudsters looking to steal credit card numbers and other personal information belonging to PayPal users, according to data from research and analysis firm Netcraft (netcraft.com).
Netcraft says the scammers tricked users into accessing a URL hosted on the genuine PayPal site. The URL used SSL to encrypt information transmitted to and from the site and a valid 256-bit SSL certificate was presented to confirm that the site belonged to PayPal. When the victims went on the PayPal page, they were presented with a message that said, "Your account is currently disabled because we think it has been accessed by a third party. You will now be re-directed to Resolution Center." They were promptly led to an external server in Korea, which presented a fake PayPal Member log-in page used to get information like social security numbers, credit card information and ATM PIN numbers from the unsuspecting visitors. PayPal has currently addressed the vulnerability and says it is working with the Korean Internet service provider that hosts the malicious site to get it shut down. PayPal doesn't know how many people have fallen victim to the scam.
Netcraft says the scammers tricked users into accessing a URL hosted on the genuine PayPal site. The URL used SSL to encrypt information transmitted to and from the site and a valid 256-bit SSL certificate was presented to confirm that the site belonged to PayPal. When the victims went on the PayPal page, they were presented with a message that said, "Your account is currently disabled because we think it has been accessed by a third party. You will now be re-directed to Resolution Center." They were promptly led to an external server in Korea, which presented a fake PayPal Member log-in page used to get information like social security numbers, credit card information and ATM PIN numbers from the unsuspecting visitors. PayPal has currently addressed the vulnerability and says it is working with the Korean Internet service provider that hosts the malicious site to get it shut down. PayPal doesn't know how many people have fallen victim to the scam.
Reads: 1901 | Category: General | Source: TheWHIR : Web Host Industry Reviews
URL source: http://www.thewhir.com/marketwatch/062006_PayPal_Deals_With_Security_Flaw.cfm
Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!
📅 -