Welcome to Spyware Removal News

PayPal Closes a Phishing Vulnerability


It looks like the PayPal login page, but some things are off. For one, the title is "Login - PayPal Phishing Proof of Concept". That is because this isn't the PayPal login page at all, but a Phishing proof of concept. It was hosted on PayPal's servers and secured with PayPal's security certificates, but I had complete control over all the HTML, including where the login form sent usernames and passwords. This page would not have been caught by any of today's anti-phishing programs, because thanks to a vulnerability, PayPal itself was serving this page.


Thankfully, the people we contacted at PayPal were responsive and the vulnerability was resolved within minutes. To our knowledge, their quick action prevented any customers from coming to harm as a result of this vulnerability, and we applaud their speedy and responsible action on this issue. It serves as a reminder, however, of the importance of secure development when web sites are being brought online, and the importance of speedy reaction when vulnerabilities are discovered. PayPal Closes a Phishing Vulnerability - CA Security Advisor Research Blog - CA





20% off PC Tools Spyware Doctor
20% off PC Tools Spyware Doctor Offer Expires 06/30/08

Coupon Code: pctools20
Please Visit our Home Page

Home

More Spyware Removal News