Press release
Auctionbytes.com uncovers Paypal security flaw
Natick, Massachusetts - March 25, 2006 - AuctionBytes ( http://www.auctionbytes.com ) today reported a major security flaw on PayPal's website could help scammers who send out "phishing" emails by allowing them to determine a PayPal member's full name and include it in hoax emails, giving them an air of legitimacy.AuctionBytes discovered the URL with the vulnerability on Friday evening when it was sent in by an anonymous user who stated he was told the security hole had been in place for about 1 year and that many scammers were aware of its existence. Adding a PayPal member's email address to the end of that specific PayPal URL ( https://www.paypal.com/affil/pal= ) caused a box to appear with that member's full name. Entering an email address of a non-member brought up an error message. There was no need to log into PayPal to access that URL, and it isn't clear what the page was designed to accomplish.
PayPal tells its users to expect official PayPal emails to contain their names in the body of the email. Phishing emails that include a person's correct name that corresponds to their email address could fool the recipients into believing the email is actually from PayPal. Phishing emails are sent to trick people into revealing financial information and/or account passwords. AuctionBytes began reporting on hoax emails targeting PayPal in June of 2002 ( http://auctionbytes.com/cab/abn/y02/m06/i27/s03 ). Since then, phishing attacks have become a serious problem for PayPal and eBay members as the emails get more sophisticated and attackers prey on unsuspecting users.
In PayPal's tips called "Protect Yourself from Fraudulent Emails" in a section titled "Please use the following tips to stay safe with PayPal," it states: "Greeting: Emails from PayPal will address you by your first and last name or the business name associated with your PayPal account. Fraudulent emails often include the salutation "Dear PayPal User" or "Dear PayPal Member".
A graphic of a screenshot of the page that comes up after entering eBay CEO Meg Whitman's email address, meg@ebay.com can be viewed on the Auctionbytes.com Web site ( http://www.auctionbytes.com/cab/abn/y06/m03/i24/s00 ). A test by AuctionBytes of 30 email addresses brought back real names of over 25 PayPal users.
PayPal has a section of its site devoted to educating members about security issues at http://www.paypal.com/cgi-bin/webscr?cmd=_security-center-outside , and eBay has a section about Marketplace Safety on its site at http://pages.ebay.com/securitycenter/mrkt_safety.html that includes a tutorial about spoof emails. eBay also recommends that PayPal and eBay members use its toolbar, which can detect when a user is visiting a valid PayPal or eBay site.
A PayPal spokesperson called the vulnerability a bug, and by late on Friday the URL redirected to PayPal's homepage.
About AuctionBytes
AuctionBytes launched in 1999 and is the leading publisher and number one source of news for the online-auction industry. AuctionBytes publishes two free email newsletters and the AuctionBytes Web site, which provides resources for auction buyers and sellers, including "Cool Tools" and Discussion Forums. AuctionBytes publishers David and Ina Steiner are frequently quoted by major news organizations about eBay, online trading and Internet fraud including such publications as Wall Street Journal, New York Times, Smart Money Magazine, and Fortune Small Business and have appeared on major television networks including CNN and CNBC.
For More Information Contact:
David Steiner
Email - dsteiner@auctionbytes.com
Phone - 1-508-655-5697
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release Auctionbytes.com uncovers Paypal security flaw here
News-ID: 6851 • Views: …
More Releases from Auctionbytes.com

AuctionBytes Report on eBay Data Hits Nerve with Sellers
Natick, Massachusetts -- July 03, 2007-- AuctionBytes (auctionbytes.com) today released a report that examined buyer and seller metrics on eBay.com and revealed problems on the US site that began in the first quarter of 2006 that have yet to improve. The report titled "Data Points to Problems on eBay.com" examined industry-wide Alexa rankings, Medved's eBay.com listing numbers and Nielsen/Netratings data on average time spent on eBay.com.
Nielsen/NetRatings shows that eBay users…
More Releases for PayPal
DoJiggy Integrates Fundraising Platform with PayPal
July 24, 2024 - This new integration allows organizations to add PayPal as a payment processing option on the DoJiggy fundraising platform.
Boulder, CO - DoJiggy, an industry-leading fundraising platform, has added PayPal as a payment processing option for campaign organizers. This collaboration simplifies donation collection, enhances the donor experience, and offers a trusted and comprehensive solution for accepting payments online.
The integration with PayPal is built into the…
Alternative Payment Solution: PayPal By Braintree, Venmo, Visa, PayPal, Masterca …
PayPal is one of the largest payment service providers globally. It enables digital payments and offers acceptance solutions for consumers and merchants. The company specializes in online payments, mobile and e-commerce, fund transfers, and payment processing. It has expanded its capabilities through the acquisitions of Zong, Paydiant, CyActive, Modest, Braintree, Xoom, Swift Financial, and TIO Networks.
Founded in 1998 in the US, PayPal is now available in more than 200 markets,…
Global Bluetooth Beacons Market 2018 - Estimote, PayPal, Gimbal
Eminent Market, recently published a detailed market research study focused on the “Bluetooth Beacons Market” across the global, regional and country level. The report provides 360° analysis of “Bluetooth Beacons Market” from view of manufacturers, regions, product types and end industries. The research report analyses and provides the historical data along with current performance of the global PP Pipe industry, and estimates the future trend of Bluetooth Beacons on the…
Alternative Payment Solution: PayPal
ReportsWorldwide has announced the addition of a new report title Alternative Payment Solution: PayPal to its growing collection of premium market research reports.
In terms of transaction value, PayPal is the second-largest alternative payments service provider globally, after Alipay. It enables digital payments and offers acceptance solutions for consumers and merchants. The company specializes in online payments, mobile and e-commerce, fund transfers, payment processing, payment security and monetization services for developers.…
Victoria Plumb Introduces PayPal Payments
Hull, United Kingdom (21 June, 2011) - Victoria Plumb, a leading UK online luxury retailer of bathroom furniture and accessories, announce that from 7th June 2011 they will be introducing PayPal payments on their website.
Victoria Plumb is passionate about designer bathroom furniture which can cater to both modern and traditional homes. Victoria Plumb continually strive to provide their customers with the finest bathroom furniture ranges on the market, which…
Carat wins £2m PayPal media account
Carat has been appointed in the UK to handle the £2m media strategy, planning and buying requirements across all on- and off-line media for PayPal, the online payment platform.
PayPal is a platform providing a secure online payment method, which can be used for payment at thousands of online retailers, without sharing any financial information with them.
Carat, who pitched successfully against a number of undisclosed agencies, will develop a multiple…