eBay Suspension & PayPal Limited Forums  
Join Today
Register Subscribe
     

Registration is fast, simple and absolutely free so please, join our community today!


Go Back   Home

eBay Suspended & PayPal Limited Forums

eBay Suspended & PayPal Limited Forums (https://www.aspkin.com/forums/)
-   eBay Discussion! (https://www.aspkin.com/forums/ebay-discussion/)
-   -   Warning: Huge eBay Security Flaw (https://www.aspkin.com/forums/ebay-discussion/3641-warning-huge-ebay-security-flaw.html)

imjustme 03-26-2008 10:57 AM

Warning: Huge eBay Security Flaw
 
There seems to be a huge security flaw going on at eBay right now. Before I write this, I have to state that I use Firefox and I *always* clear all cookies, both automatically and manually, when my browser closes AND when it starts up.

I just logged into one of my accounts and found myself logged into another username I have never heard of, but apparently someone who lives in the same city as me, in Japan.

How is that possible? I have no idea, but I was able to check his listings, even edit them (if I wanted to, but I didn't). I could check the closed listings, the customer information, when they paid, etc. I could also see his private address and phone details, even the credit card details (as far as eBay shows).

I only use my computer at home, so I'm not on a public computer that could have had traces of cookies. The only thing I'm thinking it could be is that eBay's cookie system recognized the same IP (I was on dialup) that he used before and logged me into his account based on that.

I then logged off that dialup connection and back in with a different provider that gave me a different IP, then I had no problems getting into my own account fine. I logged back off and on again with the other provider's same IP and again, it logged me into the other eBayer's account, again giving me full access.

I am thinking this is a huge security flaw at eBay that needs to be addressed as soon as possible, but I don't want any attention from eBay to my own account, so I'm not going to be reporting it, at least not from my own account.

Just a heads up, be careful guys! Something is fishy. I worked in the IT industry as a programmer for many years, so I know my way around cookies and servers even if I was blind. Believe me, this is not something on my end. It's on eBay's end and it's a security flaw ...and a bad one. Their cookie system is logging customers into their account based on IPs. That's baaaaaad.

rock45 03-26-2008 12:15 PM

this is shocking...

mantisinc 03-26-2008 12:53 PM

Good grief, that's not good at all.
Shame it didn't log you into a dormant account from '03 =)

jscan 03-27-2008 01:43 AM

thats disgusting, imagine if that happened and some Nigerian scammer got hold if your details. the sooner eBay has a real competitor the better for all of us

aspkin 03-27-2008 09:13 AM

That is pretty bad... is it still happening?

imjustme 03-27-2008 01:05 PM

As of 5 minutes ago, I could still log onto that IP and get logged into his account. He's a quite active seller in the same time zone, so I'm thinking while he's on and I'm using the same IP, I can log in anytime...

Jonas 03-28-2008 03:06 AM

Are you only able to log into that one person's account and nobody else's?


All times are GMT -5. The time now is 10:41 PM.

vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Ad Management by RedTyger


Aspkin Group

All times are GMT -5. The time now is 10:41 PM.


Stop the guessing games and learn how you can quickly and easily get back on eBay today!
Read the best selling step-by-step eBay Suspension guide eBay Stealth!
Amazon Suspension? Read Amazon Ghost to get back on Amazon!
vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Ad Management by RedTyger

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58