ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

EBay closes password option to plug hole

Troy Wolverton CNet

Published: 03 Apr 2002 10:56 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

EBay disabled a password function on its site Tuesday to close a "very serious" security hole that could allow hackers access to users' accounts, a spokesman said.

EBay disabled the "Change Your Password" function in an effort to close the vulnerability, eBay spokesman Kevin Pursglove said Tuesday. That feature will remain disabled until eBay can put a fix in place, he said.

"We don't see (the vulnerability) existing in other features," and no customers have complained, Pursglove said. "From what we can tell right now, we have not seen anybody's account compromised in any way."

Greg Shipley, chief technology officer of security consulting firm Neohapsis, blamed the problem on a "design failure" in eBay's authentication system.

"It's just a bad design. It's kind of disappointing coming from a company the size of eBay," Shipley said.

The vulnerability, discovered by a Canadian security expert and brought to eBay's attention late last week, would allow a person who has the user ID of an account to go in through eBay's "Change Your Password" feature, change a user's password and gain access to the account.

Pursglove said people who potentially exploited the vulnerability would not have been able to see credit card numbers.

"What they can see is the credit card transaction history of a user," Pursglove said, calling the problem "very serious." The credit card numbers, he said, are behind a separate firewall.

While eBay has disabled access to that security hole, the company is still working on a fix for an earlier problem involving so-called dictionary attacks. These attacks utilize a bot, or an automated program, to find passwords for known eBay user IDs by combing though a list of common passwords and a dictionary of words.

EBay has said that the number of accounts compromised by dictionary attacks has been no more than the "low triple digits." The company has also said that less than one one-hundredth of 1 percent of its listings end in confirmed cases of fraud.

"We're working on it right now," Pursglove said, adding that changes to the login procedure would be in place in four to six weeks. "We think it will make it harder for these (attacks) to work."

Security experts have criticised the company's log-in system, saying that because it generally transmits passwords and account information in plain text, it is vulnerable to "packet sniffers," programs that can monitor the transmission of data between computers.

EBay has also repeatedly warned members in recent months about another, more low-tech scam: fraudulent e-mail messages that purport to come from the company but link to bogus Web sites that ask for their passwords or other account information.


For everything Internet-related, from the latest legal and policy-related news, to domain name updates, see ZDNet UK's Internet News Section.

Have your say instantly, and see what others have said. Go to the Telecoms forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
26 out of 61 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Sentry Posts Blog

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Please educate your clients!

This extremely short post appeared following a meeting with a decision maker of a potential client. During the conversation I realized that this highly respected and well paid top manager... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains