Hacking PayPal Accounts with one click posted December 2014
An interesting 0day on paypal was discolsed by Yasser Ali.
We have found out that an Attacker can obtain the CSRF Auth which can be valid for ALL users, by intercepting the POST request from a page that provide an Auth Token before the Logging-in process, check this page for the magical CSRF Auth “https://www.paypal.com/eg/cgi-bin/webscr?cmd=_send-money”. At this point the attacker Can CSRF “almost” any request on behave of this user.
A CSRF attacks (Cross-Site Request Forgery) happens when you can send a link to someone (or embed it into an iframe on your website) and it makes the user do something on a particular website (like paypal) that he didn't intend to do. Or as the name of the attack says, it makes him send a request you forged from outside the website. A CSRF token is used to cancel this attack. It's usually a random value that is send along the request and verified server side. This value is difficult to predict and thus you usually can't forge it along the request.
Comments
Zita
Hack my sisters wifi, she's a hoe
zITA
I mean PayPal
Diogo Cadete
Good
Alex
Hi I need an paypal account!
Alex
Help!
Wang Fei
I be Wang Fei
Oacar
Hello I wanted to know how I could load money in my account
Nelson
Can I get one
Joe
can i have some money plz lol :p
Josh
can i have an account???
Temitope Michael
Please, how can i contact Yasser Alli? Please reply me through my mail [email protected]
James
HI i would like a paypal account.
Jad
I need $50
Taylor Dewhirst
I wish I knew how to make real cash.
leave a comment...