News

Bug in PayPal Renders Two-Factor Authorization Useless

Security blogger Joshua Rogers of Melbourne wrote a piece about PayPal’s two -factor authorization system at the beginning of June and discovered a pretty concerning bug in it. Anyone with it enabled, would be able to access the PayPal account by using a special login page designed for eBay.

Like any responsible person, he informed PayPal about the issue right away instead of publishing it. The exploit still works 2 month later despite his warnings, so he decided to go public with it now.

eBay’s function to link a PayPal account is the culprit here. When you’re setting up this service and are entering your login details, a cookie is set with your details and you’re redirected to confirm it. Once logged in that way, just go to the main PayPal page and you’re also logged in there. eBay’s special login page completely ignores any two-way factor authorization settings.

Joshua wrote that he could repeat the process unlimited times and even created a YouTube video demonstrating it.

Thank you Just Another Security Blog for providing us with this information

Image courtesy of PayPal

Bohs Hansen

Disqus Comments Loading...

Recent Posts

Gray Zone Warfare Has Sold Half a Million Copies in 4 Days

MADFINER Games is a globally recognised Czech independent game studio that has recently released a…

15 hours ago

NVIDIA GeForce NOW Gets Improved Support for Steam Deck and 25 New Games

Are you a fan of GeForce NOW? Well, if you are, or if you're still…

15 hours ago

Upcoming Helldivers Warbond Is Filled With Lots of Fun Gear

The next Helldivers 2 warbond is coming and recently Arrow Head Studios have revealed what…

15 hours ago

Varmilo VEA109 Moonlight Gaming Keyboard, MX-Red, White-LED

110% mechanical keyboard with 109 keys in a UK ISO layout V-silk PBT keycaps with…

17 hours ago

HGC Osmi 3.1 Aluminium Mini-ITX Case – Black

Recent years have seen Small Form Factor (SFF) PCs become increasingly popular. Obviously they are…

17 hours ago

Next Level Racing Go Kart Cockpit Racing Simulator

Introducing the Next Level Racing® Go Kart Plus cockpit, designed for the whole family to…

17 hours ago