Lupa Kata Sandi? Klik di Sini

atau Masuk melalui

Belum Memiliki Akun Daftar di Sini


atau Daftar melalui

Sudah Memiliki Akun Masuk di Sini

Konfirmasi Email

Kami telah mengirimkan link aktivasi melalui email ke rudihamdani@gmail.com.

Klik link aktivasi dan dapatkan akses membaca 2 artikel gratis non Laput di koran dan Majalah Tempo

Jika Anda tidak menerima email,
Kirimkan Lagi Sekarang

eBay Criticized as Hacks Continue

Translator

Editor

19 October 2018 19:10 WIB

eBay Logo . AP/Ben Margot

TEMPO.CO, Jakarta - Leading security researchers have called on eBay to take immediate action over dangerous listings, as the problem continues to put users at risk, as reported by BBC News.

The BBC has now identified more than 100 listings that had been exploited to trick customers into handing over personal data.

Over the weekend, readers got in touch with the BBC, saying they had attempted to warn eBay about the problem.

The company said it would "continue to review all site features and content".

The BBC has found that innocent user accounts were hijacked in order to place the fake listings. Many of the accounts had 100% positive feedback, and had sold hundreds of items.

One victim who had his account hijacked told the BBC he was locked out of his account - and later billed "around £35" by eBay to cover seller's fees for items he had not auctioned.

When customers clicked on a listing that had been compromised, they were brought to a sophisticated, official-looking site that asked victims to log in and share bank account details.

The types of items used to target victims ranged from smartphones and televisions to hot tubs and clothing.

The vulnerability centres around users' ability to place custom Javascript and Flash content into their listings pages.

Often sellers will use this method to make their pages look more exciting, with animations or other eye-catching techniques.

But use of Javascript and Flash, eBay acknowledged, significantly raised the likelihood that malicious code could be included within the site's pages - due to a hacking technique known as cross-site scripting (XSS).

It meant users clicking on eBay listings that appeared legitimate were being automatically re-directed to harmful websites designed to steal user information, including credit card details.

"The summary is that it is exceptionally dodgy and redirecting the user to a nasty web page with some really suspect scripts," said James Lyne from the security firm Sophos.

"At present we can't get our hands on the end payload, so can't be sure of the attackers complete motive, but it is clear there are still nasty malicious redirects on the eBay site."

The problem has affected the site since at least February, the BBC has confirmed - although some experts say it has been an issue for more than a year.

BBC NEWS | DAVE L | LEO K




Presidential Debate Series: Expert Warns of Rising Cyber Security Threats

3 Januari 2024

Presidential Debate Series: Expert Warns of Rising Cyber Security Threats

The upcoming presidential debate will discuss the theme of "Defense, Security, International Relations, and Geopolitics".


BSSN Deploys Cyber Task Force Ahead of Bali AIS Forum

9 Oktober 2023

BSSN Deploys Cyber Task Force Ahead of Bali AIS Forum

The National Cyber and Encryption Agency (BSSN) deployed a cyber security task force to ensure the implementation of the AIS Forum in Bali.


Today's Top 3 News: Jokowi's Cyber Security Strategy, Indonesia's Plan to Take World Bank Loan

4 Agustus 2023

Today's Top 3 News: Jokowi's Cyber Security Strategy, Indonesia's Plan to Take World Bank Loan

Tempo English compiles three popular news on the platform on Friday, August 4, including Kaspersky's comment on Indonesia's cyber security strategy.


Jokowi's Cyber Security Strategy Strengthens Indonesia Digital Landscape

4 Agustus 2023

Jokowi's Cyber Security Strategy Strengthens Indonesia Digital Landscape

Russian cyber security company Kaspersky comments on Jokowi's Regulation No. 47 of 2023 on the National Cyber Security Strategy.


34 Million Indonesian Passport Data Allegedly Leaked; Kominfo Responds

6 Juli 2023

34 Million Indonesian Passport Data Allegedly Leaked; Kominfo Responds

Kominfo Ministry confirmed that it has been informed about the alleged leak of 34,900,867 Indonesian citizens' passport data.


Indonesia's Digital Economy Growth Projected to Hit Rp3,216tn in 2027: Kadin

19 Juni 2023

Indonesia's Digital Economy Growth Projected to Hit Rp3,216tn in 2027: Kadin

Indonesian Chamber of Commerce and Industry (Kadin) predicted that the country's digital economy growth will reach Rp3,216 trillion in 2027.


BSSN, Huawei Tighten Synergy in Cyber Security Development

16 Juni 2023

BSSN, Huawei Tighten Synergy in Cyber Security Development

Indonesian Cyber and Encryption Agency (BSSN) renewed its MoU with Chinese telecom giant Huawei for cooperation in cyber security.


Data Belonging to Tax DG Leaked, Distributed Freely on Hacking Forum

3 Maret 2023

Data Belonging to Tax DG Leaked, Distributed Freely on Hacking Forum

Data allegedly belonging to the Finance Ministry's Directorate General of Tax were distributed freely on a hacking forum site.


Moeldoko Says Losses Caused by Hackers Hit $6tn

26 Oktober 2022

Moeldoko Says Losses Caused by Hackers Hit $6tn

Presidential Chief of Staff Moeldoko highlights financial losses caused by hackers and scammers in the digital world.


Kaspersky Reveals Web Attacks, Password Thefts Targeting Southeast Asian MSME

17 Oktober 2022

Kaspersky Reveals Web Attacks, Password Thefts Targeting Southeast Asian MSME

Russian cybersecurity company Kaspersky revealed malicious activities targeting MSMEs in Southeast Asia during the first half of 2022.