On mySimon: Just Keep Swimming
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jun 16, 2006 11:12:00 PM

PayPal has fixed a flaw in its Web site to block a sophisticated scam designed to obtain sensitive data from members, the payment service said Friday.

By exploiting the flaw, attackers were able to redirect people from a PayPal Web page to an online trap located in South Korea, a representative for the service said. The page actually has a real PayPal URL, but hosts malicious code that presents a message warning members that their account had been compromised. It then redirects them to a "phishing" Web site.

At the malicious, information-thieving Web site, people are asked for their PayPal login information, experts at Netcraft, an Internet monitoring company in England, said in an advisory. Subsequently, the scammers are urged to enter their Social Security number and credit card details, Netcraft said.

"As soon as we became aware of this scheme, we changed some of the code on the PayPal Web site. So this scheme, or any scheme like it, can no longer be effective," Amanda Pires, a PayPal spokeswoman, said in an interview.

PayPal, a unit of online auctioneer eBay, is working with the Internet service provider that hosts the malicious site to get it shut down, Pires added. The company has no information on how many people may have fallen victim to the scam, she said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 5 Talkback(s)
The phishing sites are so obvious
The message that I got was so riddled with grammatical errors charactaristic of speakers of asiatic languages, that it is inconceiveable for me that anyone could fall prey to it. Doesn't anyone read ... (Read the rest)
Posted by: nhf7170 Posted on: 06/19/06 You are currently: a Guest | | Terms of Use
Punishing Phishing Website Hosts  alanmcrae@... | 06/17/06
phishing and also spam.  wnij. | 06/19/06
PayPal phishing hole  rmarsha**3 | 06/17/06
Blacklist Spammers' ISPs  Hsbarney@... | 06/17/06
The phishing sites are so obvious  nhf7170 | 06/19/06

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here