Quantcast

How to Avoid Falling Into the Phishing Hole

A cross-site scripting scam on eBay highlights how easy it is to get fooled. We show you what to look out for.

Tom Spring, PC World

  • 0 Yes
  • 0 No

You never can defend yourself too much while online.

A PC World reader alerted me to a flaw on eBay's Web site that enabled a scam designed to trick people into handing over their personal information. eBay promptly patched the flaw last week, but experts I spoke with are wondering how long the fix will hold.

The flaw allowed a scammer to use an increasingly common type of attack called cross-site scripting, or XSS, to redirect people from an eBay listing to a spoofed eBay site. Though eBay may have plugged the hole for now, experts say, similar problems have surfaced in the past on eBay and other sites, and it's a safe bet they will again. The problem is not going away, and it will continue to cause visitors to eBay and other sites trouble for the foreseeable future.

How It Worked

Click to view an image of the spoofed site.On a tip from a PC World reader, I reviewed the scam before eBay canceled the auction that it keyed to. Once potential victims were taken to the fake, or spoofed, eBay site, anyone interested in the item in the auction--a 1961 Volkswagen Microbus--was encouraged to e-mail the scammer directly at 4naffairs@yahoo.com to proceed with the sale.

According to security experts, such attacks are a very common and effective way of tricking Internet users into visiting fake sites.

"Any site that accepts user-generated content has likely had to patch their site for this flaw," says Bill Pennington, vice president of services at WhiteHat Security. Pennington says his company finds nearly 600 instances of cross-site scripting flaws on the Web every day.

Can the Vulnerability Be Fixed?

For eBay's part, it says that it constantly monitors its site for security problems and corrects them as quickly as they are found. "As soon as we became aware of this scheme, we changed some of the code on our site. So this scheme, and ones like it, can no longer be effective," says Nichola Sharpe, an eBay spokesperson.

And eBay is far from alone when it comes to being a target of this type of attack. Similar attacks on major sites like Amazon.com, MySpace.com, Verisign, and even the United States National Security Agency's Web site have been documented.

Security experts say cross-site scripting is part of doing business on the Internet. "There is no one fix [for Web sites] to solve this problem," says Ken Dunham, security expert with VeriSign iDefense Security Intelligence Service. He says finding and patching cross-scripting flaws is like a game of Whack-A-Mole, with new flaws popping up all the time.

In the example found on eBay, the cross-site scripting exploit first inserted malicious JavaScript code into the auction listing description. Next, when users visited the rigged eBay auction, the JavaScript directed the users' Internet Explorer or Firefox browser to instantaneously forward the users to a spoofed Web page that looked exactly like an eBay auction page.

eBay says it now prevents JavaScript on its site from forwarding visitors to third-party sites automatically. However, experts say, hackers can easily modify JavaScript code to once again trigger the same behavior.

  • Recommend this story?
  • 0 Yes
    0 No

"How to Avoid Falling Into the Phishing Hole" Comments

With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.

Related Security Articles

  • Mac Security Focus: Antivirus Although Apple computers are not somehow magically immune to viruses and other malware, they've been remarkably free of such...
  • On The Defensive Lock up employee data, or face the consequences.
  • Unscramble This Encrypting data can save you lots of heartache. How should you do it?
  • 5 Ways to Foil Hackers Are you the only you out there? When it comes to protecting your identity, a bit of prevention is worth a megabyte of cure.
  • Mac Security Focus: Firewalls Firewalls monitor and regulate the data moving on and off your computer or network. They can keep criminals out while allowing...
  • HP LaserJet Printers Satisfy your needs by combining fax, copy and scan capabilities with high-quality laser printing. Visit the Resource Center for more info...
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...
  • CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)