Latest in Ebay

Image credit:

Watch out: eBay vulnerability leads to phishing log-in page

28 Shares
Share
Tweet
Share
Save

Sponsored Links

Thinking about picking up a used iPhone on eBay? Shop carefully, friends: it's apparently phishing season. The BBC is reporting some auction listings are redirecting to counterfeit eBay login pages -- fronts for phishing scams designed to steal customer usernames and credit card information. The good news is that eBay isn't technically hacked. The online marketplace allows sellers to use scripting to gussy up item listings. Cross-site scripting is generally not allowed, but these scammers are doing it anyway.

"Cross site scripting is not allowed on eBay and we have a range of security features designed to detect and then remove listings containing malicious code," eBay told Engadget. Even so, the BBC says it was able to identify 64 malicious listings from the last 15 days. All those auctions have been removed, of course, and eBay says it is actively seeking out and removing these kinds of listings. Still, better safe than sorry: if eBay is asking you to log in at an erroneous time, double check your address bar to make sure you haven't been mysteriously redirected.

Source: BBC
In this article: ebay, passwords, phishing, scam
All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
28 Shares
Share
Tweet
Share
Save
Comments

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr