Top 10 winner
Hacking PayPal Accounts with 1 Click
Yasser Ali's Blog » Hacking PayPal Accounts with one click (Patched)
PayPal's anti-CSRF Auth token turned out to be reusable, and a valid one could be picked up before logging in from the send-money page, making it usable against any account. Paired with a security-question setup request that was not password protected, one click on an attacker page could reset the victim's security answers, email and payment details and take the account over.
Record
- Document
- Yasser Ali's Blog » Hacking PayPal Accounts with one click (Patched)
- Researcher
- Yasser Ali
- Published by
- yasserali.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yasser Ali, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .