Results 1 to 4 of 4

Thread: PayPal Leaking Customer Email Addresses

  1. #1
    Samurai's Avatar Usenet Fanboy
    Join Date
    May 2003
    Location
    London, United Kingdom
    Age
    41
    Posts
    4,333
    Windows enthusiast site, MSFN.org, have highlighted a rather serious problem with PayPal's email removal feature.

    Most emails sent from corporations have "removal" links to comply with anti-spam legislation in the USA. On clicking the link sent out by PayPal, users can remove themselves from future mailings from the company. However, the system used to do this suffers from a lack of proper input validation and security. By changing elements of the URL, a malicious user can reveal other PayPal user's email addresses. The problem exposes a serious flaw in the system.

    The potential for damage is serious; ever inventive spammers already harvest email addresses from websites on a massive scale and it would take only the most basic of tools to gain a large list of PayPal email addresses. Exactly how exposed PayPal have left their users is not yet known. Neowin was able to manually gain the email addresses of 20 users within 5 minutes. Interestingly, although it's possible to unsubscribe a user, PayPal still hold their email address on file. So far, PayPal have not released a fix for the problem, and have not responded to our inquiries.

    PayPal, now owned fully by eBay, have "56 million account members worldwide", and are "available in 45 countries" around the world. PayPal is a member of BBOnline, and TRUSTe, two privacy groups. BBOnline's terms state that member sites "must have appropriate security measures in place to prevent unauthorized electronic access".

    Source: http://www.neowin.net/comments.php?i...&category=main

  2. The Drawing Room   -   #2
    Barbarossa's Avatar mostly harmless
    Join Date
    Jun 2002
    Location
    Over here!
    Posts
    15,180
    PayPal is a mugs game.

  3. The Drawing Room   -   #3
    Harsh!'s Avatar n00b
    Join Date
    Oct 2004
    Location
    New Zealand
    Posts
    415
    Seen this a few days ago at Neowin...
    Paypal is not your "pal"...

  4. The Drawing Room   -   #4
    UcanRock2's Avatar Phantom Gander
    Join Date
    Sep 2003
    Location
    "Out West"
    Age
    61
    Posts
    871
    Never trusted those mothers anyway.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •