Hacked by Paypal

Ο “Artsploit” Stepankin, ένας ανεξάρτητος ερευνητής ασφαλείας, ανακάλυψε ένα κρίσιμο ελάττωμα ασφαλείας στην PayPal που του επέτρεψε να εκτελέσει κακόβουλο κώδικα στους servers της εταιρείας. Το γεγονός του επέτρεψε να αποκτήσει τον πλήρη έλεγχο της υποδομής της PayPal.paypal

The security gap starts from various open Java libraries.

The researchers who discovered this flaw, first in Java (before Stepankin applied it to Paypal) also published a tool that automatically generates the malicious code needed to exploit this flaw. s through the Apache Commons Collections Java library.

Stepankin used this tool to create a malicious Java serialized object, which he then used on PayPal. So he discovered that the company's IT failed to protect it.

“I realized that this unsigned Java serialized object could be managed by the ,” Mr. Stepankin said.

"This means you can send the Java serialized object to the server as readObject or as readResolve."

The first malicious with Java that the researcher was able to upload to PayPal's servers was just a simple test.

After finding the evidence Mr Stepankin created a second exploit, much more intrusive. This exploit contained shell commands and was able to access the / etc / passwd file.

Stepankin came in contact with PayPal and informed them of his discovery. Although the company was already aware of the security gap from another security researcher, he thanked the researcher for his discovery and rewarded him with cash.

As Stepankin says, the matter was reported to the company in mid-December and today it has been repaired.

See PoC

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).