<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shoestring Theory &#187; scammers</title>
	<atom:link href="http://shoestringtheory.com/tag/scammers/feed/" rel="self" type="application/rss+xml" />
	<link>http://shoestringtheory.com</link>
	<description>Currently documenting the house that is eating our lives, we will return to regularly scheduled programming in a couple of more months</description>
	<lastBuildDate>Sun, 11 Sep 2011 19:25:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>German group demonstrates security flaw in eBay</title>
		<link>http://shoestringtheory.com/2008/03/13/german-group-demonstrates-security-flaw-in-ebay/</link>
		<comments>http://shoestringtheory.com/2008/03/13/german-group-demonstrates-security-flaw-in-ebay/#comments</comments>
		<pubDate>Thu, 13 Mar 2008 21:29:58 +0000</pubDate>
		<dc:creator>thetheorist</dc:creator>
				<category><![CDATA[eBay]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scammers]]></category>

		<guid isPermaLink="false">http://shoestringtheory.com/2008/03/13/german-group-demonstrates-security-flaw-in-ebay/</guid>
		<description><![CDATA[AuctionBytes has an in-depth piece up on a security vulnerability in how eBay handles scripts in auction pages. A German watchdog organization, Falle-Internet.de, demonstrated the exploit this week. The vulnerability allows scammers to capture a wealth of information about an eBay user that visits an auction with the malicious script in it: By loading the [...]]]></description>
			<content:encoded><![CDATA[<p>AuctionBytes has an <a href="http://www.auctionbytes.com/cab/abn/y08/m03/i13/s01">in-depth piece</a> up on a security vulnerability in how eBay handles scripts in auction pages.  A German watchdog organization, Falle-Internet.de, demonstrated the exploit this week.  The vulnerability allows scammers to capture a wealth of information about an eBay user that visits an auction with the malicious script in it:</p>
<blockquote><p>By loading the auction into our browsers, with Javascript and Flash enabled, AuctionBytes was able to see the private information for our account on a separate website page set up by Falle-Internet.de. The information included IP, Name, address, eBay User ID, email address, Bank Routing number, the last 4 digits of our bank account number, the last four numbers of our credit card, and the credit card expiration date. The page also showed auctions that were being watched, as well as saved searches and favorite sellers.</p></blockquote>
<p>eBay, of course, said they had tools in place to stop such activity&#8230;which didn&#8217;t stop Falle-Internet.de from proving that the exploit works with a live auction.  </p>
]]></content:encoded>
			<wfw:commentRss>http://shoestringtheory.com/2008/03/13/german-group-demonstrates-security-flaw-in-ebay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

