Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

PayPal pays $10,000 to discoverer of massive security flaw (+video)

NavyRet

Yes, that's really me
V I P
DW Legend
Joined
Jan 1, 1970
Messages
973,885
Reaction score
8,399
Points
201
Loc
The Pegasus Galaxy
An Egyptian security researcher has scooped the top payout for security bugs from PayPal for discovering a massive security flaw that exposed the accounts of over 150 million users.

Yasser Ali was able to get around PayPal's CSRF Prevention System and capture an authentication token that could be used to effect a customer's PayPal account. You could add, remove or confirm e-mail addresses, add fully privileged users to a business account, change security questions, billing info, shipping info, payment methods and so on.

He disclosed the bug to PayPal and received the firms top award incentive for bug hunters, pocketing $10,000 for his work.

He also detailed how he beat PayPal's security systems on his blog, and provided this proof of concept video.
Code:
https://www.youtube.com/watch?feature=player_embedded&v=KoFFayw58ZQ
More Here:
Code:
http://www.afterdawn.com/news/article.cfm/2014/12/07/paypal-pays-10-000-to-discoverer-of-massive-security-flaw?utm_source=newsletterENG&utm_medium=email&utm_campaign=20141209
 
The number of bugs in any sophisticated software or security arrangement is infinite and remains constant no matter how many you have removed, while patching one creates at least one more which is harder to find. Too many words. Katz has put it more succinctly:

Debugging is the replacement of old bugs by new ones. (Katzenfreund)
 
Back
Top