[13946] in bugtraq

home help back first fref pref prev next nref lref last post

Re: ebay sends passwords in the clear

daemon@ATHENA.MIT.EDU (Andrew Bennett)
Mon Feb 21 16:31:32 2000

Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Message-Id:  <4.2.0.58.20000220015041.00be1790@mail.cruzio.com>
Date:         Sun, 20 Feb 2000 02:00:04 -0800
Reply-To: Andrew Bennett <abennett@CRUZIO.COM>
From: Andrew Bennett <abennett@CRUZIO.COM>
X-To:         BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <200002161903.LAA12086@relay.EECS.Berkeley.EDU>

At 11:03 AM 2/16/00 -0800, rfromm@cs.berkeley.eduwrote:
>I've been trying to get ebay to do something about this for a month and a
>half, to no avail.  See http://avocado.dhs.org/ebpd/ for details, including an
>ebay password sniffer.

I noticed that ebay has a link on their Sign In feature page to sign in via
SSL.  It's not the most obvious link.  An easy way to get there:

- when prompted for your id/password, below the box, click the Sign In link
- when prompted again for your id/password, below the box, click the 'here'
link

Of course, take note of the cookie that they will place on your
computer.  You'll have to close your browser, or it will expire in 40
minutes of inactivity, whichever comes first, according to the web page.

Couple this with the 'my ebay' preferences as to what activities you want
your password remembered, one might only have to enter their password once,
during the SSL session where the cookie gets set.


Andrew
--
   Andrew Bennett
   abennett@cruzio.com

home help back first fref pref prev next nref lref last post