eBay plays ostrich

Opinion
Mar 18, 20052 mins

Question: When is a phish not a fish?

Answer: When a phisher uses a real eBay URL to bounce unsuspecting victims to a phishing site.Register published an article on just such a phishing relay that takes advantage of a redirect feature in eBay’s Web pages.

At the end of February, the

From the article:

“Phishers are exploiting a redirection script on eBay’s site to make fraudulent e-mails look more convincing. Three Register readers noticed the trick in scam e-mails they received. Alerted by The Register, e-mail security firm MessageLabs confirmed that it has detected and blocked the same trick a number of times in the last two weeks.

“We have yet to hear back from the online auction house, despite notifying

eBay of a potential problem on Wednesday (23 February) and making several

calls since then.”

Note that eBay’s been closed-lipped about this. That’s been my experience

with them, too. Never comment on something that might reflect poorly on

brand identity. Not that they didn’t have image problems before this. They’ve had a reputation of being shifty and unreachable whenever their customers are in trouble.

For example, when I reported for Computerworld in 2002 on eBay’s fraud detection system running amok and locking eBay users out of the funds in their PayPal accounts, eBay’s PR person told me, “We’re not going to let you talk to any of our executives because we don’t like what you’re writing. So don’t call us anymore.”

Now I read that eBay is doing its guerilla PR tactics again. And I have it on good authority that the right people at eBay have known about the Web application flaw for a year but chose to ignore it until now.

What eBay executives fail to take into account is that word gets around. And

the more eBay and PayPal try to keep it quiet, the more outraged users

become and the more they talk about it in blogs, postings and “I hate eBay”

and “PayPal Sucks” sites.

So I’ll leave you with this BugTraq

posting about eBay’s redirect problem, which appeared two weeks before the Register report.

deb_radcliff

Deb Radcliff is an investigative journalist and analyst focused on computer crime and security. Her work has appeared on Security Boulevard, the SANS Cyber Security Blog, and SC Media, among other outlets. She stood up an analyst program for SANS Institute and ran it for 15 years before joining the Cyber Risk Alliance as strategic analyst on the business intelligence unit. She is author of the popular cyber thriller series, “Breaking Backbones,” available at Amazon.

Deb won two Neal Awards for investigative business reporting. She holds a Bachelor’s degree in journalism from San Jose State University.

More from this author