PayPal.com XSS Vulnerability
71–79 of 79 posts
Re: PayPal.com XSS Vulnerability
#72On a sidenote, does anyone have a good setup for browsing securely to avoid issues like this? I ran with JS restricted to a whitelist for a while, but many random websites that I have to use require it these days. Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?
I suppose it might be useful with a browser extension/feature that allowed you to lock access to certain site's cookies until you have explicitly granted use. Sort of like how the keychain works on os x.
Re: PayPal.com XSS Vulnerability
#73PayPal should have put the reward into a trust for them for a year if there were legal issues. Kudos for them being honest with both the bug and their age regardless. The future is probably filled with teenagers discovering things, good and bad. Teenagers are still prosecuted as adults but legally treated as less for other responsibilities.
* a 12 years old found a stack overflow bug in firefox's document.write, in 2010: http://www.mercurynews.com/san-jose-neighborhoods/ci_1640189... (https://news.ycombinator.com/item?id=1822117)
* "Pinkie Pie" is an anonymous teenager, he won $60k at Pwnium, and did it again at Pwnium 2
* @CimStordal, 15 (at the time), found XSS in Facebook, Apple, Google and Microsoft sites: http://www.internet-security.ca/internet-security-news-archi...
Tech has always been filled with teenagers discovering things, now more than ever. Most bounty handlers treat them as valued contributors, Paypal — as usual — shits all over everything.
Re: PayPal.com XSS Vulnerability
#74Earlier quoted context omitted.
This choice should be considered a career limiting decision by any hiring manager. Are you saying that you're holding a 17 year old student in Germany responsible for not understanding US labor laws?
It makes me angry, but the law here in the US is that "ignorance is not a defense." Oh... you didn't know our several million laws when you broke one? Too bad, they say. Lawyers counter that if the law was simpler, they wouldn't have jobs.
Re: PayPal.com XSS Vulnerability
#75(From memory, he also took a few photos of it also).
Would be interested to hear your response as it might give this another angle entirely, haha.
My personal experience with PayPal isn't particularly great, I'm a security researcher who's just turned 18, and even when I was underage I never actually disclosed that but regardless I had the following knocked back;
(Whole heap of non-critical XSS's, and two critical stored ones, The ability to edit titles on some PayPal subdomains (without giving too much information out) - This vulnerability still exists but I was told it was quote "not serious" even though the title field was vulnerable to stored XSS.
Full path disclosures, open administrative panels, whole variety of cookie/SSL/TSL based issues which I was told did not warrant a bounty.
Also had a personal friend (the same guy who found the XSS you've posted here) find a couple SQLi's on a few PayPal domains (post-auth) and he still hasn't heard back from them.
I'm not going to be the guy to accuse PayPal of not playing fair here, but my friend has also reported vulnerabilities I had previously reported and gotten paid for them. (Might be because he reports them from his security company email, whereas I was reporting them as an individual).
Anyway, Sad to hear you didn't get a bounty!
Also, if you don't have it here's a pretty good bug bounty list; http://bugcrowd.com/list-of-bug-bounty-programs/
Re: PayPal.com XSS Vulnerability
#76Re: PayPal.com XSS Vulnerability
#77Earlier quoted context omitted.
The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.
They didn't have to pay him. Still very poorly handled. Should've gone something like: 1. "Hey, that's awesome that you found that, thanks!" 2. "For very good reasons (a), (b) and (c) we can't actually pay you, that really sucks :(" 3. "But hey we like your style, so how about we fly you over for an internship when you've finished school / investigate if Germany has different rules / look at scholorship options and a…
Re: PayPal.com XSS Vulnerability
#78Earlier quoted context omitted.
The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.
"This choice should be considered a career limiting decision by any hiring manager." Hopefully not forever. When I was young and stupid and the net was a much simpler place I casually fully disclosed the problem with posting your Cisco configs with "encrypted" passwords to Usenet: https://groups.google.com/d/msg/comp.dcom.sys.cisco/WjuKAOQL... I would not do something like this today, especially not in such a full-of…
who knew people were saving stuff back in 94-95. hell anyway 18 year old me didn't care, but luckily I can cover for him.
Re: PayPal.com XSS Vulnerability
#79Earlier quoted context omitted.
It makes me angry, but the law here in the US is that "ignorance is not a defense." Oh... you didn't know our several million laws when you broke one? Too bad, they say. Lawyers counter that if the law was simpler, they wouldn't have jobs.
Ok. Now if only the kid actually was over there in the US.
You make it sound like if you hacked into Paypal from Germany you'd be completely immune to American law on the matter because you're not in the US.
That's simply not true.