Live data from Hacker News

PayPal.com XSS Vulnerability

seclists.org

71–79 of 79 posts

Re: PayPal.com XSS Vulnerability

#72
post #51

On a sidenote, does anyone have a good setup for browsing securely to avoid issues like this? I ran with JS restricted to a whitelist for a while, but many random websites that I have to use require it these days. Can you use something like Ghostery to allow any site to do its own JS but not external JS, besides whitelisted sites/externals?

Run your browser in private mode, or create a separate user account and run the browser under that. Or just use a different browser for the "secure stuff" (E.g. your online banking etc.). Then it doesn't matter what kind of xss trickery they throw at you, cause your cookies aren't accessible to the browser.

I suppose it might be useful with a browser extension/feature that allowed you to lock access to certain site's cookies until you have explicitly granted use. Sort of like how the keychain works on os x.

Re: PayPal.com XSS Vulnerability

#73
post #69

PayPal should have put the reward into a trust for them for a year if there were legal issues. Kudos for them being honest with both the bug and their age regardless. The future is probably filled with teenagers discovering things, good and bad. Teenagers are still prosecuted as adults but legally treated as less for other responsibilities.

As x9k noted on /r/netsec (http://www.reddit.com/r/netsec/comments/1f3bt1/17_years_old_...)

* a 12 years old found a stack overflow bug in firefox's document.write, in 2010: http://www.mercurynews.com/san-jose-neighborhoods/ci_1640189... (https://news.ycombinator.com/item?id=1822117)

* "Pinkie Pie" is an anonymous teenager, he won $60k at Pwnium, and did it again at Pwnium 2

* @CimStordal, 15 (at the time), found XSS in Facebook, Apple, Google and Microsoft sites: http://www.internet-security.ca/internet-security-news-archi...

Tech has always been filled with teenagers discovering things, now more than ever. Most bounty handlers treat them as valued contributors, Paypal — as usual — shits all over everything.

Re: PayPal.com XSS Vulnerability

#74

Earlier quoted context omitted.

This choice should be considered a career limiting decision by any hiring manager. Are you saying that you're holding a 17 year old student in Germany responsible for not understanding US labor laws?

It makes me angry, but the law here in the US is that "ignorance is not a defense." Oh... you didn't know our several million laws when you broke one? Too bad, they say. Lawyers counter that if the law was simpler, they wouldn't have jobs.

Ok. Now if only the kid actually was over there in the US.

Re: PayPal.com XSS Vulnerability

#75
Can you clarify exactly when you reported this XSS as a personal friend of mine reported it (exact same bug with a slightly different XSS vector) and was told it had already been found a reasonable while back.

(From memory, he also took a few photos of it also).

Would be interested to hear your response as it might give this another angle entirely, haha.

My personal experience with PayPal isn't particularly great, I'm a security researcher who's just turned 18, and even when I was underage I never actually disclosed that but regardless I had the following knocked back;

(Whole heap of non-critical XSS's, and two critical stored ones, The ability to edit titles on some PayPal subdomains (without giving too much information out) - This vulnerability still exists but I was told it was quote "not serious" even though the title field was vulnerable to stored XSS.

Full path disclosures, open administrative panels, whole variety of cookie/SSL/TSL based issues which I was told did not warrant a bounty.

Also had a personal friend (the same guy who found the XSS you've posted here) find a couple SQLi's on a few PayPal domains (post-auth) and he still hasn't heard back from them.

I'm not going to be the guy to accuse PayPal of not playing fair here, but my friend has also reported vulnerabilities I had previously reported and gotten paid for them. (Might be because he reports them from his security company email, whereas I was reporting them as an individual).

Anyway, Sad to hear you didn't get a bounty!

Also, if you don't have it here's a pretty good bug bounty list; http://bugcrowd.com/list-of-bug-bounty-programs/

Re: PayPal.com XSS Vulnerability

#76

bitcoin user not affected

MtGox, BTC-e, among other big bitcoin exchanges have been hacked before.

Bitcoin is not mtgox or any other exchange. But to be fair, bitcoin itself had its share of security issues (fixed, but who knows what the future holds)

Re: PayPal.com XSS Vulnerability

#77
post #33

Earlier quoted context omitted.

The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.

They didn't have to pay him. Still very poorly handled. Should've gone something like: 1. "Hey, that's awesome that you found that, thanks!" 2. "For very good reasons (a), (b) and (c) we can't actually pay you, that really sucks :(" 3. "But hey we like your style, so how about we fly you over for an internship when you've finished school / investigate if Germany has different rules / look at scholorship options and a…

internship for $300k / year would be appropriate

Re: PayPal.com XSS Vulnerability

#78

Earlier quoted context omitted.

The Federal Labor Standards Act has provisions about anyone under the age of 18 working for companies whose revenue is greater than $500,000. It sucks to be a kid for a lot of reasons. This kid just blamed Paypal for one of our country's many idiotic federal laws. This choice should be considered a career limiting decision by any hiring manager.

"This choice should be considered a career limiting decision by any hiring manager." Hopefully not forever. When I was young and stupid and the net was a much simpler place I casually fully disclosed the problem with posting your Cisco configs with "encrypted" passwords to Usenet: https://groups.google.com/d/msg/comp.dcom.sys.cisco/WjuKAOQL... I would not do something like this today, especially not in such a full-of…

just an FYI, you can (even if you don't have the email anymore) get old posts removed from google groups, you have to jump through a bunch of hoops, but it isn't too hard to do. Just read around. I had to cover for 18 year old me posting god knows what on usenets several years ago. I did this when google first bought deja news however, you can likely get them to remove it.

who knew people were saving stuff back in 94-95. hell anyway 18 year old me didn't care, but luckily I can cover for him.

Re: PayPal.com XSS Vulnerability

#79

Earlier quoted context omitted.

It makes me angry, but the law here in the US is that "ignorance is not a defense." Oh... you didn't know our several million laws when you broke one? Too bad, they say. Lawyers counter that if the law was simpler, they wouldn't have jobs.

Ok. Now if only the kid actually was over there in the US.

It's not that simple. When you access an American network, your usage is governed my American laws -- period.

You make it sound like if you hacked into Paypal from Germany you'd be completely immune to American law on the matter because you're not in the US.

That's simply not true.

Post reply on HN