Mailinglist Archives:
Infrared
Panorama
Photo-3D
Tech-3D
Sell-3D
MF3D

Notice
This mailinglist archive is frozen since May 2001, i.e. it will stay online but will not be updated.
<-- Date Index --> <-- Thread Index --> [Author Index]

P3D Ebay Security Flag


  • From: Bob Wier <wier@xxxxxxxxxxxxxxxxx>
  • Subject: P3D Ebay Security Flag
  • Date: Thu, 29 Apr 1999 21:37:27 -0600

I've recently been reminded (thanks Jay!) that there is a 
possible security problem with Ebay which has been known for
awhile ... see

http://www.because-we-can.com/ebayla/default.htm

Briefly, the problem is that it is (or at least was) possible for
someone to embed a Java/Javascript code in an ad which *could* send
password information (as used in bidding and listing ads) to 
someone *besides* ebay. 

It would seem right offhand that if one were to disable Java &
Javascript in their browser, then you would not have the problem.
However, it's also not clear that you could still bid (kind of
a drawback in an auction :-)

I thought this relevent due to the e-bay discussion right now.
I'm personally not terribly concerned about this, since
the liability issue for a given individual is small. Probably
the greatest risk is the use of your id/password in a bogus
ad which is designed as a vehicle to defraud other bidders. 
Naturally you'd not want to be perceived as the perp of such
a scheme.

THANKS

              Bob Wier
     mailto:wier@xxxxxxxxxxxxxxxxx
   9:36 PM Thursday, April 29, 1999
        Unix/Internet Administrator
   Rocky Mountain College, Billings MT.



------------------------------