• Press Releases
    • Submit a press release
    • Read All
  • Advertise
  • Contact us
Sensei Inu Logo Sensei Inu Logo
Bitcoinist.com
No Result
View All Result
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • Gambling
      • Bitcoin Casinos
      • Real Money Slots
      • Online Casino Real Money
      • Casino utan svensk licens
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
  • Industry
    • Industry News
    • Press Releases
  • Price
    • Bitcoin Price
    • Ethereum Price
    • Litecoin Price
    • Binance Coin Price
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
    • Bitcoin Casinos – Where, What and How to Play
  • Events
  • Play Games
  • Play Casino Games
  • Play Finance
  • Best crypto casino
Breaking News: BREAKING: Three Arrows Capital Co-Founder Receives 4-Month Jail Sentence In Singapore
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • Gambling
      • Bitcoin Casinos
      • Real Money Slots
      • Online Casino Real Money
      • Casino utan svensk licens
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
  • Industry
    • Industry News
    • Press Releases
  • Price
    • Bitcoin Price
    • Ethereum Price
    • Litecoin Price
    • Binance Coin Price
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
    • Bitcoin Casinos – Where, What and How to Play
  • Events
  • Play Games
  • Play Casino Games
  • Play Finance
  • Best crypto casino
Bitcoinist.com
No Result
View All Result
Breaking News: BREAKING: Three Arrows Capital Co-Founder Receives 4-Month Jail Sentence In Singapore
Bitcoinist_Malicious Code

Recent PayPal Exploit Shows Benefits of Decentralized Payment Solutions

Jp Buntinx by Jp Buntinx
8 years ago
in Bitcoin, Bitcoin Breaking News Brief, Breaking Bitcoin News, Breaking News, Companies, News, News teaser
0

Online payments are becoming more and more important every day, but that doesn’t mean the platforms we use are stepping up their security game. PayPal, one of the largest online payment processors in the world, recently fell victim to a bug in their account system, allowing users to send malicious code through confirmation emails. Luckily, the person discovering this issue has reported the exploit to PayPal through their bug bounty program, rather than using it for malicious intent.

Also read: Cashila Announces Convenient Buy and Sell Feature For Ethereum

Sending Malicious Code With PayPal Confirmation Emails

Bitcoinist_Malicious Code Paypal

Larger online payment processing platforms have a bigger chance of becoming vulnerable to some form of exploit sooner or later. Luckily for PayPal, German security researcher Benjamin Kunz Mejri discovered a flaw which he reported to the company immediately. If someone else had made this discovery, the company would have been off far worse.

The way this exploit works is by sending emails with malicious code through an existing PayPal account. Sending an email to a different PayPal user requires users to fill in a name – usually first and last name – but it turned out that entry field could be filled with random code, including malicious scripts.

Doing so was not as straightforward as it sounds, though, as Mejri had to bypass a security filter, which can be seen in the video below this article. Once that step was completed, he used the Paypal feature to share an account with other users by adding multiple email addresses. This feature can be compared to a multisignature Bitcoin wallet, albeit with entirely different security precautions.

All of the email addresses on the list to share this particular PayPal account with would receive a confirmation email to accept this invitation. Once a user opens this email, the malicious code is executed in the background, originating from PayPal’s servers. As most people have guessed by now, this method makes it rather easy to execute phishing attacks against other users, while ensuring the email sender is PayPal, rather than spoofing the header.

Other exploits included session hijacking, and even redirecting the user to different web pages or websites. Luckily for all PayPal users, this exploit has been patched in early March 2016, and Mejri received a US$1,000 bounty for reporting this security flaw. White hat hackers are of incredible value to financial service providers, which is why companies such as PayPal have their bug bounty program.

Bitcoin is An Answer To Centralized Services

Bitcoinist_Malicious Code Paypal Bitcoin

Although Paypal is one of the most popular online payment processors in the world, their entire business model is as centralized as it can get. Not only do they take a cut of every transaction – and quite a big one too – but they also hold on to customer funds when both depositing and withdrawing money. Relying on a service with a central point of failure is putting consumer’s funds at risk.

Bitcoin, on the other hand, is entirely decentralized at its core, although there are centralized platforms in this ecosystem as well. Financial control is something very few consumers are accustomed to,  and no longer relying on centralized services requires a major mind shift. However, for those willing to take financial matters into their own hands, Bitcoin is a viable option.

What are your thoughts on this recent PayPal vulnerability? Let us know in the comments below!

Source: Tweakers (Dutch)

Images courtesy of PayPal, Shutterstock

ShareTweetShareShare

Sign Up for Our Newsletter!

For updates and exclusive offers enter your email.

I consent to my submitted data being collected and stored.

Jp Buntinx

Jp Buntinx

JP Buntinx is a freelance Bitcoin writer and Bitcoin journalist for various digital currency news outlets around the world. In other notes, Jean-Pierre is an active member of the Belgian Bitcoin Association, and occasionally attends various Bitcoin Meetups in Ghent and Brussels

Related Posts

Bitcoin price $30,000

Bitcoin Price Sets Sights On $30,000 As Holder Metric Hits New All-Time High

19 hours ago
Bitcoin

Bitcoin Long-Term Metrics Point To A Different Scenario Than 2019 Fakeout: Top Analyst

21 hours ago
Bitcoin

Bitcoin Hash Rate: Public Miners Account For Just 28% – Is Decentralization In Jeopardy?

1 day ago
Bitcoin

Bitcoin Recent Hiccup: Understanding The Invalid Block 

2 days ago
BitBoy

Crypto Influencer ‘BitBoy’ Arrested Live On YouTube – Here’s What Happened

4 days ago
Bitcoin

Could Bitcoin Be On The Verge Of New ATH Rally? Analyst Identifies These Conditions

4 days ago
Please login to join discussion

Premium Partners

Premium Casino Partners

Play Finance

Top Casinos

Trust Dice
Trust Dice
Punt Casino
Punt Casino
mBit
mBit

Press Releases

  • 6 Best Cryptos To Buy For Huge Growth in 2023

    2 hours ago
  • Best 7 Cryptos For Beginners To Buy

    4 hours ago
  • From Setbacks to Success: Uwerx’s Recovery/Relaunch...

    6 hours ago
  • Prepare for the Next Bull Market: The 5 Best Cryptos to Buy...

    11 hours ago
  • Meta Force and Lado Okhotnikov Presented the Results of...

    23 hours ago

Bitcoin news portal providing breaking news, guides, price analysis about decentralized digital money & blockchain technology.

Bitcoin

  • News
  • Price
  • Businesses
  • Acceptance
  • Technology
  • Investment
  • Regulation
  • Reviews

Altcoins

  • News
  • Price
  • Ethereum
  • Ripple
  • Litecoin
  • EOS
  • NAGA

Categories

  • Blockchain
  • Security
  • FinTech
  • Technology
  • Trending
  • Breaking News
  • Press Releases
  • How to

Pages

  • Contact us
  • Editorial Policy
  • Advertise
© 2023 Bitcoinist.com. All Rights Reserved.
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • Gambling
      • Bitcoin Casinos
      • Real Money Slots
      • Online Casino Real Money
      • Casino utan svensk licens
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
  • Industry
    • Industry News
    • Press Releases
  • Price
    • Bitcoin Price
    • Ethereum Price
    • Litecoin Price
    • Binance Coin Price
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
    • Bitcoin Casinos – Where, What and How to Play
  • Events
  • Play Games
  • Play Casino Games
  • Play Finance
  • Best crypto casino

© 2023 Bitcoinist. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy.