Jump to content

Recommended Posts

  • FPCH Admin
Posted

paypal.jpg

 

 

Mobile security consultant Henry Hoggard uncovered a worrying failure in how PayPal had implemented its two-factor authentication (2FA) feature:

 

Recently I was in a hotel needing to make a payment, there was no phone signal so I could not receive my Two Factor Auth token. Luckily for me Paypal’s 2FA took less than five minutes to bypass.

 

Any suggestion that PayPal's 2FA security is flawed is definitely a serious concern, so how did he do it?

 

Well, if you don't have your mobile easily to hand to receive your 2FA code from PayPal they'll give you the option of answering your special security question instead.

 

2ee04cab428a52e770d687177ac41f6f.jpeg

 

However, Hoggard discovered that meddling with the post data sent by his browser to remove securityQuestion0 and securityQuestion1 would trick PayPal into believing he had verified his account access.

 

ed4d69d30060e26153e0e51f6c775e8b.jpeg

 

Hoggard told PayPal about the vulnerability at the start of this month, and the company has now fixed the flaw and rewarded the researcher with a bug bounty.

 

Of course, attackers would not have been able to exploit this flaw unless they already knew a user's password - but we know all too well that many users either choose weak passwords or reuse the same password on multiple sites. When built properly, two-factor authentication can make it harder for attackers to break into your account in these situations.

 

It's great when websites offer their users two-factor and two-step verification, but they also need to ensure that they have implemented the feature securely.

 

Source: Graham Cluley

~I know that you believe you understand what you think I said, but I'm not sure you realize that what you heard is not what I meant.~

~~Robert McCloskey~~

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...