main

PayPal Leaking Customer Email Addresses

Mr magoo   on 22 January 2005 - 18:03 · 54 comments & 8021 views

Advertisement (Why?)
Windows enthusiast site, MSFN.org, have highlighted a rather serious problem with PayPal's email removal feature.

Most emails sent from corporations have "removal" links to comply with anti-spam legislation in the USA. On clicking the link sent out by PayPal, users can remove themselves from future mailings from the company. However, the system used to do this suffers from a lack of proper input validation and security. By changing elements of the URL, a malicious user can reveal other PayPal user's email addresses. The problem exposes a serious flaw in the system.

The potential for damage is serious; ever inventive spammers already harvest email addresses from websites on a massive scale and it would take only the most basic of tools to gain a large list of PayPal email addresses. Exactly how exposed PayPal have left their users is not yet known. Neowin was able to manually gain the email addresses of 20 users within 5 minutes. Interestingly, although it's possible to unsubscribe a user, PayPal still hold their email address on file. So far, PayPal have not released a fix for the problem, and have not responded to our inquiries.

PayPal, now owned fully by eBay, have "56 million account members worldwide", and are "available in 45 countries" around the world. PayPal is a member of BBOnline, and TRUSTe, two privacy groups. BBOnline's terms state that member sites "must have appropriate security measures in place to prevent unauthorized electronic access".

Update : PayPal have now closed up the hole; they've yet to reply to concerns about their data security policy.

View: Neowin Forum Thread | Screenshot
View: PayPal | Example URL


Cont...

As a result, the publisher is expecting record results in the current quarter, which runs through to the end of its financial year on March 31st, and includes the launch of titles including Splinter Cell: Chaos Theory and key new brands Brothers In Arms and Cold Theory.

Ubisoft is projecting fourth quarter earnings of 220 million Euro, which will leave its overall sales for the year up by ten per cent - a reversal of the first nine months of the year, which have seen sales down by 11 per cent.

The company, whose future has been the target of intense speculation after Electronic Arts acquired a 20 per cent shareholding in late December, is also targeting growth of at least 12 per cent in 2005/06, which would bring sales to over 600 million Euro.

"Ubisoft is well on its way to meeting its fiscal-year objectives," according to CEO Yves Guillemot, "and can count on an excellent year in 2005/06. This proves that our unique assets, brands and studios, are generating significant growth and profitability."

Post a comment · Send to friend Comments · There are 54 additional comments
#1 Cyranthus on 22 Jan 2005 - 18:20
ouch... that sucks.
(2 replies) #2 clamjouster on 22 Jan 2005 - 18:21
lol paypal sucks
#2.1 tommie on 22 Jan 2005 - 19:41
I bet you use it
#2.2 lare2 on 23 Jan 2005 - 00:22
^^
#3 M2Ys4U on 22 Jan 2005 - 18:29
I just read the forum post. this is bad for PayPal.
#4 Gowcra on 22 Jan 2005 - 18:33
yes very bad!!!
#5 UnnamedStone on 22 Jan 2005 - 18:37
omg

(1 reply) #6 Mx² on 22 Jan 2005 - 18:41
Ouch, nasty
#6.1 blachole on 23 Jan 2005 - 04:57
lol..yea its not good.
(3 replies) #7 eSouL on 22 Jan 2005 - 18:42
i thought msfn.org is considered spam in neowin's forums?
#7.1 creamhackered on 22 Jan 2005 - 18:46
We're gonna remove that Don't worry....
#7.2 slimy on 22 Jan 2005 - 20:37
FINALLY! WOOT!
#7.3 Quick Reply on 22 Jan 2005 - 23:36
Never thaught that I'ld ever see that in my lifetime. They are both awesome sites with great content, I don't know why it wasn't done sooner.
(2 replies) #8 Gowcra on 22 Jan 2005 - 18:44
Why ^^^^???
#8.1 vetMr magoo on 22 Jan 2005 - 18:48
A long time ago, the site seemed to spend time copy pasting complete stories from neowin, which i think many would agree is pretty un-acceptable / not on. However, they've sharpened up their act and are now sourcing / crediting us properly.
#8.2 xper on 22 Jan 2005 - 22:29
Not true, but it's not important anymore.
#9 bartwizzkid_ on 22 Jan 2005 - 19:08
Paypal... I never thought it was safe....
#10 BlinX on 22 Jan 2005 - 19:29
Tom, Can you point the link to http://www.neowin.net/forum/index.php?showtopic=274873&pid=585337361 .
#11 Gersson on 22 Jan 2005 - 19:34
Holy Smokes!
How can I keep safe?
I don't want any trouble!
(4 replies) #12 tommie on 22 Jan 2005 - 19:39
Big deal.. an e-mail address! WOOOOWWWW!
#12.1 BlinX on 22 Jan 2005 - 20:18
Looks like you won't give a sh** If I found out your paypal and found out your email addy and posted it, huh? and then bots spamming it?
#12.2 IGx89 on 22 Jan 2005 - 21:24
Well, searching for my e-mail address (@hotmail.com) in Google turns up 35 pages, but I "only" get 5-15 junk e-mails a day in my junkmail folder; I'm not too worried about my e-mail address being revealed.
#12.3 tommie on 22 Jan 2005 - 21:38
That's right I wouldn't give a **** because you couldn't do **** with it
#12.4 Jugalator on 23 Jan 2005 - 01:22
It's not "an", with an automated tool, it's well, however many they bother to let it dig for.
(3 replies) #13 smp on 22 Jan 2005 - 19:55
Yuck screen take in ie
#13.1 M2Ys4U on 22 Jan 2005 - 21:49
that was my first reaction too... like it is whenever I see shots taken in it.
#13.2 SquareSoft0 on 23 Jan 2005 - 01:24
Article is about... Paypal. Your post is... off topic. Have a nice day.
#13.3 smp on 23 Jan 2005 - 06:23
But still Yuck it was taken in winbloze the person who took it look like a n00b, use linux!
#14 Darth Cow on 22 Jan 2005 - 20:16
Anyone know the theme for that screenshot?
#15 BlinX on 22 Jan 2005 - 20:17
The theme is called "Energy Blue". Yes, I'm using it currently and thanks for fixing the link .
#16 nic on 22 Jan 2005 - 20:25
thats really scary. Paypal wants all kinds of sensitive information from you. It makes me really nervous.

Thanks for the heads up, tom :thumbs up:
#17 Blazin on 22 Jan 2005 - 20:37
omg... this is a really bad thing for ebuggerbay
#18 datafreak on 22 Jan 2005 - 22:46
Yup, nice for the media to go full blown about it telling them spammers/phishers.

When will the media ever think
#19 TGD on 22 Jan 2005 - 22:55
Paypal aren't really "leaking" email info. There's a flaw in the system, but the headline makes it sound like there's some harsh intent on their behalf.
#20 idiomind on 22 Jan 2005 - 23:09
Great...and I just signed up with paypal yesterday.
(4 replies) #21 fubarshibby on 22 Jan 2005 - 23:20
Big deal, it's just an email address. People get spam already... Nobody's going to notice getting any more spam. That's all that can happen with an email address being found out too. It's not like they're giving the names out, or they're giving a phone number out, etc...
#21.1 olly86 on 23 Jan 2005 - 00:02
QUOTE
People get spam already...


No, the email account I've got with PayPal has never received any SPAM. I don't need this address flooding as well as two other boxes
#21.2 Quick Reply on 23 Jan 2005 - 00:06
just because you get spammed doesn't mean that you should be so spiteful as to show disregard if we get it too.
#21.3 rIaHc3 on 23 Jan 2005 - 00:07
I dont get spammed....


Maybe you should stop giving your email out to those "free" porn sites....
#21.4 olly86 on 23 Jan 2005 - 09:11
OR maybe I should stop using Yahoo's free email/group service and News Groups
#22 Neonemesis on 23 Jan 2005 - 00:55
Plus, all you need now for an injection is the table name of the database where the emails are kept.
#23 theyarecomingforyou on 23 Jan 2005 - 01:02
I can imagine people just typing in random numbers to bring up email address, then clicking the nice "Go" button to remove their address from PayPal - I predict that they will have precisely 13 customers left by the end of today.
#24 anog on 23 Jan 2005 - 01:05
Yeah, the address should NEVER have been posted...
Now even I, a simple programmer with little or no skills, can create an email database!...
Those are the kind of details that should be given to Paypal and ONLY Paypal...
#25 i3x171um on 23 Jan 2005 - 01:20
http://ebay.benchmarkportal.com/paypal/opt_out.taf?id='%20google

Sure glad it input validates!

Last edited by 56181 on 23 Jan 2005 - 01:26
#26 anog on 23 Jan 2005 - 01:33
It's down now At least me and two friends of mine can't access it anymore
#27 i3x171um on 23 Jan 2005 - 01:41
Yeah, it stopped working a few seconds after I tried my "' google" thing (which, FYI, throws back a syntax error). They are so lucky they didn't get hacked with all the exposure this got.
#28 BlinX on 23 Jan 2005 - 02:52
About time they read this post ;P.
(2 replies) #29 Alpha2004 on 23 Jan 2005 - 03:54
Yeah... creamhackered removed my previous post and gave me a warning. I said it once and I will say it again; it is incredibly foolish to have posted the link to the email address generator. Nothing good can come out of giving thousands of people the emails of paypal users. Especially when there are so much scammers on the net.

I refuse to be censored.
#29.1 creamhackered on 23 Jan 2005 - 04:01
Calling a staff member a ****ing idiot isn't something we appreciate unfortunately.

Clearly it was a wise move to post the link since paypal have patched this in the fastest time possible. We still haven't received a response from Paypal but I assume it will be forthcoming.
#29.2 McG on 23 Jan 2005 - 05:59
I got your back, cream.
#30 SniperX on 23 Jan 2005 - 09:36
Yeah it's so bad that in all this time nobody has noticed it and I haven't heard of any hacks related to it. And whippee, my mail address? Is that it? These 'security' anouncements are becoming laughable.

Hell if anyone's THAT desperate, I'll give them my mail address.

As for "and have not responded to our inquiries." Why on earth would they? I'd expect them to use their own site for such things.

Last edited by 33613 on 23 Jan 2005 - 10:19
#31 [ timko ] on 23 Jan 2005 - 09:41
Great
#32 welshkid on 23 Jan 2005 - 11:04
sucks
#33 droozel on 23 Jan 2005 - 13:58
Not good, not good..

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)