PayPal fixes app authentication token hijack flaw

By
Follow google news

Online payments processor didn't implement OAuth right.

PayPal has plugged a security hole that could have easily been used to hijack third-party application authentication tokens, giving attackers access to accounts connected to the apps.

PayPal fixes app authentication token hijack flaw

The flaw was discovered by Adobe senior software engineer Antonio Sanso while testing his own OAuth client.

OAuth is an open standard for secure authentication used by many technology companies including Google and Facebook, which had similar flaws to PayPal that were also discovered by Sanso.

The vulnerability stems from PayPal accepting localhost - the name used to resolve the IPv4 address 127.0.0.1 and IPv6 address ::1 to users' local systems - as a valid for the redir_uri parameter in the authentication flow, Sanso said.

By adding a specific domain name system entry for his website (localhost.intothesymmetry.com), Sanso was able to trick PayPal's validation systems into revealing OAuth authentication tokens he would normally not have been entitled to see.

The vulnerability worked for any PayPal OAuth client, Sanso said.

Sanso reported the flaw to PayPal on September 9 this year, and received a response 18 days later that indicated PayPal did not consider the issue a vulnerability, the researcher said.

The software developer persisted with the report and in early November PayPal said it had fixed the issue and awarded a bug bounty to Sanso for finding the flaw.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Health and Aged Care CISO retires

Health and Aged Care CISO retires

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?