Home > General News, Webappsec > Hacker uses public APIs to breach eBay

Hacker uses public APIs to breach eBay

October 22nd, 2007

eBay has begun an audit of its IT systems after a hacker managed to access and disable user accounts. The company said last week that the hacker exploited public application programming interfaces (APIs) that enable merchants to build e-commerce sites on top of eBay. “This fraudster found very old administrative interfaces into the eBay system that had not been deactivated when we changed the security of our internal systems several years ago,” a member of the company’s trust and safety division said in a posting on an eBay blog.

Categories: General News, Webappsec Tags:
Comments are closed.