Send to a friend Print

Risk Management

Hacker uses public APIs to breach eBay

Author:
Cliff Saran
Posted:
11:39 22 Oct 2007

eBay has begun an audit of its IT systems after a hacker managed to access and disable user accounts.

The company said last week that the hacker exploited public application programming interfaces (APIs) that enable merchants to build e-commerce sites on top of eBay.

"This fraudster found very old administrative interfaces into the eBay system that had not been deactivated when we changed the security of our internal systems several years ago," a member of the company's trust and safety division said in a posting on an eBay blog.

"We immediately identified the functions that were accessed and deactivated, and we are undergoing an audit to ensure obsolete code that may still exist for other reasons is secure."

ADVERTISEMENT

Richard Brain, technical architect at IT security firm Procheckup, said "Public APIs are available to anyone and are used to enable businesses to communicate electronically with trading partners." He urged businesses that offer programmable access to their website to assess whether access to APIs should be limited to reduce security risks.

An eBay spokeswoman said, "We were able to block the fraudster quickly before any permanent damage had been done. At no point did the fraudster get any access to financial information or other sensitive data."




Special Reports & Profiles

Computer data recovery: An essential guide for IT professionals
Computer data recovery can be a tricky business, usually requiring the help of hard drive data recovery experts. But in all hard drive recovery situations, experts advise users remain calm and not act in a way that will make matters worse.
Security think tank Computer Weekly Security Think Tank
Information security questions answered by experts from: (ISC)2, British Computer Society, Gartner, National Computing Centre, Information Security Forum, Information Systems Security Association, and The Corporate Information Forum
Heathrow Terminal 5 Heathrow Terminal 5 - the latest from Computer Weekly
BAA’s latest London airport terminal, Heathrow Terminal 5 is based on ambitious and innovative use of IT, despite its currebt difficulties. Catch up on the background and latest news
ADVERTISEMENT

Featured Blog

Information MeltdownAs if it wasn’t bad enough to have organisations losing sensitive citizen information, we now have hackers...MoreAll blogs
ADVERTISEMENT
Advertisements