„Paypal“ und wischofon des tages

The video demonstrates a security bug in the official paypal mobile ios api. The bug allows to bypas [sic!] the account restriction by usage of a validation flaw inside of the service.

The identity check approves restricted user accounts. In the first released issue we demonstrated how to bypass the auth. In case of the new issue the researcher demonstrates how to bypass the identity check that approves the paypal account. The attacker bypass the validation by multiple requests and dumps the real website for login inside the app with cookies and co.

Auch weiterhin viel spaß mit euren wischofonen und dem immer häufiger angebotenen bekwemen bezahlen mit den wischofonen!

