PayPal DOS

From: Levi Ruiz (lruizat_private)
Date: Mon Apr 30 2001 - 10:38:30 PDT

  • Next message: Rev. Chris Cappuccio: "Re: Hijack IP Address using cable modem"

     
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    A recent encounter with PayPal has made me discover a fairly serious
    DOS condition with PayPal.  If the user was to input the wrong
    password 3 times then PayPal will automatically disable that users
    account and issue them a new password via USPS.  When I did this, it
    took nearly a week to get that letter and until then my account was
    useless.  Calls and e-mails to PayPal went unanswered.  
    
    If someone was to do something as simple as harvest PayPal users from
    eBay or some other way, all they would have to do is try logging in
    as those people three times then effectively lock them out of PayPal
    for a week.
    
    .·°·»---------------------------------------------------------«·°·.
        -If everyone throws in their two cents worth,             -     
        -but its a penny for your thoughts...who keeps the profit?-
    
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP 7.0.1
    
    iQA/AwUBOu2kf8bgHXR4hb1iEQLKsACg7iucEPp7gm9GkGYVfgb48OqVZtcAn1zL
    FM+RYGyMpq1/3Uv8rSV2QbI3
    =cjqz
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Mon Apr 30 2001 - 11:14:26 PDT