Skip to content
Yasser Ali's Blog
  • Home
  • About me
  • Contact me!
  • Training
  • Toggle website search
Menu Close
  • Home
  • About me
  • Contact me!
  • Training
  • Toggle website search

Yearly Archives: 2014

  1. Home>
  2. 2014
Read more about the article Hacking PayPal Accounts with one click (Patched)
The application generates a valid "Auth" token for a logged-out user!

Hacking PayPal Accounts with one click (Patched)

  • Post author:eng_yasser
  • Post published:October 9, 2014
  • Post category:Security
  • Post comments:105 Comments

Continue ReadingHacking PayPal Accounts with one click (Patched)
Read more about the article Microsoft-careers.com Remote Password Reset
Microsoft-careers hacked

Microsoft-careers.com Remote Password Reset

  • Post author:eng_yasser
  • Post published:August 4, 2014
  • Post category:Security
  • Post comments:11 Comments

Continue ReadingMicrosoft-careers.com Remote Password Reset
Read more about the article How I could change your eBay password
Hijacking eBay users

How I could change your eBay password

  • Post author:eng_yasser
  • Post published:June 3, 2014
  • Post category:Security
  • Post comments:12 Comments

Continue ReadingHow I could change your eBay password

Recent Posts

  • Hacking PayPal Accounts with one click (Patched)
  • Microsoft-careers.com Remote Password Reset
  • How I could change your eBay password

Recent Comments

12 responses to “How I could change your eBay password”

  1. P Bowie Avatar
    P Bowie
    September 22, 2014

    Id love to be able to get into one gmail acct !! 🙂

    Reply
  2. evilReddy Avatar
    evilReddy
    September 23, 2014

    nice bro..

    Reply
  3. Zoltan L. Nemeth Avatar
    Zoltan L. Nemeth
    December 8, 2014

    Hi Yasser,

    Many thanks for your efforts to explain your discoveries, its a great help for the whole security community.

    But, I think that in the figure the phrase

    “Attacker intercepts the request, save the reqinput …”

    is somewhat misleading, as the attacker do not need to catch the e-mail, as the figure might suggests, but he learns the reqinfo token earlier by browsing the page where he enters the victim’s e-mail address.

    More precisely, the reqinput token is sent by the server in a hidden input field of the
    /EnterUserInfo page.

    I am sure you are aware of this, I just made this comment for the less experienced
    readers like me.

    Congrats for your success on Paypal, regards

    Zoltan

    Reply
    1. yasser Avatar
      yasser
      December 8, 2014

      Yes, We could do it that way too 🙂

      Reply
      1. Brooke Avatar
        Brooke
        May 14, 2015

        Yasser, I am having difficulties doing this.

        Can we please speak? I desperately need help with this!

        Reply
        1. yasser Avatar
          yasser
          May 16, 2015

          Yes, because it has been patched 😉

          Reply
  4. Ava Avatar
    Ava
    June 3, 2015

    Yasser, Does this hack still work?

    Please let me know Thanks!

    Reply
    1. yasser Avatar
      yasser
      June 4, 2015

      Nope, This has been patched be eBay.

      Reply
  5. Web Application Security & Bug Bounty
    February 22, 2019

    […] How I could change your eBay passwordby Yaaser Ali […]

    Reply
  6. Guide 001 |Getting Started in Bug Bounty Hunting.. – Muhammad Khizer Javed
    June 3, 2019

    […] How I could change your eBay password by Yaaser Ali […]

    Reply
  7. Bug Bounty Methodology (TTP- Tactics,Techniques and Procedures) V 2.0 ~ Cyberzombie
    July 3, 2019

    […] How I could change your eBay password by Yaaser Ali […]

    Reply
  8. Getting Started in Bug Bounty Hunting | Complete Guide
    August 30, 2019

    […] How I could change your eBay password  Yaaser Ali […]

    Reply
Yasser Ali's Blog