[ale] [OT] FYI: faked ebay seller profiles

On Fri, 23 Jan 2004 18:16:18 -0500
Stephan Uphoff <ups at stups.com> wrote:

> Link in German:
> http://www.tagesschau.de/aktuell/meldungen/0,1185,OID2858696_REF4,00.html

It sounds like they can even alter feedback comments.  An excerpt from
the fish:

Small Javascript

The trick functions according to to the data, as the salesman adds a
small Javascript with providing his offer to the description text. If a
eBay user looks at itself the offer, its Browser implements the mini
program usually automatically. Javascript exchanges the data in the eBay
profile of the salesman as desired. Only who switches Javascript off in
its Browser, the genuine profile of the apparently respectable offerer
sees. In addition cheats can deceive users, by fading in arbitrary
evaluation texts of allegedly content buyers.

eBay nothing undertakes

According to the magazine the auction platform knows the safety gap, it
however yet did not close. Until the hole is plugged, the magazine
recommends ebay customers to deactivate before a purchase at least
temporarily Javascript in their Internetbrowser.