|
How difficult is it to get a paypal password...
I figure out what billing company you use for your websites payment proccessing. I obtain the scripts you use. I figure out that your transaction log is world readable and download it. Now I have your customers user/pass/email information. I also have their address/city/state/zip possibly I have their CC/CVV2/ExpDate... I rip the database for the email:pass and create a simple program to bruteforce paypals login screen.
Out of your 200,000 past users I get 800 working paypals, 250 working epassportes, etc... easy as cheese...
|