PayPal issues critical patch to prevent hackers from stealing OAuth tokens

jayar.decenella@gmail.com' By: Jay Decenella
2 minute read

OAuth serves as an open standard for token-based authentication employed by many internet giants, including PayPal. That is why the discovery of a critical flaw in the online payments service that could have allowed hackers to steal OAuth tokens from users has sent PayPal scrambling to roll out a patch.

Antonio Sanso, a security researcher and Adobe software engineer, discovered the flaw after he tested his own OAuth client. In addition to PayPal, Sanso also detected the same vulnerability in other major internet services like Facebook and Google.

Sanso says the problem lies in the way PayPal handles the redirect_uri parameter to give applications certain authentication tokens. The service has been using enhanced redirect checks to confirm the redirect_uri parameter since 2015. Still, it did not stop Sanso from bypassing these checks when he started to investigate the system in September.

PayPal lets developers use a dashboard that can produce token requests in order to enlist their apps with the service. The resulting token requests are then sent to a PayPal authorization server. Now, Sanso found an error in how PayPal recognizes a localhost as a valid redirect_uri parameter during the authentication process. He said this method wrongly implemented OAuth.

Gaming the validation system

Sanso then went on to game PayPal’s validation system and have it reveal the otherwise confidential OAuth authentication tokens. He managed to trick the system by adding a certain domain name system entry to his website, noting that localhost served as the magic word for overriding PayPal’s exact matching validation process.

The vulnerability could have compromised any PayPal OAuth client according to Sanso. He advised users to create a very specific redirect_uri when making an OAuth client. Sanso wrote in a blog post:

DO register https://yourouauthclient[dot]com/oauth/oauthprovider/callback. NOT JUST https://yourouauthclient[dot]com/ or https://yourouauthclient[dot]com/oauth.

PayPal did not believe Sanso’s findings at first, though the company eventually reconsidered its decision and now issued a fix to the flaw.

Read also:

For various PC problems, we recommend this tool.

This software will repair common computer errors, protect you from file loss, malware, hardware failure and optimize your PC for maximum performance. Fix PC issues now in 3 easy steps:

  1. Download this PC Repair Tool rated "Excellent" on TrustPilot.com.
  2. Click “Start Scan” to find Windows issues that could be causing PC problems.
  3. Click “Repair All” to fix all issues with Patended Technologies (requires upgrade).

Next up

Best Windows 10 antivirus software to use in 2018

By: Radu Tyrsina
7 minute read

Update – 2018 will soon come to an end and we already have a guide on what is the best antivirus you should get in […]

Continue Reading

These features are out for good with Windows 10 version 1809

iamsovy@gmail.com' By: Sovan Mandal
2 minute read

Microsoft is all set to launch its next big update, Windows 10 version 1809 in October. While that should be a nice piece of news […]

Continue Reading

Windows 10 18H2 builds no longer receive new features

By: Matthew Adams
3 minute read

The Windows 10 October 2018 Update (otherwise 18H2) rollout might now be two to three weeks away. For the last few months, new build previews […]

Continue Reading

Discussions