<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: eBay&#8217;s Daily Deal is Now A Malware Victim from the Auctiva Trojan</title>
	<atom:link href="http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/</link>
	<description>eCommerce business top seller videos from top eBay online commerce seller</description>
	<lastBuildDate>Wed, 17 Mar 2010 20:08:57 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sorry Wrong Number: Could The eBay/Skype Deal Go Bust? - News: Everything-e</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-2301</link>
		<dc:creator>Sorry Wrong Number: Could The eBay/Skype Deal Go Bust? - News: Everything-e</dc:creator>
		<pubDate>Thu, 17 Sep 2009 22:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-2301</guid>
		<description>[...] Letter&#8221;? Share this article...Close&#160;Bookmark and Share This Page Save to Browser...eBay&#8217;s Daily Deal is Now A Malware Victim from the Auctiva Trojan Share this article...Close&#160;Bookmark and Share This Page Save to [...]</description>
		<content:encoded><![CDATA[<p>[...] Letter&#8221;? Share this article&#8230;Close&nbsp;Bookmark and Share This Page Save to Browser&#8230;eBay&rsquo;s Daily Deal is Now A Malware Victim from the Auctiva Trojan Share this article&#8230;Close&nbsp;Bookmark and Share This Page Save to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-798</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Mon, 23 Feb 2009 08:59:17 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-798</guid>
		<description>To be clear regarding Lisa&#039;s comments, Bonanzle is NOT affected in the sense that any malware has been detected in any of our listings, forums, or anywhere else on site.  However, if one were to leave our site and visit Auctiva (for instance, by clicking on an Auctiva image), then (depending on their browser) they would get the Auctiva malware warning.

I may have more sympathy for Auctiva than most, since I know how extremely difficult it can be to keep a site free of the thousands of different security threats out on the web.  And in the case of Auctiva, chances are they didn&#039;t even *know* they had been compromised until they Googled their name one day and saw the Google message.  And now they&#039;ve got a regular bruhaha on their hands.  Sucks to be them.

From my experience, there are two main attack vectors that get exploited to cause 95% of these types of break-ins.  The first is leaving one&#039;s site vulnerable to XSS attacks (http://en.wikipedia.org/wiki/Cross-site_scripting) by having insufficient filtering of potentially malicious Javascript in item listings.  If I were to guess, I would imagine that was what bit Auctiva.  eBay&#039;s HTML filter is extremely permissive, since they&#039;ve had the resources to tweak it for years to ensure that it allows every possible good HTML element through an no bad ones.  Bonanzle&#039;s HTML filter is very strict, which means we often get annoyed sellers telling us that HTML elements imported from eBay don&#039;t work at Bonanzle, but it&#039;s the price we pay to ensure that we are as immune as possible to a potential XSS attack.

The other vector of attack is running one&#039;s server on Windows with ASP, where the systems are much more complex, and thus have historically had a greater number of vulnerabilities.  Bonanzle runs on Linux with open source software that is simple and transparent, so very unlikely to be vulnerable to a direct attack on the system.  

I hope that Google gets a chance to verify Auctiva&#039;s fix soon -- it&#039;s a really rotten position they&#039;ve been put in.</description>
		<content:encoded><![CDATA[<p>To be clear regarding Lisa&#8217;s comments, Bonanzle is NOT affected in the sense that any malware has been detected in any of our listings, forums, or anywhere else on site.  However, if one were to leave our site and visit Auctiva (for instance, by clicking on an Auctiva image), then (depending on their browser) they would get the Auctiva malware warning.</p>
<p>I may have more sympathy for Auctiva than most, since I know how extremely difficult it can be to keep a site free of the thousands of different security threats out on the web.  And in the case of Auctiva, chances are they didn&#8217;t even *know* they had been compromised until they Googled their name one day and saw the Google message.  And now they&#8217;ve got a regular bruhaha on their hands.  Sucks to be them.</p>
<p>From my experience, there are two main attack vectors that get exploited to cause 95% of these types of break-ins.  The first is leaving one&#8217;s site vulnerable to XSS attacks (<a href="http://en.wikipedia.org/wiki/Cross-site_scripting" rel="nofollow">http://en.wikipedia.org/wiki/Cross-site_scripting</a>) by having insufficient filtering of potentially malicious Javascript in item listings.  If I were to guess, I would imagine that was what bit Auctiva.  eBay&#8217;s HTML filter is extremely permissive, since they&#8217;ve had the resources to tweak it for years to ensure that it allows every possible good HTML element through an no bad ones.  Bonanzle&#8217;s HTML filter is very strict, which means we often get annoyed sellers telling us that HTML elements imported from eBay don&#8217;t work at Bonanzle, but it&#8217;s the price we pay to ensure that we are as immune as possible to a potential XSS attack.</p>
<p>The other vector of attack is running one&#8217;s server on Windows with ASP, where the systems are much more complex, and thus have historically had a greater number of vulnerabilities.  Bonanzle runs on Linux with open source software that is simple and transparent, so very unlikely to be vulnerable to a direct attack on the system.  </p>
<p>I hope that Google gets a chance to verify Auctiva&#8217;s fix soon &#8212; it&#8217;s a really rotten position they&#8217;ve been put in.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lisa</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-792</link>
		<dc:creator>Lisa</dc:creator>
		<pubDate>Mon, 23 Feb 2009 01:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-792</guid>
		<description>Hey James,

Bonanzle is affected too.  I just found your forums.  All those Ebay uploads you have been promoting has affected Bonanzle as well.</description>
		<content:encoded><![CDATA[<p>Hey James,</p>
<p>Bonanzle is affected too.  I just found your forums.  All those Ebay uploads you have been promoting has affected Bonanzle as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Auctiva Trojan Troubles Compounded By Suggestion To Turn Off Security Warnings : eCommerce Marketing Radio Network</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-791</link>
		<dc:creator>Auctiva Trojan Troubles Compounded By Suggestion To Turn Off Security Warnings : eCommerce Marketing Radio Network</dc:creator>
		<pubDate>Mon, 23 Feb 2009 00:49:29 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-791</guid>
		<description>[...] &#8220;Colderice&#8221; Lawson is reporting that the eBay Daily Deals which features items submitted through [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8220;Colderice&#8221; Lawson is reporting that the eBay Daily Deals which features items submitted through [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-790</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Mon, 23 Feb 2009 00:12:19 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-790</guid>
		<description>Hey John,

I get the error with Chrome, but not with IE 7.  Enjoy your blog.  Thanks!

Dave</description>
		<content:encoded><![CDATA[<p>Hey John,</p>
<p>I get the error with Chrome, but not with IE 7.  Enjoy your blog.  Thanks!</p>
<p>Dave</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tree411</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-787</link>
		<dc:creator>tree411</dc:creator>
		<pubDate>Sun, 22 Feb 2009 22:33:33 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-787</guid>
		<description>Hello colderice..Please see your e-mails. I have sent over some e-mails from Feb. 8th. when I first noticed and reported issues. It just seems to me that this may be the same thing from as long if not longer from when I first started to get warning when viewing imported eBay listings, as well as the warnings on the eBay site.</description>
		<content:encoded><![CDATA[<p>Hello colderice..Please see your e-mails. I have sent over some e-mails from Feb. 8th. when I first noticed and reported issues. It just seems to me that this may be the same thing from as long if not longer from when I first started to get warning when viewing imported eBay listings, as well as the warnings on the eBay site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-785</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sun, 22 Feb 2009 22:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-785</guid>
		<description>You Sir without a Doubt are Top Notch. Consider me a Member now and forgive the Picture. it&#039;s the most recent one I have. I have my ears cropped now and had a Jaw lift.</description>
		<content:encoded><![CDATA[<p>You Sir without a Doubt are Top Notch. Consider me a Member now and forgive the Picture. it&#8217;s the most recent one I have. I have my ears cropped now and had a Jaw lift.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: colderice</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-784</link>
		<dc:creator>colderice</dc:creator>
		<pubDate>Sun, 22 Feb 2009 22:11:29 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-784</guid>
		<description>Delete it? Heck no...I am an evangelist of self promotion...Thank you for the invite. Long as it is NOT spammy, they are welcome.</description>
		<content:encoded><![CDATA[<p>Delete it? Heck no&#8230;I am an evangelist of self promotion&#8230;Thank you for the invite. Long as it is NOT spammy, they are welcome.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-783</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sun, 22 Feb 2009 22:06:52 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-783</guid>
		<description>Well Shameless as it is eBay has more Problems than just Auctiva now. Plus with the upcoming changes they have coming promoting a sure thing seems good. By the way Thanks for not deleting the comments. You to are welcome to stop by. We do not take names or even email addresses for that matter.</description>
		<content:encoded><![CDATA[<p>Well Shameless as it is eBay has more Problems than just Auctiva now. Plus with the upcoming changes they have coming promoting a sure thing seems good. By the way Thanks for not deleting the comments. You to are welcome to stop by. We do not take names or even email addresses for that matter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: colderice</title>
		<link>http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/comment-page-1/#comment-782</link>
		<dc:creator>colderice</dc:creator>
		<pubDate>Sun, 22 Feb 2009 21:59:46 +0000</pubDate>
		<guid isPermaLink="false">http://3rdpoblogs.com/colderice/2009/02/22/ebays-daily-deal-is-now-a-malware-victim-from-the-auctiva-trojan/#comment-782</guid>
		<description>Never miss an opportunity for a shamless self promotion, LMAO</description>
		<content:encoded><![CDATA[<p>Never miss an opportunity for a shamless self promotion, LMAO</p>
]]></content:encoded>
	</item>
</channel>
</rss>
