Skip to main content

UPDATE - Problem liegt vermutlich bei eBay

(English summary below.)

Hab noch etwas mehr rumprobiert und dank https://twitter.com/AskPayPal bin ich auf etwas aufmerksam geworden:

Wenn ich mich bei PayPal (über die ganz normale Seite https://www.paypal.de/) einlogge und dann in einem anderen Tab eBay aufmache, einen Artikel in den Warenkorb lege und dann PayPal als Zahlungsmethode werde ich bei PayPal ausgeloggt!

eBay macht mir die Session (bzw. den Cookie) kaputt sobald dieser vermurkste Pop-up aufgeht! (Statt die Session die bereits da ist zu nutzen...)

Kann auch super jederzeit reproduziert werden:
  1. Tab Nr. 1: PayPal öffnen und einloggen (man ist hier auf der Übersichtsseite).
  2. Tab Nr. 2: eBay öffnen, einen Artikel in den Warenkorb legen.
  3. Im Warenkorb auf "Weiter zur Kaufabwicklung" klicken
  4. PayPal als Zahlungsmethode auswählen. (Zu diesem Zeitpunkt ist man in Tab Nr. 1 bei PayPal noch eingeloggt!)
  5. Auf "Weiter" klicken - hierbei öffnet sich das Pop-up und gleichzeitig geht die Session in Tab Nr. 1 kaputt!
  6. Ohne dass man irgendwas in dem Pop-up klickt oder einträgt kann man jetzt auf den PayPal-Tab zurückwechseln und z.B. irgendeine Transaktion anklicken (oder die Seite neu laden). Die Transaktion wird nicht geöffnet, sondern man wird auf die Loginseite zurückgeworfen!
Also liegt die Vermutung, dass hier eBay Mist baut immer näher!

-----------

Okay, so a short summary of the above in English: thanks to AskPayPal Twitter did some more testing.

One thing I did was open PayPal in a tab in my browser, log in and then open eBay on another tab. Then I tried to buy an item and pay with PayPal. I selected PP as payment method and clicked on "Continue". The pop-up opens. Then - without doing anything in the pop-up - I went back to the other tab where PP was open and tried to click on a previous transaction (or I could've tried to reload the page). Instead of getting the transaction information I was redirected to the login page of PP.

So it seems, that eBay (or the PP pop-up) destroyed my session cookie.

Comments

Popular posts from this blog

Making a game for the PlayStation 2

Actually, not really for the PS2 - not natively at least. Rather making a game for YaBasic which can be played on the PS2. I started my geek life when I was 11 years old and got my first computer (486). A few years later I found some games written in QBasic on a gaming magazine's CD. That was the first time I came in contact with programming. I didn't understand much back then, because I wasn't taught before and I didn't speak any English (it's my 3rd language...) so I was just trying to figure out how the games worked by modifying stuff. These games were simple text adventures, where you had to make choices and the game would progress that way. There were no commands like "go left" or "pick up". The game presented you all the options and you had to input the number of the option you chose. And instead of "if-else" there were GOTOs everywhere. This was how I made my first game, a multiple-choice quiz with 10 questions. Since I didn...

RE: "Hacking" the PS2 - Game development

Happy 2019 everbody! This is a follow-up to my previous post:  "Hacking" the PS2 This whole thing started basically when I discovered that there is a possibility to write your own programs for the PS2. I didn't have a PS2 back in the day (I started collecting consoles around 2011) so I just found out recently. Finding out how YaBasic worked and "reverse engineering" the checksum in the source code proved to be so entertaining that I basically lost interest in making a game after that. During the holidays I had a lot of time and to make something productive I decided to take it up again and this time actually make a game. I also wanted to "streamline" the development process by not having to use 3 different programs and 2 OS's to test every change in the code I make. My old process was: write the code in Vim run the Bash script (from the previous post) to add the checksum use PS2 Save Builder to make a save file use mymc to a...

Open Source doesn't work

Before you misunderstand me: I'm a Linux user and love open source software (OSS)! I always try to use OSS if there is one available. But speaking from personal experience the idea behind open source doesn't really work. Hear me out. Open source is based on the premise that everybody can contribute and this way the software gets better. The more people do it the better it gets. Well, I have 2 cases for you. The first one is Ansible . I've made a small patch in one of the plugins (hashi_vault) to make the plugin more flexible. I've created a pull request (PR) back in August 2019. At that time the patch had no conflicts with the master branch. But it was never merged. Now, over 8 months later the patch still isn't merged and has conflicts, because the code changed so much since then. So instead of quickly accepting a good patch - which would help not only me, but probably quite a few others - it was left and forgotten. I find this rather sad. It shows the go...