Skip to main content

UPDATE - Problem liegt vermutlich bei eBay

(English summary below.)

Hab noch etwas mehr rumprobiert und dank https://twitter.com/AskPayPal bin ich auf etwas aufmerksam geworden:

Wenn ich mich bei PayPal (über die ganz normale Seite https://www.paypal.de/) einlogge und dann in einem anderen Tab eBay aufmache, einen Artikel in den Warenkorb lege und dann PayPal als Zahlungsmethode werde ich bei PayPal ausgeloggt!

eBay macht mir die Session (bzw. den Cookie) kaputt sobald dieser vermurkste Pop-up aufgeht! (Statt die Session die bereits da ist zu nutzen...)

Kann auch super jederzeit reproduziert werden:
  1. Tab Nr. 1: PayPal öffnen und einloggen (man ist hier auf der Übersichtsseite).
  2. Tab Nr. 2: eBay öffnen, einen Artikel in den Warenkorb legen.
  3. Im Warenkorb auf "Weiter zur Kaufabwicklung" klicken
  4. PayPal als Zahlungsmethode auswählen. (Zu diesem Zeitpunkt ist man in Tab Nr. 1 bei PayPal noch eingeloggt!)
  5. Auf "Weiter" klicken - hierbei öffnet sich das Pop-up und gleichzeitig geht die Session in Tab Nr. 1 kaputt!
  6. Ohne dass man irgendwas in dem Pop-up klickt oder einträgt kann man jetzt auf den PayPal-Tab zurückwechseln und z.B. irgendeine Transaktion anklicken (oder die Seite neu laden). Die Transaktion wird nicht geöffnet, sondern man wird auf die Loginseite zurückgeworfen!
Also liegt die Vermutung, dass hier eBay Mist baut immer näher!

-----------

Okay, so a short summary of the above in English: thanks to AskPayPal Twitter did some more testing.

One thing I did was open PayPal in a tab in my browser, log in and then open eBay on another tab. Then I tried to buy an item and pay with PayPal. I selected PP as payment method and clicked on "Continue". The pop-up opens. Then - without doing anything in the pop-up - I went back to the other tab where PP was open and tried to click on a previous transaction (or I could've tried to reload the page). Instead of getting the transaction information I was redirected to the login page of PP.

So it seems, that eBay (or the PP pop-up) destroyed my session cookie.

Comments

Popular posts from this blog

Making a game for the PlayStation 2

Actually, not really for the PS2 - not natively at least. Rather making a game for YaBasic which can be played on the PS2. I started my geek life when I was 11 years old and got my first computer (486). A few years later I found some games written in QBasic on a gaming magazine's CD. That was the first time I came in contact with programming. I didn't understand much back then, because I wasn't taught before and I didn't speak any English (it's my 3rd language...) so I was just trying to figure out how the games worked by modifying stuff. These games were simple text adventures, where you had to make choices and the game would progress that way. There were no commands like "go left" or "pick up". The game presented you all the options and you had to input the number of the option you chose. And instead of "if-else" there were GOTOs everywhere. This was how I made my first game, a multiple-choice quiz with 10 questions. Since I didn...

Copyright needs to die

In latest gaming news: Mafia was released on GOG! Yay! That's great news, because it means that you can get the game DRM-free and guaranteed to work with your Win7 or Win10 installation! (And it's a real classic.) But wait! What's that? You're sitting in a car. Waiting for that famous tune everybody associates with Mafia . You don't know the title or the artist, but you immediately know that song. It plays on the radio. At least: it used to play on the radio. It's silent now. The radio is broken. No sound. Enjoy the view while driving... The game released on GOG all right. Unfortunately due to copywrong it was released without it's original soundtrack. No licensed music. No Django Reinhardt playing Belleville (that's the song you were looking for ;)). All this because copyshit still "protects" music (more like "extorts" people) after over 75 years! Yes, Belleville was first released in 1942. I mean I would get it if co...

RE: "Hacking" the PS2 - Game development

Happy 2019 everbody! This is a follow-up to my previous post:  "Hacking" the PS2 This whole thing started basically when I discovered that there is a possibility to write your own programs for the PS2. I didn't have a PS2 back in the day (I started collecting consoles around 2011) so I just found out recently. Finding out how YaBasic worked and "reverse engineering" the checksum in the source code proved to be so entertaining that I basically lost interest in making a game after that. During the holidays I had a lot of time and to make something productive I decided to take it up again and this time actually make a game. I also wanted to "streamline" the development process by not having to use 3 different programs and 2 OS's to test every change in the code I make. My old process was: write the code in Vim run the Bash script (from the previous post) to add the checksum use PS2 Save Builder to make a save file use mymc to a...