Falle-Internet.de invited us to be witness to what they said would be a demonstration of an eBay security vulnerability. We signed into eBay at the appointed time and visited a listing they had created on eBay Germany. On another computer we were monitoring a page Falle-Internet.de had set up that they said would display our eBay account information as soon as we had visited their eBay listing. Sure enough, it did.
This is a known cross-site scripting vulnerability, and eBay said they have software to detect malicious code on eBay.com, and policies in place in eBay Germany to prevent listings like this from launching.
In Thursday's Newsflash, we are publishing a full account of this demonstration.
Falle-Internet.de sprung from an eBay Germany chat room on security issues. Our contact said the watchdog group was frustrated with eBay Germany's lack of attention to the problem and that's why they conducted the demonstration.