You are on page 1of 2

1)Eligible Vulnerabilities

We encourage the coordinated disclosure of the following eligible web application vulnerabilities:

Authentication/Authorization

Cross-site scripting (XSS)

Cryptography

Cross-site request forgery (CSRF) in a privileged context

HTTP response splitting

Injection vulnerabilities

Information leakage

URL redirector abuse

Other, including:

o Server-side code execution/remote code execution

o XML attacks

o Directory traversal

o Significant security misconfiguration

2)LeadsOnline (Global Asset Protection Team Partnership)

LeadsOnline is First Responder Service is available 24/7/365. Ebay partnership with LeadsOnline makes it
possible for law enforcement personnel to locate possible stolen merchandise that has been listed for
sale or sold on eBay. LeadsOnline can assist with the following searches:

Locate seller ID information for property listed on eBay.

Locate seller listings and sales history for property listed on eBay.
3)Partnering with Retailers Offensively Against Crime and Theft

Retail Loss Prevention departments in North America seeking assistance with an investigation relating to
eBay may contact eBay's PROACT program for assistance. The PROACT program features, among other
benefits a way to report evidence of theft to eBay for investigation dedicated email address to facilitate
quick communication with eBay about retail theft investigations: PROACT@ebay.com.

You might also like