Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Car shoppers' credit details exposed in bulk
Kevin Poulsen, SecurityFocus 2003-09-25

At least 1,000 automobile shoppers who submitted online credit applications to any of 150 different automotive dealerships around the U.S. had their personal and financial details exposed on a publicly-accessible website, according to a computer security consultant who stumbled across the privacy gaffe.

Comments Mode:
Car shoppers' credit details exposed in bulk 2003-09-25
Anonymous (3 replies)
This sounds really bad, but in reality what happened? A pen tester found the file. It was not publically accessible. Someone had to look for it, someone with skills probably well above what your ordinary script kiddy has.

...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-26
Anonymous
Its not hard to stumble across something like that. Even if the webserver shouldn't have been public then its still not ilegal to come across it.

Full details are never released to the public about security breaches....

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-26
Jake (1 replies)
Er, from what it said, it didn't take that much skill; someone found a link to a "hidden" page which gave out the credit card info.

Dealerskins reply in the final paragraph seems to say "We're going to get hacked anyway, so we might as well be nice to those hackers and make it easy for them. Oh,...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-28
Anonymous
Excuse me? These are sites that sell cars. Credit card info? Pardon? They aren't buying books with their Visa card, they're applying for credit. Is the hole any more forgivable? No. It was stupid and avoidable. But let's keep the situation clear....

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-30
Anonymous
Anybody can view source code through their particular flavor of web browser. it actually is a big deal....

[ more ]  [ reply ]
Those wascally hackers 2003-09-25
Anonymous (1 replies)
Yes, given enough time and resources, you too may be able to "read HTML source code" someday! However, beware the years of arduous study required for such a task.

Indeed this is the holy grail of hacker knowledge!...

[ more ]  [ reply ]
Those wascally hackers 2003-09-26
Anonymous
it's those tags that stump me. "Only a truly gifted hacker could make sense of that!" I always end of saying...

Does that make web designers hackers?

Does that make any app that creates HTML code a hacker program?...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-25
Anonymous (2 replies)
The question in my mind is; why would anyone who just wanted to make a service appointmnet spend hours looking for a security breach and then downloading 1000 credit applications? IF, they had a real job? Obviously they had A LOT of time on their hands. This hardly sounds quite as innocent or hel...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-29
Anonymous
That kind of quality information can be sold to ID-theft rings for good money. Selling that quality and quantity of information might have been work many, many thousands of dollars....

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-30
Good Samaritan
Common folks - What this guy did took little knowledge and little time. The code on the page (and we are talking clear text here) referenced a page. He went to that page. He got booted to an admin page. (Admin pages that come with web tools are normally not secured.) He looked at the URL and sa...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-25
Anonymous (2 replies)
Hmmm.....

Right click | View Source

Yep, thems some m4d skilz....

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-26
Anonymous (1 replies)
Oh hold on, slow down. Right-click what?...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-29
Roger
Anonymous wrote:

> Oh hold on, slow down. Right-click what?

Right-click the web page you are looking at. A "context sensitive menu" will pop up. One of the options is "View Page Source" or "View Source". Selecting that option shows you the HTML instructions for the page you are looking at. It ta...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-29
Anonymous
Anyone got the 'sploit code ? ...

[ more ]  [ reply ]
Shame on you, Security Focus? 2003-09-26
Anonymous (2 replies)
Let me get this straight, some anon. source finds a whole, and then instead of working with the vendor -- they go to Security Focus so you can have a "scoop"?

...

[ more ]  [ reply ]
Shame on you, Security Focus? 2003-09-28
Anonymous
Let me get this straight. You would have the guy come forward and identify himself to the company in an effort to correct the situation?

That plan didn't seem to work out so well for Adrian Lamo, now did it?

Great job Mr. Poulsen and Security Focus, for allowing a venue where people feel that...

[ more ]  [ reply ]
Shame on you, Security Focus? 2003-09-29
Anonymous
"Anonymous" ironically criticized anonymity by writing:

> Let me get this straight, some anon. source finds a whole, and then instead of working with the vendor -- they go to Security Focus so you can have a "scoop"?

Yeah, and so recently after the major headlines about the FBI prosecuting some...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-26
Grimm (1 replies)
It takes only rudmentary knowledge of html to sort through and pick out a blatantly obvious flaw like this. Shame on their IT security for not knowing better. They deserve whatever befalls them over this....

[ more ]  [ reply ]
Shame on their IT security? 2003-09-30
Anonymous
I blame the CIO, who clearly is an idiot. Does he even have an IT security staff?

More than likely, the CIO's idea of IT security is a web designer who set up a web server and believed that because the transaction was handled via SSL, everything was encrypted.

Besides this, how often is IT se...

[ more ]  [ reply ]
CIO = Buffoon 2003-09-26
Anonymous
From its press release, Dealerskins shows itself culturally and technically incompetent. It will never be able to secure this database.

It has been my experience that CTO's and CIO's may have MBA's, but usually have no understanding of the technology they are supposed to be managing. That is beyo...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-09-27
0ption
it all comes down to this...html is one of the easieast things to look at without proir understanding and get even a faint concept of whats going on. Also i veiw source on lots of sites just to see how "they" did it. Not to mention if you knew htlm pretty good and you knew that there are risks in pu...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-10-01
BojanTrojan
Scenario:

You're an IT Director using a CRM package with a serious security bug you've just discovered. Every one of the over 5000 installations of this software are easily compromised with knowledge of this bug.

What do you do?

1. Nothing

2. Alert the vendor and maybe get a medal.

3. Sta...

[ more ]  [ reply ]
Car shoppers' credit details exposed in bulk 2003-10-02
Anonymous
This appears to be a no win situation for anyone with some computer knowledge. There have been too many accounts of people stumbling onto a vulnerability and getting screwed for it. There has to be a way for a consumer to identify a problem and report it without that person being investigated by th...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus