Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Car shoppers' credit details exposed in bulk
Kevin Poulsen, SecurityFocus 2003-09-25

At least 1,000 automobile shoppers who submitted online credit applications to any of 150 different automotive dealerships around the U.S. had their personal and financial details exposed on a publicly-accessible website, according to a computer security consultant who stumbled across the privacy gaffe.

Comments Mode:
Those wascally hackers 2003-09-25
Anonymous (1 replies)
Those wascally hackers 2003-09-26
Anonymous
Car shoppers' credit details exposed in bulk 2003-09-25
Anonymous (2 replies)
Car shoppers' credit details exposed in bulk 2003-09-30
Good Samaritan
Common folks - What this guy did took little knowledge and little time. The code on the page (and we are talking clear text here) referenced a page. He went to that page. He got booted to an admin page. (Admin pages that come with web tools are normally not secured.) He looked at the URL and saw what was getting passed. He wrote a script to increment the values. done. He got 1000 results. done. all in all, I would be surprised if he spent more than 20 minutes on it. This guy is a Good Samaritan that's getting jacked because he was concerned about public safety. He's a whistle-blower. He should be protected from those that would rather us keep our heads in the sand. Please note that he didn't advertise his name and he informed a legit security group of this hole... ie no fame, no celebrity.. just one guy who knows, trying to protect those who don't. If we made it a habit of putting those people in jail, we would still have child labor and no environmental protection.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/7067/22710#22710
Shame on you, Security Focus? 2003-09-26
Anonymous (2 replies)
Shame on you, Security Focus? 2003-09-28
Anonymous
Shame on you, Security Focus? 2003-09-29
Anonymous
Car shoppers' credit details exposed in bulk 2003-09-26
Grimm (1 replies)
Shame on their IT security? 2003-09-30
Anonymous
CIO = Buffoon 2003-09-26
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus