Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Car shoppers' credit details exposed in bulk
Kevin Poulsen, SecurityFocus 2003-09-25

At least 1,000 automobile shoppers who submitted online credit applications to any of 150 different automotive dealerships around the U.S. had their personal and financial details exposed on a publicly-accessible website, according to a computer security consultant who stumbled across the privacy gaffe.

Comments Mode:
Those wascally hackers 2003-09-25
Anonymous (1 replies)
Those wascally hackers 2003-09-26
Anonymous
Shame on you, Security Focus? 2003-09-26
Anonymous (2 replies)
Shame on you, Security Focus? 2003-09-28
Anonymous
Shame on you, Security Focus? 2003-09-29
Anonymous
Car shoppers' credit details exposed in bulk 2003-09-26
Grimm (1 replies)
Shame on their IT security? 2003-09-30
Anonymous
I blame the CIO, who clearly is an idiot. Does he even have an IT security staff?

More than likely, the CIO's idea of IT security is a web designer who set up a web server and believed that because the transaction was handled via SSL, everything was encrypted.

Besides this, how often is IT security listened to by the system and network admins? How often are IT security allowed to do penetration tests, just for the heck of it. How often is IT security allowed to review all code from another department, in this instant web development?

The CIO is fully to blame in my mind ...

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/7067/22725#22725
CIO = Buffoon 2003-09-26
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus