Citibank security hole
from the there-is-no-excuse-for-this dept
As a Citibank credit card holder I often check my account statement online. In fact, I don't even get paper statements from them. I recently discovered a security hole in their system. Anyone can view transaction records of any account holder, without any password or username. Don't believe me? Click on this link. That's the monthly membership fee for my account with Citibank. There is absolutely no excuse for this type of security hole from any online site, much less a bank.
5 Comments | Leave a Comment..
If you liked this post, you may also be interested in...
- Hadopi Sends Info On Those Accused (Not Convicted) Of Repeat Infringement On To Prosecutors
- DailyDirt: Autonomous Vehicles
- How Publishers Repeated The Same Mistake As Record Labels: DRM Obsession Gave Amazon Dominant Position
- Park Ranger Tases Guy Walking Dogs Without A Leash
- Brazilian Government Ordering Web Hosting Firms To Kill Domain Names They Don't Like





Reader Comments (rss)
(Flattened / Threaded)
Look closer...
https://www.accountonline.com/CB/amount.jsp?POSTING_DATE=10%2F20%2F00&SALE_DATE=10%2F20%2F00&TR ANSACTION_TYPE_TEXT=ANONYMOUS+USAGE&REFERENCE_NUMBER=00000000&PERSON_NAME=&TRANSACTION_AMOUNT=1000.0 0&FOREIGN_CURRENCY=&MERCHANT_DESCRIPTION=ANONYMOUS+USAGE+OCT+00-SEP+01++++++++++++&SIC_DESCRIPTION=+ +++++++++++++++++++++++++++++++++++++++&STATEMENT_DATE=10%2F19%2F00
Now this would all change if account number and any reference numbers were part of the URL passed.
Greg
[ reply to this | link to this | view in thread ]
Re: Look closer...
[ reply to this | link to this | view in thread ]
Re: Look closer...
[ reply to this | link to this | view in thread ]
The URL is secure
Otakudo - The Way of the Nerd.
[ reply to this | link to this | view in thread ]
Re: Look closer...
[ reply to this | link to this | view in thread ]
Add Your Comment