Ameritech ebill security hole

A security hole with Ameritech's E-bill online bill payment system was discovered today by Tap Internet, a web services firm in Ypsilanti, Michigan. Basically the hole allows other users to alter the url and possibly pull up other records of other users.

"By simplying modifying the "stmt" portion of the web address, a user can view statement records for other customers. While there is no direct way to look up information on specific customers, customers' names and phone records are listed on statements, so randomly searching through online statements can still yield extremely personal information. "

You can view the full release here.

posted @ Wednesday, March 21, 2001 11:27 PM

Print

Comments on this entry:

No comments posted yet.

Your comment:






 
 
 
Please add 5 and 3 and type the answer here:
 

Live Comment Preview:

 
«September»
SunMonTueWedThuFriSat
31123456
78910111213
14151617181920
21222324252627
2829301234
567891011