ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Wanadoo closes serious security hole

David Meyer ZDNet.co.uk

Published: 19 May 2006 16:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Broadband provider Wanadoo UK has closed a security hole that left the login details of thousands of its customers exposed.

The security lapse was brought to light on a user forum, WanadooProblems.co.uk, earlier in the week. It occurred when index listings were made available due to a configuration error on a Wanadoo server based in Madeira, Portugal.

The ISP attempted to correct the error after it was brought to attention by forum members, but left the files open to viewing by anyone who knew their location. This was pointed out, and it has now moved the files, meaning the hole now finally appears to be closed.

The number of customers whose personal details were left exposed is unclear. Estimates on the forum have been as high as 20,000, although a spokesperson for Wanadoo told ZDNet UK on Friday that it had "taken the precaution of writing to approximately 7,000 customers to ask them to change their passwords as an added security measure".

What is also unclear is the length of time for which the customer information was left unprotected. The owner of WanadooProblems.co.uk told ZDNet UK that, from looking at the data, it appeared the security hole "may have been there since 2004". Wanadoo's spokesperson declined to clarify this matter, but said the "previously unidentified vulnerability... was closed as soon as [Wanadoo was] made aware of it".

There is no evidence as yet that customer information was obtained and misused by any third party.

Wanadoo's spokesperson thanked the forum's owner for bringing the matter to the ISP's attention, but pointed out that "he is under a legal obligation to destroy any copies of the data that he has". The forum owner assured ZDNet UK that the "6,986 files" he managed to download from the exposed server will now be destroyed.

Ian Fogg, a senior analyst at Jupiter Research, believes that the security lapse could hurt Wanadoo's reputation with its customers.

"Sixteen percent [of broadband users] use antivirus software provided by their ISP," he said on Friday. "Will they continue to trust it? Why would you go to your ISP for antivirus software if they can't keep the basics secure?"

There is also a possibility that Wanadoo may have unwittingly breached the Data Protection Act by leaving its customers' details exposed. The ISP's spokesperson told ZDNet UK that "Wanadoo takes its Data Protection Act obligations very seriously, and is working to ensure that this doesn't happen again".

Wanadoo UK is merging with its sister company Orange, at the cost of thousands of jobs. As reported at the time, WanadooProblems.co.uk will subsequently be changing its name to OrangeProblems.co.uk.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
122 out of 196 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Quality Lead - Unilever - Level C-00055185

The Quality and Process Improvement programme (QPI), Sarbanes Oxley (SOX) Compliance and Security are highly visible subject matter on this ...

SENIOR PROJECT MANAGER, PROGRAMME MANAGER, PRINCE2, SOUTH YORKSHIRE

The ability to act effectively as a bridge between the technical and non-technical workforce. For more details on this excellent opportunity please ...

IT Governance Security Analyst 32,000 - 34,500 + benefits, Telford

IT Governance 6: Assist with IT Business Continuity Planning The right candidate will need to have ideally Sarbanes Oxley and Data Protection Act ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Challenges of Nigeria mobile Banking

Mobile Banking refers to provision of banking and financial services with the help of mobile telecommunication devices. The scope of offered services may include facilities to conduct... More

Post a comment

Mobile marketing innovations will driv...

Farmed out License Holder, Etisalat Nigeria sure understand how to engage the subscribers in the 3G Era. During the launch of the Network last week in Lagos, the company spokesperson... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment