Advertisement
Promo

Security threats Toolkit

M&S plays down security exposure

Will Knight ZDNet.co.uk

Published: 20 Oct 2000 12:02 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK retail giant Marks & Spencers confirmed Friday that its Web site experienced a malfunction that left customer information and system passwords exposed.

An online customer stumbled across the information after clicking a broken link at the Web site www.marksandspencers.com at the weekend. Marks and Spencers today issued a statement to reassure customers that this was an isolated incident and that the vulnerability was swiftly plugged.

According to a spokesman, the information exposed concerned users browsing habits, such as their IP address, and the pages they had visited as well as some passwords to the SQL database running the site.

Marks & Spencers says it is highly unlikely that the information exposed could have been used to gain access to other sensitive data because of other security measures in place.

"This error was swiftly identified and within hours all steps necessary were taken to ensure that a repetition of this event is not possible," says the company's statement. "We remain convinced that shopping online with Marks & Spencers is as safe as shopping in high street stores."

Some security experts, however, disagree with the company's claim that the incident could not lead to a broader security breach.

Neil Barrett, technical director of computer security firm IRM, was shown the message by online news service Silicon.com and says that the file contained encrypted passwords for the SQL platform as well as plain text passwords for accessing SQL services. This could potentially give an unauthorised user access to a system where personal information might be stored, says Barrett. "I'm 90 percent sure that I'd be able to get access to personal data," he says.

Barrett says that patterns used to generate the passwords in the dump file would also give a hacker a good chance of guessing other system passwords, which he says is a common trick.

To have your say online click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
63 out of 126 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters