ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

B&Q Web site lets hackers do it themselves

Munir Kotadia and Matt Loney ZDNet.co.uk

Published: 14 Nov 2003 17:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A major security flaw has been exposed on home improvement retail giant B&Q's Web site, www.diy.com, which allows a potential hacker relatively easy access to its customers' personal details.

The flaw, which was discovered by a ZDNet UK reader, makes it possible to log in under accounts of other B&Q customers with little or no technical knowledge. Once logged in, it is possible to view or change the personal details of that customer -- including full name, delivery address, phone number and email address. Once access to an account is gained, if the customer has entered their credit card details, it is also possible to order goods on their account.

B&Q customer John Dunbar said he was horrified when told about the security flaw by ZDNet UK. "The thing is you assume that big companies like this have sorted it out, and that the security its there," he said. "You don't for a minute think that other people can get access to your details. It's absolutely diabolical -- the thought that someone could order on thousands of pounds worth of goods in my name."

James O'Brien from Reading, who is not a regular B&Q customer but had once filled in the registration form on the company's Web site, told ZDNet UK he was not impressed with the security breach: "It is a bit worrying that anyone can get your address and telephone number, but I don't see it as a major threat -- unless they had my credit card details." However, O'Brien admits it could have been different: "I would have used my credit card if I had bought something from them, but I can't even remember what I used the account for now," he said.

According to the security notice on B&Q's Web site, every online transaction is checked by the company's "fraud control systems" and "in the unlikely event of fraudulent or unauthorised use" the company promises to refund any money received by B&Q, but it stipulates that the customer must first notify their credit card company and B&Q directly (0870 0101 006) or through the company's Web site.

Security expert Neil Barrett, a visiting professor at Cranfield University, said B&Q had made a very basic error on its site. "I've come across mistakes very similar though not the same. It's very easy to make those sorts of errors. And very simple to fix."

Paul Worthington, chief technology office of B&Q's parent company Kingfisher, said the issue was being resolved. "Making sure that all our customers' details are secure is paramount, and we do all we can to ensure they are protected," said Worthington.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
58 out of 88 people found this useful


Full Talkback thread

1 comment

  1. Until recently I worked (not in IT) at B&Q. Their... Anonymous

Company/Topic Alerts

Create a new alert from the list below:




Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Should a security professional have a...

My own experience and talking to colleagues has prompted me to wonder whether the day has arrived that security professionals will need a legal background. The information security... More

1 comment

Transys comment speculation

I've been pondering why it's so difficult to get any official comment out of any of the organisations involved when it comes to what is happening with Transys. Transys is the consortium... More

Post a comment

Wallet Phones Are Coming:Visa Should J...

Wallet Phones Are Coming:Visa Should Jump On Board Author: Eric Everson, Founder MyMobiSafe.com I have touched on the subject of wallet phones (a mobile handset capable of eliminating... More

Post a comment