ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cahoot bank accounts in security scare

Will Sturgeon silicon.com

Published: 05 Nov 2004 14:58 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet bank Cahoot, owned by Abbey, has been exposed for a flaw in its online security which enabled users to move freely in and out of other customers' accounts.

The problem was a result of an upgrade 12 days ago and was discovered by a customer who had bookmarked areas of his online bank account. He then discovered he was able to access those areas on future visits to the site without entering any more than his user name.

When he began tinkering with the site he discovered he was also able to access other customers' accounts simply by guessing user names and then moving to a bookmarked page.

The process of guessing user names is far from rocket science given the likelihood of there being a number of variations on popular names - such as John Smith or Jill Brown.

Security consultant Neil Barrett told ZDNet UK sister site silicon.com this morning that he had witnessed a number of tests of this method in a controlled environment and confirmed one such common name, written in surname and first initial format, yielded instant access to one account. Barrett also said he was shocked at how easy it was.

He added: "I think the ease with which it was possible to access these accounts may have been Cahoot's saving grace. It was so very simple it is likely it fell below the radar of the hackers."

It's not uncommon for wannabe hackers to surf secure Web sites removing and replacing parts of a URL in an attempt to gain access to accounts, but Barrett confirmed there was no specialist knowledge required in this instance.

However, a spokeswoman for Abbey told ZDNet UK sister site silicon.com this morning that the customer who discovered the flaw has been in touch regularly with the bank in the past "raising various security issues, all of which have been answered to his satisfaction". It would appear his concerns over the latest discovery were justified.

Cahoot was forced to take the site down for 10 hours while it fixed the flaw.

The Abbey spokeswoman said during that time the previous system was put in place and independently tested by Qinetiq and found to prevent this particular breach -- confirming it was the systems upgrade which was responsible.

Barrett believes Cahoot may not be only bank affected, warning that others who have adopted the same system could "be open to the same level of exposure".

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
67 out of 147 people found this useful


Full Talkback thread

0 comments


Related Jobs

PHP / MYSQL / CSS / HTML / Javascript / Design Developer 25K Bolton

XML, Linux, Apache (desirable) E-Commerce, Content Management (desirable) You will be working on big key accounts so you have to be an excellent ...

Commercial Support Manager - Coventry - 40k - 50k

Ensure that new business is priced in accordance with pricing guidelines and that new accounts are correctly implemented from a commercial and ...

SAS Programmer + VBA Programming Skills - Thames Valley - Urgent

Our client, who has some major household names among their accounts, is looking for a SAS Programmer with VBA programming experience for a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment