• On MovieTome: See the TRAILER for TERMINATOR 4!

November 5, 2004 4:35 PM PST

Bank accounts in online security scare

Related Stories

Wells Fargo computers stolen

November 3, 2004

Old scams pose the 'greatest security risk'

November 1, 2004

Hacking--do the pros now rule?

October 28, 2004
British Internet bank Cahoot has plugged a flaw in its online security that could have enabled people to move freely in and out of other customers' accounts.

Cahoot took the site down for 10 hours while it fixed the flaw, according to a representative for Abbey, Cahoot's parent financial institution. The problem was likely the result of an upgrade 12 days ago. During the outage, the previous system was put in place, independently tested by Qinetiq and found to prevent the breach--indicating it was the systems upgrade that was responsible.

The vulnerability was discovered by a customer who had bookmarked areas of his online bank account, Abbey said. The customer was then able to access those areas on future visits to the site without entering anything other than a user name.

When the customer began tinkering with the site, he noticed he was also able to access other customers' accounts simply by guessing user names and then moving to a bookmarked page.

The process of guessing user names is far from rocket science, given the likelihood of there being a number of variations on popular names such as John Smith or Jill Brown.

Security consultant Neil Barrett said that he had witnessed a number of tests of this method in a controlled environment. He confirmed that a common name, entered in the last name-first initial format, had yielded instant access to one account. Barrett also said he was shocked at how easy it was.

He added: "I think the ease with which it was possible to access these accounts may have been Cahoot's saving grace. It was so very simple, it is likely it fell below the radar of the hackers."

It's not uncommon for wannabe hackers to surf secure Web sites where they remove and replace parts of the URLs to try to gain access to accounts. Barrett said there was no specialist knowledge required in the Cahoot instance.

However, the Abbey representative said that the customer who discovered the flaw has been in touch regularly with the bank in the past "raising various security issues, all of which have been answered to his satisfaction."

Barrett believes Cahoot may not be only bank affected. He warned other financial institutions that have adopted the same system could "be open to the same level of exposure."

Will Sturgeon of Silicon.com reported from London.

See more CNET content tagged:
bank, account, financial company, hacker, flaw

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right