Follow Slashdot stories on Twitter


Forgot your password?
Slashdot Deals: Deal of the Day - 6 month subscription of Pandora One at 46% off. ×

Submission + - Thieves found Citigroup site an easy entry (

klubar writes: After logging in, theives used a simple GET replacement to switch among Citibank credit card accounts. Anyone with a simple browser sniffer (fiddler tools, and many others) can see the URL strings. This one appears to be even easier as it was in the URL string. You think that they would have checked for such a rookie mistake and put in better security. It's also interesting that it took so long to discover.

A failure will not appear until a unit has passed final inspection.