Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
Security

Submission + - Thieves found Citigroup site an easy entry (msn.com)

klubar writes: After logging in, theives used a simple GET replacement to switch among Citibank credit card accounts. Anyone with a simple browser sniffer (fiddler tools, and many others) can see the URL strings. This one appears to be even easier as it was in the URL string. You think that they would have checked for such a rookie mistake and put in better security. It's also interesting that it took so long to discover.

Slashdot Top Deals

Old programmers never die, they just branch to a new address.

Working...