Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
DEAL: For $25 - Add A Second Phone Number To Your Smartphone for life! Use promo code SLASHDOT25. Also, Slashdot's Facebook page has a chat bot now. Message it for stories and more. Check out the new SourceForge HTML5 Internet speed test! ×
Security

Submission + - Thieves found Citigroup site an easy entry (msn.com)

klubar writes: After logging in, theives used a simple GET replacement to switch among Citibank credit card accounts. Anyone with a simple browser sniffer (fiddler tools, and many others) can see the URL strings. This one appears to be even easier as it was in the URL string. You think that they would have checked for such a rookie mistake and put in better security. It's also interesting that it took so long to discover.

Slashdot Top Deals

"If it's not loud, it doesn't work!" -- Blank Reg, from "Max Headroom"

Working...