<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
        <description>and other usefull contact information..

Using this, a scammer could VERY easily phone a site's customers, pretending to be from that site, and ask to confirm credit card details, or anything they need to 'double check' that could be used for ID theft etc. (Who would argue if you buy from a site, and then they phone you within 5 minutes, even I probably would fall for that)

the thing is, they all have the simplest flaw with them ... here's an example, identifying marks stripped for now:

I log in an go to change my contact details, it takes me to a form, populated with my existing details, which I can change and submit, 
https://www.FOO.com/account/edit_profile.asp?s=1&amp;amp;pid=29436 so far so good.

however.... if I change the PID value +1 or -1 .... I get someone elses personal details pre-populating the form.

Quickest ID theft EVER :)

I've found 3 sites withoout even looking for them (sites I had a real reason to use and happened to notice the 'CUST=' or 'PID=' in the URL)... how many more must there be out there? Has anyone else noticed this pattern, it seems to be pretty common;  I bet I could find 5 more sites that suffer from it in under an hour....

(wait one, I'll check :D )</description>
        <link>http://sla.ckers.org/forum/read.php?15,16764,16764#msg-16764</link>
        <lastBuildDate>Thu, 23 May 2013 03:48:54 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,24771#msg-24771</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,24771#msg-24771</link>
            <description><![CDATA[Ho, Found one for the crapy www.simplylinking.com]]></description>
            <dc:creator>tribalmp</dc:creator>
            <category>Privacy</category>
            <pubDate>Tue, 30 Sep 2008 15:02:18 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16911#msg-16911</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16911#msg-16911</link>
            <description><![CDATA[They do care since it means bad image and possibly profit losses. It just comes down to the people who make these sites don't know web app sec enough or don't care as long as they get payed. Also the companies don't want to spend too much on security since they think someone hacking them is unlikely or not worth the effort protecting against. Like TJX =oP]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>Privacy</category>
            <pubDate>Sat, 20 Oct 2007 17:36:12 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16882#msg-16882</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16882#msg-16882</link>
            <description><![CDATA[So there are LOTS of people who really don't care about their customers' personal information...<br />
<br />
At least in England that's very illegal... time to get a list together for the ICO and get them to bust some heads :)]]></description>
            <dc:creator>Jeffuk</dc:creator>
            <category>Privacy</category>
            <pubDate>Fri, 19 Oct 2007 02:13:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16864#msg-16864</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16864#msg-16864</link>
            <description><![CDATA[Thanks Ronald, I'm quite new to all this stuff so I appreciate your blatantness.]]></description>
            <dc:creator>w0ts0n</dc:creator>
            <category>Privacy</category>
            <pubDate>Thu, 18 Oct 2007 05:11:03 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16811#msg-16811</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16811#msg-16811</link>
            <description><![CDATA[Njoy!<br />
<br />
hxxp://www.google.com/search?q=inurl:&quot;aspx?cust=]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Privacy</category>
            <pubDate>Tue, 16 Oct 2007 20:10:01 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16810#msg-16810</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16810#msg-16810</link>
            <description><![CDATA[Local ISP's billing website in my town also has this problem. They have the account number in the URL and its incremental.]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>Privacy</category>
            <pubDate>Tue, 16 Oct 2007 19:35:48 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16799#msg-16799</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16799#msg-16799</link>
            <description><![CDATA[Which websites? I want to try this out for myself..]]></description>
            <dc:creator>w0ts0n</dc:creator>
            <category>Privacy</category>
            <pubDate>Tue, 16 Oct 2007 07:59:34 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16765#msg-16765</guid>
            <title>Re: I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16765#msg-16765</link>
            <description><![CDATA[Found another...<br />
<br />
On another site I use regularly... This time when you go to checkout it populates a form with your profile delivery address, based on a URL variable... <br />
<br />
this is too easy..]]></description>
            <dc:creator>Jeffuk</dc:creator>
            <category>Privacy</category>
            <pubDate>Sun, 14 Oct 2007 07:34:29 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?15,16764,16764#msg-16764</guid>
            <title>I've found a common security flaw in websites... That gives away juicy personal info, billing addresses.....</title>
            <link>http://sla.ckers.org/forum/read.php?15,16764,16764#msg-16764</link>
            <description><![CDATA[and other usefull contact information..<br />
<br />
Using this, a scammer could VERY easily phone a site's customers, pretending to be from that site, and ask to confirm credit card details, or anything they need to 'double check' that could be used for ID theft etc. (Who would argue if you buy from a site, and then they phone you within 5 minutes, even I probably would fall for that)<br />
<br />
the thing is, they all have the simplest flaw with them ... here's an example, identifying marks stripped for now:<br />
<br />
I log in an go to change my contact details, it takes me to a form, populated with my existing details, which I can change and submit, <br />
https://www.FOO.com/account/edit_profile.asp?s=1&amp;pid=29436 so far so good.<br />
<br />
however.... if I change the PID value +1 or -1 .... I get someone elses personal details pre-populating the form.<br />
<br />
Quickest ID theft EVER :)<br />
<br />
I've found 3 sites withoout even looking for them (sites I had a real reason to use and happened to notice the 'CUST=' or 'PID=' in the URL)... how many more must there be out there? Has anyone else noticed this pattern, it seems to be pretty common;  I bet I could find 5 more sites that suffer from it in under an hour....<br />
<br />
(wait one, I'll check :D )]]></description>
            <dc:creator>Jeffuk</dc:creator>
            <category>Privacy</category>
            <pubDate>Sun, 14 Oct 2007 07:28:46 -0500</pubDate>
        </item>
    </channel>
</rss>
