Get Paid to Participate     Twitter     Facebook     Google+
Hosting Discussion
 

Hosting Discussion > HostingDiscussion Community > General Discussion > Yet Another Hack - This Time on Citigroup
forgot password?


Reply


Old
  Post #1 (permalink)   06-09-2011, 03:03 PM
HD Wizard
 
SenseiSteve's Avatar
 
Join Date: Mar 2009
Location: Saint Louis
Posts: 3,777
Send a message via MSN to SenseiSteve

Status: SenseiSteve is offline
Yet another hack - this is getting ridiculous how high profile companies are being hacked and holding back on notifying their clients. See this story on CNN Money.
__________________
Hands-On Web Hosting
cPanel Web Hosting, Domain Registration, Managed VPS Servers
Infusing Markets LLC - A Digital Interactive Marketing Firm
 
 
 


Old
  Post #2 (permalink)   06-09-2011, 03:31 PM
HD Management Staff
 
Artashes's Avatar
 
Join Date: Apr 2003
Posts: 7,716

Status: Artashes is offline
Quote:
The latest known hack, which occurred more than a month ago, was announced this morning: Citigroup (C) said information for about 210,000 customers, or 1% of its credit-card holders in North America, was stolen.
And they let people know over a month later??? Are they kidding me? Unacceptable.
__________________
HostingDiscussion.com - web hosting community for grown-ups.

FORUM RULES | NEWS BLOG | HOSTING SHOWCASE | Follow us on Twitter
 
 
 


Old
  Post #3 (permalink)   06-10-2011, 08:37 PM
HD Guru
 
HostLeet's Avatar
 
Join Date: May 2009
Location: Florida, USA
Posts: 625

Status: HostLeet is offline
How can a company that big be so irresponsible and wait that long? I don't understand..

Over 200K customer credit card numbers stolen, and they let their customers know a month later??!!.. Makes me wonder if they actually hacked themselves...
__________________
HostLeet.Com LLC - Fully Managed WebSite Hosting Services & Domain Names!
cPanel - LiteSpeed - CloudLinux - Softaculous Auto-Installer - 24/7/365 Support
60-Day RISK FREE Money Back Guarantee - 99.9% Uptime Guarantee - Daily Backups
Register Domain Names - Secure Payment Options - Read Our Most F.A.Q's HERE!
 
 
 


Old
  Post #4 (permalink)   06-14-2011, 04:44 PM
HD Newbie
 
Join Date: May 2011
Posts: 19

Status: PaulJ is offline
Its Bad that a reputable organization like citigroup dont have their servers hardened ed and Secured .
 
 
 


Old
  Post #5 (permalink)   06-14-2011, 09:30 PM
HD Master
 
Join Date: Apr 2009
Location: Doncaster, UK.
Posts: 393
Send a message via AIM to Paul0130 Send a message via Skype™ to Paul0130

Status: Paul0130 is offline
Shocking, I wonder how the clients feel.
 
 
 


Old
  Post #6 (permalink)   06-16-2011, 12:47 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,003

Status: handsonhosting is offline
So I take it these companies that are hacked are not following proper PCI Compliance guidelines and limiting the access to databases as required

It always blows my mind to see these large companies getting hacked and thousands of users affected as a result.

Not good to not send out a notice of the hack - that's bad business on their part. They require their clients to report if their card is stolen, so shouldn't the bank be required to do the same!
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #7 (permalink)   06-16-2011, 12:49 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 2,003

Status: handsonhosting is offline
Quote:
THE HACKING of Citibank that led to the exposure of 360,000 customers' credit card details was made by simply altering the bank's URL.
When users log into the Citi Account Online system the URL changes to include a series of numbers relevant to the user's account. However, it was discovered that someone could access another's account by simply changing those numbers, according to The New York Times.
The hackers used this remarkably simple technique to hop from account to account and they even developed a script to automate the hack for them. It's difficult to even call it a hack, as it's like copying and slightly changing a key and using it on a neighbour's front door.
SERIOUSLY? It couldn't have been that easy now could it?

Read more: http://www.theinquirer.net/inquirer/...-altering-urls
__________________
Conor Treacy
http://www.HandsOnWebHosting.com
cPanel Web Hosting, Domain Registration, Managed VPS Servers
SEO in Omaha NE
 
 
 


Old
  Post #8 (permalink)   06-17-2011, 11:51 AM
CSN-UK | Charlie
 
csn-uk's Avatar
 
Join Date: Mar 2009
Location: Swindon (UK)
Posts: 470
Send a message via MSN to csn-uk

Status: csn-uk is offline
Quote:
Originally Posted by handsonhosting View Post
SERIOUSLY? It couldn't have been that easy now could it?

Read more: http://www.theinquirer.net/inquirer/...-altering-urls
Almost Fell of my chair after reading the first line of the article, can't be possible that a "BANK" is passing session and account data within the URL to begin with let alone not verifying accounts VS active sessions.

What next, are they going to print peoples pin number on the back of the cards as well ?
__________________
CSN-UK | Shared Hosting | Dedicated | VPS | Custom Packages Avalible On Request | Quality SSL Certificates from COMODO CA
CSN-UK.net | Server Status | Client Area | Live Support
 
 
 


Old
  Post #9 (permalink)   06-20-2011, 08:57 AM
HD Wizard
 
SenseiSteve's Avatar
 
Join Date: Mar 2009
Location: Saint Louis
Posts: 3,777
Send a message via MSN to SenseiSteve

Status: SenseiSteve is offline
Quote:
Originally Posted by csn-uk View Post
Almost Fell of my chair after reading the first line of the article, can't be possible that a "BANK" is passing session and account data within the URL to begin with let alone not verifying accounts VS active sessions.

What next, are they going to print peoples pin number on the back of the cards as well ?
It is crazy, isn't it? It really is amazing how so many businesses lack adequate security. I can't tell you how many times I've done a security audit for small mom and pops to find unsecured wireless networks.
__________________
Hands-On Web Hosting
cPanel Web Hosting, Domain Registration, Managed VPS Servers
Infusing Markets LLC - A Digital Interactive Marketing Firm
 
 
 


Old
  Post #10 (permalink)   06-21-2011, 08:03 PM
HD Addict
 
Join Date: Feb 2011
Posts: 223

Status: ServerSea is offline
I guess, companies suffer such issues just because of over confidence other wise carelessness towards security is just ridiculous.
__________________
ServerSea – Low Cost High Quality Web Hosting & Designing
Domain For Life– 99.9% Up time – Super Fast Servers – Backups – True 24/7 Support
Money Back Guarantee – Special Discounts – Unlimited Downloads
http://www.serversea.com
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Sponsored By: