Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Privacy hole found in Verizon Wireless Web site

September 6, 2001 12:00 PM ET

Computerworld - Security experts discovered a flaw this week in the Web site operated by Verizon Wireless that potentially exposed the private customer information of those who used the Web site to view their personal cell phone bills.

Marc Slemko, a Seattle-based software developer, posted the warning Sept. 1 on the BugTraq security mailing list after notifying Verizon of the problem on Aug. 19 and receiving no response. Half a dozen other security experts later confirmed his findings.

The privacy hole affected users who logged on to the Verizon Wireless Web site and used the My Account feature to view or change their cell phone billing and account information. The Web site address for the feature assigns session identifications sequentially as each user logs in. The IDs are valid until the user logs out or the session times out. However, because it's the only session ID used, Slemko said it's easy to manually access the account of other users by guessing their session IDs. In addition, "automated tools [can] grab this information in bulk as users login over time," he wrote.

The vulnerability put at risk such information as names, addresses, records of calls placed and received, along with the phone number and approximate location of the user when the call was made, according to Slemko and others.

Brian Wood, a spokesman for Bedminster, N.J.-based Verizon Wireless, said IT workers at the company fixed the hole as of 5 a.m. EDT yesterday. When asked why it took Verizon so long to act on Slemko's Aug. 19 alert, Wood said Slemko didn't properly "escalate" his query.

"You have five different options to contact us on the Web site. His e-mail apparently went into the normal e-mail box and was handled by a front-line customer service representative," said Wood. "It kind of got bogged down in the system." However, Wood also said previous security tests run by Verizon on the site hadn't uncovered the flaw.

Wood said the flaw affected only a portion of the users who signed up for online billing. The hole was never an issue for former customers of Bell Atlantic Mobile, GTE Wireless, AirTouch Cellular or PrimeCo Personal Communications -- the companies that now make up Verizon Wireless.

"We've not seen any evidence that someone might have taken advantage of this hole," he said.

However, Verizon, which serves more than 28 million wireless customers, isn't alone in suffering from predictable online session IDs, according to a study presented at last month's 10th annual Usenix security conference by Kevin Fu and



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

Data Protection and Disaster Recovery with iSCSI and VMware
Data protection and disaster recovery are top of mind for any IT manager, and the challenges of complexity and cost remain as obstacles....

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...