HSBC, Barclays and The Telegraph sites were found vulnerable to cyber fraud

June 2, 2009 - 8:52am | Fraud | News |
| More
HSBC, Barclays and The Telegraph sites were found vulnerable to cyber fraud
Last week was a week of numerous discoveries of high-profile web vulnerabilities, with discoveries of careless bugs on the sites of three British companies, says the Register. Hackers published the screenshots and other details of online banking sites for HSBC and Barclays Group and the website for The Telegraph that showed all three were susceptible to attacks that could compromise the security of people who visit the properties.

The paper says that the XXS, or cross-site scripting, errors on HSBC were still present on a variety of HSBC sites on Monday afternoon California time, some 48 hours after the XSSed blog first reported them. These flaws allowed hackers to inject javascript and content into HSBC websites simply by tricking a user into clicking on a specially manipulated web address.

According to the researchers Barclays had similar bugs but as of Monday afternoon, they appeared to have been fixed.

Another XSSed report of the HackersBlog revealed details of a SQL injection vulnerability in the main website for The Telegraph. As the Reg reports the vulnerability looked especially severe because it exposed sensitive system files to those who knew how to append database commands to the website address.





RSS feed Subscribe to Ecommerce Journal RSS feed

-3 points

   Tell us what topics you want to be covered in the Ecommerce Journal?  
Image CAPTCHA
  


Comments on HSBC, Barclays and The Telegraph sites were found vulnerable to cyber fraud

Post new comment

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.



Similar Articles on Ecommerce Journal by sections

FIGURES
PAYMENT SYSTEMS
BANKS
PLASTIC CARDS
ECOMMERCE-CHECKED
INVESTMENT INDUSTRY
FRAUD
ANALYTICS
OTHER THEMES
INTERVIEWS
LAW ASPECTS