xss


Bank & Mobile Network Security: For want of a nail...
banking

Bank & Mobile Network Security: For want of a nail...

Ever since publishing a "two factor authentication vs two step verification" article in 2014, I've been waiting for an opportunity to irrefutably demonstrate the difference. Note: This article is very much a "work in progress" as until both exploits are patched, I can't provide any technical information. A quick recap... If you haven't yet read the above article, let's quickly recap on the differences between two-factor authentication & two-step verification. A "factor" falls into o
Identity theft & payment fraud?  That's ASDA price.
csrf

Identity theft & payment fraud? That's ASDA price.

Back in March 2014, I contacted ASDA to report several security vulnerabilities and despite a fix promised "in the next few weeks", little appears to have changed. @Stuho1mez All of our sites are secure, I would advise using Chrome. Thanks, Beth — Asda Service Team (@AsdaServiceTeam) January 14, 2016 After 677 days and several tweets along a similar vein, my patience has finally run out. What's the problem? Two of the simplest and most prevalent exploits allow an attacker to quickly &
acl

MyDish.co.uk Security - Missing a vital ingredient?

Update as of 15/03/13: I have received a number of emails asking for further comments on the situation @ MyDish. I firmly believe that every effort is being made to rectify the issues I've identified - and the insinuation that Carol or the team at MyDish have ignored the problem is entirely without merit.  Beyond that, I'm not prepared to discuss the matter any further at this stage.  If there are any updates, I will update this post accordingly. MyDish.co.uk is the brainchild of Carol Sav
companies house

Companies House Security Review - Part 2

Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go.  Directory traversal still possible... hint encode/escape or strip, don't add slashes!  Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs.  At least progress is being made...  can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure!  At this point, I'm not sure wh
companies house

Corporate Identity Theft - Perhaps the biggest risk is where you least expect it...

Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go.  Directory traversal still possible... hint encode/escape or strip, don't add slashes!  Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs.  At least progress is being made...  can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure!  At this point, I'm not sure w
santander

Santander aren't secure - Should we bank online?

"Your financial protection is our priority and we take this very seriously" "Our service actively protects both your identity and your finances." "We take every step possible to keep your finances and personal details safe." Confident statements; so you'd be forgiven for having equal confidence in their abilities to protect your information. In November 2011, I contacted Santander to alert them to several security concerns which needed to be addressed. Take the "online security" page for e