Skip to main content

Privacy breach at Australian ISP Astratel

posted onMarch 31, 2006
by hitbsecnews

A SECURITY hole in Sydney internet provider Astratel's LiveBilling online account management system has seriously compromised its customers' privacy.

Astratel customer Nick Adams notified the ISP after he discovered that he could view billing information and call records for other customers, by lodging their phone number into an online query form.

Mr Adams also demonstrated that non-Astratel member could access the compromised web query service by transplanting code from the page where it was located and placing it at an alternative web address.

"There's no security moving between the pure members section and this LiveBilling part of the web site. You can put anyone's phone number and you pull their call records and their account balance," Mr Adams said.

Source

Tags

Privacy

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th