Feeds

Glitch allows online shoppers to rip-off retailers

Right click and change the price

  • alert
  • submit to reddit

Remote control for virtualized desktops

A glitch in many systems for order fulfilment on the Web has been reported which allows the fraudulent to create their own online prices for goods.

The loophole in many ecommerce Web sites was discovered by ebusiness services company Alphakinetic.net during the course of developing ecommerce Web sites for its clients.

Alphakinetic founder Sam Chowdhury estimated that between 10 to 20 per cent of sites were vulnerable to the issue, which involves how payment information is passed between a merchant's site and a secure payment gateway.

The root cause of the problem is that when an Internet shopper passes through a checkout on a merchant's site, a click on the right mouse button might allow a shopper to edit the contents of the page - including the price of goods paid for.

Mark Rowlands, chief technical officer of Alphakinetic, said the problem was not with shopping basket software itself but rather with the lack of checks between a merchant site and a payment site that data had not been altered.

He added that the vulnerability was easy to exploit.

A story in today's Telegraph identifies a number of smaller Web sites that were vulnerable to the breach. These included Aloud.com, CheapNames.co.uk, and Welsh internet shop Wales Direct. ®

External links

Security hole threatens UK etailers
Alphakinetic's take on the problem

Related Stories

Travelocity drops customers' pants in public
Egghead doubts hackers got the goods

Internet Security Threat Report 2014

More from The Register

next story
MI6 oversight report on Lee Rigby murder: US web giants offer 'safe haven for TERRORISM'
PM urged to 'prioritise issue' after Facebook hindsight find
Assange™ slumps back on Ecuador's sofa after detention appeal binned
Swedish court rules there's 'great risk' WikiLeaker will dodge prosecution
NSA mass spying reform KILLED by US Senators
Democrats needed just TWO more votes to keep alive bill reining in some surveillance
'Internet Freedom Panel' to keep web overlord ICANN out of Russian hands – new proposal
Come back with our internet! cries Republican drawing up bill
prev story

Whitepapers

10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.