Feeds

Glitch allows online shoppers to rip-off retailers

Right click and change the price

  • alert
  • submit to reddit

Build a business case: developing custom apps

A glitch in many systems for order fulfilment on the Web has been reported which allows the fraudulent to create their own online prices for goods.

The loophole in many ecommerce Web sites was discovered by ebusiness services company Alphakinetic.net during the course of developing ecommerce Web sites for its clients.

Alphakinetic founder Sam Chowdhury estimated that between 10 to 20 per cent of sites were vulnerable to the issue, which involves how payment information is passed between a merchant's site and a secure payment gateway.

The root cause of the problem is that when an Internet shopper passes through a checkout on a merchant's site, a click on the right mouse button might allow a shopper to edit the contents of the page - including the price of goods paid for.

Mark Rowlands, chief technical officer of Alphakinetic, said the problem was not with shopping basket software itself but rather with the lack of checks between a merchant site and a payment site that data had not been altered.

He added that the vulnerability was easy to exploit.

A story in today's Telegraph identifies a number of smaller Web sites that were vulnerable to the breach. These included Aloud.com, CheapNames.co.uk, and Welsh internet shop Wales Direct. ®

External links

Security hole threatens UK etailers
Alphakinetic's take on the problem

Related Stories

Travelocity drops customers' pants in public
Egghead doubts hackers got the goods

Build a business case: developing custom apps

More from The Register

next story
Assange™: Hey world, I'M STILL HERE, ignore that Snowden guy
Press conference: ME ME ME ME ME ME ME (cont'd pg 94)
Premier League wants to PURGE ALL FOOTIE GIFs from social media
Not paying Murdoch? You're gonna get a right LEGALLING - thanks to automated software
Online tat bazaar eBay coughs to YET ANOTHER outage
Web-based flea market struck dumb by size and scale of fail
Amazon takes swipe at PayPal, Square with card reader for mobes
Etailer plans to undercut rivals with low transaction fee offer
US regulators OK sale of IBM's x86 server biz to Lenovo
Now all that remains is for gov't offices to ban the boxes
XBOX One will learn to play media from USB and DLNA sources
Hang on? Aren't those file formats you hardly ever see outside torrents?
Class war! Wikipedia's workers revolt again
Bourgeois paper-shufflers have 'suspended democracy', sniff unpaid proles
'Aaaah FFS, 'amazeballs' has made it into the OXFORD DICTIONARY'
Plus: 'EE, how shocking, ANOTHER problem I face with your service'
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.