Feeds

Qwest exposes customer data

Pick a password, any password

  • alert
  • submit to reddit

The Power of One eBook: Top reasons to choose HP BladeSystem

Telecom giant Qwest Communications acknowledged Thursday that a glitch in its Web-based paperless billing system left some long-distance customer records exposed for over a week.

Qwest offers long-distance customers a price break if they forgo printed statements and pay their bills with a credit card though the company's Web site. Subscribers who avail themselves of the service are offered a choice of logging in with a phone number and calling card PIN, or a user-specified name and password.

Earlier this month the system stopped checking passwords, allowing anyone who enters a valid username to access that subscriber's billing record, including the type of phone service for which they're signed-up, their name and billing address, the name on any calling cards issued though the account, and a complete copy of their most recent phone bill.

"An unauthorized user could go in there, if they knew the username, and they could go on there and look at billing information," said company spokesperson Barbara Faulhaber.

Examining the source code of the billing accounts preferences page also yielded the customer's credit card number and expiration date, according to users who reported the problem.

Only long-distance customers who opted for the paperless billing option were affected by the leak -- a similar system used by Qwest's local phone subscribers was not exposed.

Qwest took the site offline for several hours Thursday to close the hole. But two of the users who discovered the issue say they reported it to Qwest last week, and fault the company for not taking action faster.

William Shanks, a California software engineer, first contacted SecurityFocus about the hole last Friday, and says he reported it to Qwest the previous Wednesday, May 15th. "I can confirm that they have had a ticket, and a customer service person walked through the issue since Wednesday morning," wrote Shanks in an e-mail interview. "When I followed up on last Friday, they claimed that the group responsible for the Web services were aware of it, and had been since at least Thursday... In my opinion, the site should have been taken down on Wednesday until fixed."

Jason Hetherington, a Texas-based law student, says he reported the bug on Monday of last week, after a friend who uses the paperless billing system complained that his password had become irrelevant. "He was a Qwest customer who said he was having problems changing his password," says Hetherington. "He was changing it, and it was still letting him in."

But Qwest's Faulhaber says the company didn't learn of the hole until Wednesday, May 22nd. "As soon as this came to our attention, we took our site down and fixed it," says Faulhaber.

The Web hole was apparently introduced when Qwest changed the terms-of-service for the site, and added a click-through page for customers to accept the new agreement during the login process.

Among other things, the terms-of-service disclaim the company of any responsibility for unauthorized access to user accounts.

© 2002 SecurityFocus.com, all rights reserved.

Designing a Defense for Mobile Applications

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.