Feeds

Wanadoo in customer data security flap

Index browsing exposure uncovered

Security for virtualized datacentres

UK ISP Wanadoo has fixed a serious security problem that exposed the account information of many of its subscribers.

The flaw arose because its web servers were incorrectly configured, thereby allowing users to view the contents of an entire folder instead of just an index web page.

Because of this index browsing flaw, it was possible for snoops to uncover the real name, user name, password, email address, and web space sub domain of listed customers from the affected account recovery system web servers. No authentication would have been required to retrieve this data.

Postings on a Wanadoo user forum suggest the issue has existed for more than two years. However, there is no evidence that it has been exploited by hackers.

After the flaw came to light last weekend, Wanadoo acted to investigate the problem and roll out a fix.

In a statement, the ISP said: "Wanadoo can confirm that a small number of links to files containing customer details have been posted on the internet. Wanadoo would like to reassure customers that this was an isolated incident and as soon as we were made aware of the problem, the information was removed from the public domain.

"We are alerting those customers involved, advising them to change their password details. Our customers’ security is paramount and we take this situation extremely seriously. An investigation is currently taking place to uncover how this happened and ensure that this does not happen again." ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.