Feeds

Amazon purges account hijacking threat from site

XSS no more

The Essential Guide to IT Transformation

Amazon.com administrators on Tuesday closed a security vulnerability that made it possible for attackers to steal user login credentials for the highly trafficked e-commerce website.

The XSS, or cross-site scripting, bug on Amazon Wireless allowed attackers to steal the session IDs that are used to grant users access to their accounts after they enter their password. It exposed the credentials of customers who clicked on this link while logged in to the main Amazon.com page.

It was discovered by Nir Goldshlager, a researcher from security consulting company Avnet. It was purged from Amazon about 12 hours after The Register brought it to the attention of the website's security team.

"This is very bad news," web application expert Jeremiah Grossman of WhiteHat Security said of the flaw shortly before it was fixed. People who fell for the attack would likely be unaware anything was amiss "since it all takes place on Amazon's website."

XSS bugs are the most commonly found security vulnerability, Grossman added. A similar flaw was recently exploited to give malicious hackers access to a heavily fortified server operated by the security-conscious Apache Foundation. ®

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
Brit celebs' homes VANISH from Google's Street View
Tony Blair's digs now a Tone-y Blur
Computing student jailed after failing to hand over crypto keys
Sledgehammer once again used to crack a nut
Doctor Who season eight scripts leak online
BBC asks fans to EXTERMINATE copies before they materialise
Snowden leaks latest: NSA, FBI g-men spied on Muslim-American chiefs
US Navy veteran? Lawmaker? Academic? You're all POTENTIAL TERRORISTS
That 'wiped' Android phone you bought is stuffed with NAKED SELFIES – possibly
Infosec bods sound alarm after copping eyefuls of nudie pics
Russian MP fears US Secret Service cuffed his son for Snowden swap
Seleznev Jnr is 'prolific trafficker in stolen credit card data', it is alleged
'I don't want to go on the cart' ... OpenSSL revived with survival roadmap
Heartbleed-battered crypto library reveals long path back to health
Teensy card skimmers found in gullets of ATMs
Hi-tech fraudsters treading more softly, but gas still yielding bang for buck
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
The Power of One eBook: Top reasons to choose HP BladeSystem
Only the Power of One delivers leading infrastructure convergence, availability and scalability with federation, and agility through data center automation.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.