Allphones hack exposes staff passwords

Powered by SC Magazine
 

Hacker claims 703 accounts listed.

Telecommunications retailer Allphones has had hundreds of staff usernames, passwords and company administrator logins exposed following a hacking attack.

The breach occurred when the company's web administration interface was accessed through a SQL injection attack that targeted the Allphones website. 
 
The affected webpage
The affected webpage
 
SC Magazine Australia informed the Allphones website designer of the breach including the vulnerable link and a captured HTML page of the admin console.
 
Further vulnerable links were later discovered and shut down, and affected accounts were disabled. 
 
Table names were visible on the administration console which was accessed by the hacker using the Havij SQL injection tool.
 
SC sighted a file that contains a sample of clear text staff usernames and passwords, along with store names, and a string of what appeared to be email addresses and passwords used to access the Allphones 'webclub' customer loyalty program.   
 
The hacker claimed 703 staff credentials were listed, along with 23,077 entries in the Allphones webclub. The sample contained 40 listings and many more duplicate entries. Four adminstrative passwords were also exposed.
 
Allphones has more than 170 locations across Australia, according to its website.
 
Allphones has been contacted for comment.

Copyright © SC Magazine, Australia


Allphones hack exposes staff passwords
Credit: Allphones Facebook page
 
 
 
Top Stories
Abbott brings back Science minister in cabinet reshuffle
Science tacked onto to Industry title.
 
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
 
Credit: Allphones Facebook page
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  4%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  3%
 
A Federal Government agency (ATO, Centrelink etc)
  19%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1902

Vote
Do you support the abolition of the Office of the Information Commissioner?