iTnews
  • Home
  • News
  • Technology
  • Security

Security risk spotted on Qantas site

By Brett Winterford
Nov 30 2010 6:55AM
Follow google news

Mysterious XSS vulnerability could be bad news.

Security researchers have noted a security vulnerability lurking on the online booking website for airline Qantas.

Security risk spotted on Qantas site

The cross-site scripting vulnerability was discovered by an anonymous user and submitted to security watchlist XSSED.com - the second time the integrity of Qantas' web properties has been called into question by the publication.

 

Security experts monitoring the site are as yet unsure of what data - if any at all - the script is capable of stealing from the page.

"XSS (cross-site scripting) is one of the most common tools in the hacking trade," noted Kane Lightowler, regional sales director at IT security vendor Imperva.

"XSS allows an attacker to inject malicious software into websites that are, in turn, accessed by unwary consumers who are often asked to provide credentials such as usernames, passwords or credit card information."

Lightowler noted that "nearly every major website today has been affected by XSS attacks, including Facebook and Twitter."

UPDATE - Tuesday 3pm - Qantas has responded to this story.

"Qantas takes a proactive approach to detecting and responding to these sorts of issues. We are aware of the issues identified by XSSED.com and are currently in the process of implementing changes to remedy any associated vulnerabilities."

UPDATE - Tuesday 3:20pm

Qantas has confirmed the problem has been resolved. "We have also confirmed that there was no threat to the personal information of our customers," an airline spokesman said.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
crosssiteqantasscriptingsecurityxss

Related Articles

  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
  • US gov shortens cyber fix window to three days US gov shortens cyber fix window to three days
  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
Join our WhatsApp Channel

Partner Content

Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.