Australia Post customers exposed in direct object reference flaw

By
Follow google news

Click and Send pulled offline.

Australia Post had withdrawn its Click and Send online service after a security flaw was uncovered that could expose the details of random customers.

Australia Post customers exposed in direct object reference flaw

News.com.au reported the insecure direct object reference vulnerability, which allegedly enabled users to expose others' details by altering a shipping ID number that appeared in the URL of a completed transaction.

Click and Send could be used to prepare postage documentation online, such as customs declaration forms, and pre-pay postage.

The service was particularly targeted at eBay customers, streamlining the way they sent items they had sold on the auction site.

Australia Post said in a statement that Click and Send had been "temporarily suspended due to a system error".

The service, which is now restored, was initially re-activated with another flaw that allowed customer names to be viewed, news.com.au reported.

A system administrator tipped off News Limited to the flaw after he allegedly reported it three times to Australia Post.

The organisation did not appear to have a formal information security reporting structure.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Austrade to replace its data centre core network

Austrade to replace its data centre core network

Log In

  |  Forgot your password?