Dodo customers exposed by insecure direct object reference hole

By
Follow google news

Timeout script failed.

Name, address, phone numbers and account details of Dodo Power and Gas customers have been exposed thanks to two security gaffes which made online statements publicly accessible.

Dodo customers exposed by insecure direct object reference hole

Users could access accounts for up to 500 customers via an insecure direct object reference vulnerability which granted access when URL address were correctly manipulated.

The flaw was one of the most common affecting online websites.

The number of affected Dodo Power and Gas customers was limited to between 100 to 500 people because the statements were posted only at a customers' request,

Each statement was made available for "a number of hours", Dodo chief Larry Kestelman told the SMH which first reported the story.

The statements were supposed to be deleted earlier by an automated script which had failed.

Kestelman said the company had fixed the flaw.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Microsoft can't kill dogged researcher's Copilot for Word worm

Microsoft can't kill dogged researcher's Copilot for Word worm

Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch

Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Arch Linux halts package adoptions after malware hijacking wave

Arch Linux halts package adoptions after malware hijacking wave

Log In

  |  Forgot your password?