NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


UK Foreign Currency Exchange Service Leaks Sensitive Data

Credit card details and customer information exposed through SQL injection

By Lucian Constantin, Web News Editor

29th of September 2009, 12:04 GMT

Adjust text size:


Online FX website vulnerability exposes sensitive information
Enlarge picture
Multiple vulnerabilities discovered in the website of a UK-based company called OnlineFX, which conducts foreign exchange services, can be exploited to extract highly sensitive data from the underlying database. Credit card details and customer information are possibly compromised.

According to its own website, OnlineFX is a financial company based in central London and offers foreign currency exchange at low rates, bank money transfers to over 70 countries, as well as IT, marketing and corporate services. The onlinefx.co.uk flaws were disclosed by Romanian grey hat hacker Unu, who specializes in finding SQL injection vulnerabilities in high-profile websites.

The hacker notes that a poorly secured parameter allows executing SQL queries in the database. However, because the database server is MSSQL, the results of the queries are not displayed in the browser window. This type of attack is known as a “blind SQL injection” and requires special tools to exploit.

Unu used a specialized penetration testing application called Pangolin, developed by a Chinese security firm to see inside the database. According to the screenshots he published, the web server is running on Windows Server 2000 with a Microsoft SQL Server 2000 backend. Using the permissions obtained by exploitation of the flaw, Unu notes that he could have accessed anything on the entire computer.

The onlinefx1 database is of particular interest as it contains tables called Store_User_Info, Customer_Shipping_Info or Store_Order. Furthermore, the Store_Order table contains columns such as Card_No, Name_On_Card, Validation_Number and there are 77,726 records inside. Meanwhile, another table contains data such as customer login and password, first and last name, address, city, country, postal code phone or e-mail and the record count is 85,029.

Unu notes that he did not attempt to extract any information from the aforementioned columns as he is only interested in exposing vulnerabilities and not use them for malicious purposes. He also points out that the company did not reply to his attempts at contacting them.

Unu made his disclosure on Saturday and in an e-mail sent to us, he also revealed two other vulnerable parameters in the same website. Our messages sent yesterday morning to two different e-mail addresses belonging to the company also went unanswered.

Update: An OnlineFX spokeswoman has informed Softpedia over the phone that the vulnerabilities mentioned in this article have been addressed. She also noted that the company has thoroughly tested its website for similar flaws.

OnlineFX server information
Enlarge picture
OnlineFX Database table listing
Enlarge picture
OnlineFX Store_Order table
Enlarge picture
OnlineFX customer information columns
Enlarge picture

TAGS:

OnlineFX | foreign exchange | SQL injection | credit card | data breach
Read by 914 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 3 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


The Internet Archive Leaks Member Data

RBS WorldPay Websites Riddled with Security Holes

Hacked: ING Belgium, Dexia and HSBC France Websites

UK Parliament Website Hacked

Yahoo! Local Hacked

The Telegraph Website Leaks Subscriber Information

Orange French Portal Hacked

Tiscali.co.uk SQL Injection

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM