Language Selection

English French German Italian Portuguese Spanish

Glitch on Verizon Wireless Web Site Left Data at Risk

Filed under
Security

Verizon Wireless said yesterday that computer programming flaws in its online billing system could have allowed customers to view account information belonging to other customers, possibly exposing limited personal information about millions of people.

A spokesman for the Bedminster, N.J., company, a joint venture between Verizon Communications Inc. and Vodafone Group PLC, declined to say how many of the company's 45 million subscriber accounts were at risk. Verizon Wireless said the problem appeared to be limited to accounts for customers in the eastern United States who had signed up for its "My Account" feature.

There was no indication that anyone took advantage of the flaws or that any customer financial information, such as Social Security or credit card account numbers, was disclosed, Verizon Wireless spokesman Tom Pica said. The flaws also did not allow access to phone numbers associated with customers' incoming and outgoing calls, and "no customer data could be manipulated and changed in any way," Pica said.

Verizon Wireless said it had corrected the problem as of 2 a.m. yesterday. Pica said the company was still assessing whether it would notify customers about the situation.

The "My Account" feature has been available on the Verizon Wireless Web site for five years. Pica said the company does not yet know how long the flawed coding had been in place.

Pica confirmed the Web site flaw could have allowed a user to view another subscriber's balance of remaining airtime minutes and the number of minutes that customer had used in the current billing cycle. Two other flaws could have exposed data about a customer's general location -- city and state -- and the make and model of phone the customer uses, Pica said.

The flaw that exposed account information was reported to Verizon Wireless by Jonathan Zdziarski, a software developer from Milledgeville, Ga., who said he discovered it while writing a computer program that would automatically query his account online and report the number of minutes he had used from his wireless plan.

Zdziarski found that by simply entering another subscriber's wireless phone number on a particular portion of the site, he could pull up some information about that person's account.
Pica said the flaws did not expose customer account balances or latest payment information. But Zdziarski provided washingtonpost.com with a screenshot showing that the vulnerabilities exposed account balances and the date of the most recent payment, a claim that Pica said the company could not confirm.

After Zdziarski's alert, Verizon Wireless technicians reviewed other portions of the company's billing system and fixed one flaw but disabled the feature that allowed viewing of customer location until technicians could figure out a way to secure it, according to Pica.
Zdziarski said he later conducted other tests and found that the problem he discovered also could be exploited to transfer one customer's account to another handset, a technique known as "cloning."

The user of a cloned phone can intercept all of the victim's incoming wireless calls and make calls that would be billed to the victim's account. Zdziarski said he was prevented from fully testing whether the flaw could be used to clone Verizon Wireless phones because the service that allows customers to map existing phone numbers to new handsets appeared to be offline when he reported the flaw.

"This was a very easy hack to do," Zdziarski said. "I'm sure if I've discovered it, then certainly your typical 'script kiddie' could figure it out."

Pica said company technicians were unable to reproduce the phone-cloning scenario described by Zdziarski.

One of Verizon Wireless's competitors, Bellevue, Wash.-based T-Mobile International, disclosed in January that a security hole in its Web site exposed data on at least 400 customers, including a Secret Service agent. This year, a group of hackers used other flaws in T-Mobile's site to break into the phones of dozens of celebrities in an incident that exposed racy photographs and personal notes and contacts for hotel heiress and socialite Paris Hilton.

By Brian Krebs
The Washington Post

More in Tux Machines

Open spec SBC dual boots Android and Ubuntu on hexa-core RK3399

T-Firefly is Kickstartering the first hacker SBC with Rockchip’s Cortex-A72/-A53 RK3399. The Firefly-RK3399 has up to 4GB DDR3, M.2, and USB 3.0 Type-C. T-Firefly, which offers Linux- and Android-ready open source boards like the Firefly-RK3288 and sandwich-style Firefly-RK3288 Reload, both of which are based on the quad-core, Cortex-A17 Rockchip RK3288, has advanced to a more powerful Rockchip SoC for its new open spec Firefly-RK3399. The hexa-core Rockchip RK3399 features two server-class Cortex-A72 cores clocked to up to 2.0GHz, as well as four Cortex-A53 at up to 1.42GHz. This appears to be the first RK3399 SBC and the first SBC to include Cortex-A72 cores. Read more

Leftovers: Software

  • Manuskript is a Promising Open-Source Scrivener Alternative
    Whether you plan to work on a book, a screenplay, or better structure your dissertation, you’ll probably see apps like Scrivener recommended. If you’re running Windows, macOS or even Android then you’re spoilt for choice, with various competing proprietary apps at varying price points readily available. On Linux the choices are somewhat limited.
  • Tor 0.2.9 Is Just Around the Corner As 0.2.8.10 Fixes Memory Leak in OpenSSL 1.1
    The past weekend brought us new stable and development builds of the Tor anonymity network project, versioned 0.2.8.10, as the most advanced version out there, and 0.2.9.6 RC (Release Candidate).
  • Pitivi 0.98 Linux Video Editor Adds Customizable Keyboard Shortcuts
    Version 0.98 of the GNOME-aligned GStreamer-powered Pitivi non-linear video editor was tagged today as the newest development milestone. The main feature addition of Pitivi 0.98 is now supporting customizable keyboard supports! Aside from finally supporting customizable keyboard shortcuts for this open-source video editor, a lot of warnings were fixed from GTK 3.22, and there has been a lot of other bug fixing. Bugs around Pitivi's timeline were primarily targeted by this release.
  • Phoronix Test Suite 6.8-Tana Officially Released
    Phoronix Test Suite 6.8.0 is now available as the latest version of our open-source, fully-automated, reproducible benchmarking software for Linux, BSD, Solaris, macOS, Windows, and other operating systems. Phoronix Test Suite 6.8 is the latest stable release now of our GPL-licensed benchmarking software updated on its regular quarterly release cadence. Phoronix Test Suite 6.8 development focused on a number of low-level improvements to particularly benefit Phoromatic and the Phodevi (Phoronix Device Interface) software/hardware library abstraction layer.
  • iPerf As Another Network Benchmark Is Now Available Via The Phoronix Test Suite
  • Chromium-Based Vivaldi 1.6 Browser Enters Development, Brings Tab Stack Renaming
    Vivaldi's Ruarí Ødegaard informs us about the availability of a new snapshot for the cross-platform, Chromium-based Vivaldi web browser, which promises to let users name tab stacks. Vivaldi Snapshot 1.6.682.3 marks the beginning of the development of Vivaldi 1.6, the next major version of the popular web browser, and it looks like it has been rebased on Chromium 55.0.2883.64. Besides fixing a bunch of regressions, the new development release implements an option under Settings -> Tabs -> Tab Features -> Tab stacking -> Allow Tab Stack Renaming, which lets you rename or name tab stacks.

today's howtos