{"id":3498,"date":"2011-06-14T19:16:23","date_gmt":"2011-06-14T23:16:23","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=3498"},"modified":"2021-07-06T17:17:07","modified_gmt":"2021-07-06T21:17:07","slug":"citi-accounts-were-hacked-via-url","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2011\/06\/14\/citi-accounts-were-hacked-via-url\/","title":{"rendered":"Citi Accounts Were Hacked via URL"},"content":{"rendered":"<p><a href=\"http:\/\/consumerist.com\/2011\/06\/how-hackers-stole-200000-citi-accounts-by-exploiting-basic-browser-vulnerability.html\">The Consumerist<\/a> (via <a href=\"http:\/\/twitter.com\/#!\/mattgemmell\/status\/80763443422040064\">Matt Gemmell<\/a>):<\/p>\n<blockquote cite=\"http:\/\/consumerist.com\/2011\/06\/how-hackers-stole-200000-citi-accounts-by-exploiting-basic-browser-vulnerability.html\"><p>Basically after you logged into your account as a Citi customer, the URL contained a code identifying your account. All you had to do was change around the numbers and boom, you were in someone else&rsquo;s account.<\/p><\/blockquote>\n<p><a href=\"http:\/\/www.nytimes.com\/2011\/06\/14\/technology\/14security.html\">The New York Times<\/a>:<\/p>\n<blockquote cite=\"http:\/\/www.nytimes.com\/2011\/06\/14\/technology\/14security.html\"><p>The method is seemingly simple, but the fact that the thieves knew to focus on this particular vulnerability marks the Citigroup attack as especially ingenious, security experts said.<\/p>\n<p>One security expert familiar with the investigation wondered how the hackers could have known to breach security by focusing on the vulnerability in the browser. &ldquo;It would have been hard to prepare for this type of vulnerability,&rdquo; he said.<\/p><\/blockquote>\n<p>If this is what it sounds like, it&rsquo;s absurd to call it a vulnerability in the browser, and neither ingenious nor hard to prepare for.<\/p>","protected":false},"excerpt":{"rendered":"<p>The Consumerist (via Matt Gemmell): Basically after you logged into your account as a Citi customer, the URL contained a code identifying your account. All you had to do was change around the numbers and boom, you were in someone else&rsquo;s account. The New York Times: The method is seemingly simple, but the fact that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2018-11-26T19:10:37Z","apple_news_api_id":"91224381-6776-474f-b251-5cb52bb8d1f2","apple_news_api_modified_at":"2021-07-06T21:17:10Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AkSJDgWd2R0-yUVy1K7jR8g","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1755,2095,355,96],"class_list":["post-3498","post","type-post","status-publish","format-standard","hentry","category-technology","tag-breach","tag-exploit","tag-privacy","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/3498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=3498"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/3498\/revisions"}],"predecessor-version":[{"id":3499,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/3498\/revisions\/3499"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=3498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=3498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=3498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}