Citigroup Breached, Experts Say Dumb Things
This week’s questionable security breach reporting comes courtesy of the Daily Mail, regarding the compromise of accounts on Citigroup’s web site: http://www.dailymail.co.uk/news/article-2003393/How-Citigroup-hackers-broke-door-using-banks-website.html
The “attack” (if you can really call it that), required a logged in user to simply modify the URL of an authenticated session to change a plaintext URL parameter containing their account number to another account number. That was all that was required – no coding, phishing, social engineering or other technique that requires any thought was needed. Anyone with a rudimentary understanding of how URL parameters work could have figured this out. I’m amazed nobody figured it out sooner.
What bothers me about the article, though, is that the “expert” and law enforcement representatives who are quoted make it sound like this was a sophisticated intrusion.
One expert, who is part of the investigation and wants to remain anonymous because the inquiry is at an early stage, told The New York Times he wondered how the hackers could have known to breach security by focusing on the vulnerability in the browser.
He said: ‘It would have been hard to prepare for this type of vulnerability.’
…
Law enforcement officials said the expertise behind the attack was a ‘sign of what is likely to be a wave of more and more sophisticated breaches’ by high-tech thieves.
(Emphasis added)
Nothing about changing a plaintext URL parameter requires expertise, and it would have been trivial to prepare for that kind of vulnerability. It’s nigh unbelievable that a financial institution would have such a bad security implementation, although if this is the state of expertise in this field, I suppose I shouldn’t be as surprised as I am.