Originally posted by: chuck2002
Happy Valentines.....
SECURITY ADVISORY
FTD.COM Leaks Credit Card Numbers to the Internet
Gerald Quakenbush, CISSP, NSA-IAM
February 12, 2003
Overview
Serious security flaws exist in the way the popular
http://www.ftd.com web site is
configured and in its software that allows any hacker with kindergarten
level skills to retrieve information, unauthorized, from the site. It is
trivial to retrieve customer data, including credit card numbers, expiration
dates, account names, shipping addresses and anything else FTD knows about
the consumer.
Details
Two errors combine to make this a very serious, very urgent issue. First,
FTD has very deeply flawed session tracking logic. Secondly, server
configuration flaws allow users to connect without using SSL. These issues
are independent of each other; however, the ability to connect without SSL
simplifies the attack.
The session logic is deeply flawed. The session logic is about as simple as
session logic can get - they use an integer to track unique visitors and the
integer is simply incremented from one user to another. In order to retrieve
someone else's confidential information (yes, their credit card number among
other things) one only needs to transmit a simple request and vary a cookie
value in order to read client data.
Status
FTD has been contacted and advised of the issue. Due to the simplicity of
exploiting the attack, it was deemed necessary to alert friends, family,
country and planet to the risk.