Bank of America Giving Access to Random Accounts
privateinternetaccess.com
privateinternetaccess.com
They never admitted it, but I'm 100% sure that the issue was that (in SQL Server) they were doing:
select @@identity
Rather than the correct call of: select scope_identity()
The former retrieves the identity of the latest record entered into the table regardless of what SQL statement produced the record (such as another user connecting to the database from a different connection thread); the latter retrieves the identity of the record entered from the current session.I thought that the difference had to do with what's returned if a trigger does an insert or something like that...
More fun @ http://msdn.microsoft.com/en-us/library/ms187342.aspx
Naturally, I recorded this with Quicktime and then called WF. Their response: "It's not a big deal -- neither accounts can withdraw money." After repeatedly explaining how serious this is for identity theft, I was told to wait 10 days. Their solution was to shutdown my online account without notice. If no one can login, then it's safe!
It took over a month to get this resolved, and once I could download my statements, I "cancelled" my account. WF is like Hotel California though -- a year and many phone calls later, my accounts still aren't closed.
Pics related: http://i.imgur.com/T77ni.jpg http://i.imgur.com/WdiZK.jpg
No it's not clear. You're just looking at some HTML on the screen, it may have come out of some stale cache and have nothing to do with the session's current permissions. You might try to do the transfer and find that the internal state of your session is so hosed that you can't do anything.
Though you're right, it's a possibility :(
United, in spite of all their other faults, handled it fairly well at least and responded quickly.
Also, it isn't FDIC insurance at issue, read up on Reg E claims. Retail customers have a generous route by which they can dispute electronic charges to their bank accounts.
WELP
But yeah, that sort of site is a no-brainer to be filtered.
The newest version ate up $12MM and is very cool! One of the things I like is that when you create an internal ticket that something is broken, IT Dept has access to all your computer activity; no more screen shoots, error descriptions, etc, everything is recorded on the fly. They can rewind your PC activity 10 minutes (or whatever) prior and see exactly all the steps you took for the error to occur. Very time saving troubleshooting approach.
Edit: ok I meant they can rewind and play your interaction with the intranet systems per say, not the computer alone. But they are locked down pretty much anyways.
http://www.smh.com.au/it-pro/security-it/super-bad-first-sta...
In this particular case with Bank of America, a user did nothing out of the ordinary to expose information and reported it proper.
Just my 2 cents.
The sad state of affairs is that a lot of companies are more interested in security via cheap obscurity, and will gladly go after the person who dared to publicize their security holes.
"In rare situations, usually due to application errors, session data intended for one client might be seen by another client. This situation is referred to as session data crossover. When the DebugSessionCrossover custom property is set to true, code is enabled to detect and log instances of session data crossover. Checks are performed to verify that only the session associated with the request is accessed or referenced. Messages are logged if any discrepancies are detected. These messages provide a starting point for debugging this problem. This additional checking is only performed when running on the WebSphere-managed dispatch thread, not on any user-created threads."
http://www14.software.ibm.com/webapp/wsbroker/redirect?versi...
The most convincing explanation I received was that it was a cookie collision. Very small chance, but still possible...