Skip to main content

UK phone giant EE hit by another security lapse

The post UK phone giant EE hit by another security lapse appeared first on BardTech.

For the second time this week , U.K. phone giant EE has fixed a security lapse, which allowed a security researcher to gain access to an internal site.

The researcher, who goes by the pseudonym Six, found the company’s internal training site indexed on Google. (We’re not linking to the page as it remains an active site.) Although the site required an employee username and password to log in, the researcher found that an “admin” account existed, of which anyone with the answer to the secret question could reset the password.

It turns out that secret question could have been stronger.

“What is your eye color,” the researcher told TechCrunch. “I tried loads of colors and they all give an error,” he said. “The answer was simply ‘brown,’” he said.

From there, he gained access to the entire internal training site.

EE is the largest phone network in the U.K. with more than 30 million users.

TechCrunch reported the security lapse to the company on Wednesday. A spokesperson for EE said a fix was implemented early Thursday, and thanked the researcher.

“This account has now been disabled and we have also changed the password and security question for the account,” said a spokesperson. “No customer data is, or has been, at risk as the user account on the training website only gave access to a dummy environment with fake accounts.”

But the researcher disputed part of EE’s response, accusing the company of downplaying the security incident.

The researcher shared several screenshots with TechCrunch of the site. According to the site’s login page, the portal is the “home of training” for all EE staff. Employees are given access in the first week of their start date, and can access the site for the first time with a password which is their “surname all in lower case.”

Some screenshots showed dummy data, but others showed course content and employee knowledge base resources. He said that he had access to training on linked organizations, including Orange and Plusnet.

Although the researcher found no employee or customer data, he said the admin account allowed him to grant himself “any permissions” he wanted, and change the access of any other group of users, he said.

“I didn’t do any of that because of the law, but that doesn’t mean a malicious attacker couldn’t have done it,” he said.

Earlier this week, EE fixed a vulnerability that allowed customers to gift their own or linked accounts unlimited data for free. The company fixed the bug within two days.

Original Content By TechCrunch

The post UK phone giant EE hit by another security lapse appeared first on BardTech.



Tags: cellphones, cybersecurity, data, EE, Password, Security, another, giant, lapse, phone, security

Original link: here
via BardTech

Comments

Popular posts from this blog

How to change the PIM of a VeraCrypt volume

The developers of VeraCrypt introduced Personal Iterations Multiplier (PIM) functionality in the encryption program in version 1.12 . PIM stands for "Personal Iterations Multiplier". It is a parameter that was introduced in VeraCrypt 1.12 and whose value controls the number of iterations used by the header key derivation function. PIM is used by volumes even if the creator of the volume did not specify a value. It is an optional component that improves security: it adds another step to the authentication process similarly to two-factor authentication. The main difference is that the PIM value is fixed and not generated on the fly when requested. An attacker needs to know the master password and the PIM, if not set to default, to breach the encryption successfully and access the content of the drive or partition. A couple of good reasons exist to change the PIM value: It was leaked or stolen. The default value is used and that is not as secure as using a custom PIM. Yo...

Huawei Mate 20 Pro launched in India with Kirin 980 for ₹69,990 ($988)

For years, the highest-end Android flagship used to be defined by Samsung’s Galaxy Note series as the “best-of-the-best” Android phones. Google entered the premium smartphone segment in 2016 with the Google Pixel . In addition, one company that has been steadily improving its flagship phones is Huawei. Huawei has also been steadily increasing the prices of its flagship phones at the same rate. Indian consumers, however, were left out as Huawei had not opted to launch any Mate series phone in India before. This year, as the company’s strategy has changed, high-end flagship smartphone buyers now have another option to choose from. The Huawei P20 Pro was launched in India in April . Now, Huawei has launched the Huawei Mate 20 Pro in India—the first ever launch of a Mate series phone in the country. The Huawei Mate 20 Pro is the successor of the Huawei Mate 10 Pro . It’s positioned as a higher-end variant of the standard Huawei Mate 20. It should be noted that Huawei didn’t launch the s...

The 5 Best Free IPTV Apps to Watch Live TV on Android

It’s easier than ever to watch on-demand TV shows and movies on your Android device. But what about live TV? Yes, there are services like Sling and PlayStation Vue. However, if you know where to look, you don’t need to subscribe to their expensive plans. You can use free IPTV instead; you just need an IPTV app and an IPTV source. What Is an IPTV App? IPTV apps are a bit like Kodi; they are empty shells that can’t stream any content without some user input. You have the responsibility for adding channels, playlists, and other sources. Typically, you cannot use the apps to watch Netflix, Hulu, or direct content from other third-party providers. Here, we’re not interested in the best on-demand streaming apps or places to watch TV online. We are only looking at the IPTV apps themselves. Specifically, we want to know what the best IPTV apps on Android are. 1. Lazy IPTV Our first pick is Lazy IPTV. It supports M3U playlists in open-view, ZIP, and GZ formats. The app can also read pl...