PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Three exposed Brit’s privates with sloppy survey code

Posted on June 19, 2015 by pogowasright.org

Darren Pauli reports:

Hacker Joseph Redfern has reported a privacy flaw at UK telco Three, which exposed names and email addresses in online surveys.

The telco shuttered the offending survey site and the exposed API which returned the private information in JSON forms when a user entered data.

Refern says the flaw meant any phone number could be keyed into the clear text requests. Doing so would produce the real name and email address of the owner.

“The site was making an AJAX request to an API … over cleartext HTTP passing my mobile phone number in the URL,” Redfern says.

Read more on The Register.

Category: BreachesBusinessNon-U.S.Online

Post navigation

← Spy court clears path to renewing NSA powers
Samsung’s security failures leave 600 million Android users vulnerable to simple keyboard hack →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed

RSS Recent Posts on DataBreaches.net

  • International cybercrime tackled: Amsterdam police and FBI dismantle proxy service Anyproxy
  • Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
  • N.W.T.’s medical record system under the microscope after 2 reported cases of snooping
  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy