Follow Us

Royal Bank of Scotland fixes data-stealing flaw

Three weeks later.

The Royal Bank of Scotland (RBS) has fixed a cross-site scripting flaw in its Worldpay Internet payments service that could have allowed attackers to steal users' credit card details, according to a report.

Adam Grit discovered the cross-site scripting (XSS) flaw in a secure payment page of the Worldpay site, RBS' Internet payments service, according to a report from IT industry journal The Register.

The flaw allowed third parties to inject content into the page, as Grit demonstrated with a pop-up window reading "Is it safe?"

An attacker could have taken advantage of the flaw to inject a false login box and steal user credentials, Grit said.

"I have tested this and confirm that unfortunately it does work on the live Worldpay website," Grit wrote in a 29 April email to RBS, quoted in the report. "Potentially, a fraudulent website could send the user to the Worldpay website in order to pay for their purchase, with all of the credit card details being then sent back to the hacker's server."

The flaw reportedly remained in place until Monday, a delay of three weeks, but has now been patched.

The page affected was protected by an SSL certificate, which industry bodies have said can instill a false sense of security.

In newer browsers, SSL-protected sites are downplayed in favour of those using Extended Validation SSL, which requires more thorough validation of the body requesting the certificate.

Last week eBay's PayPal acknowledged a similar XSS flaw that affected a page using an EV-SSL certificate, casting doubt on the claims of EV-SSL to assure users of more secure web pages.

RBS did not immediately respond to a request for comment.




Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *