Comments

One Misplaced Line of JavaScript Caused the Ticketmaster Breach

One Misplaced Line of JavaScript Caused the Ticketmaster Breach
Published on June 30, 2018 at 11:34PM
An anonymous reader quotes ITWire: Well-known British security researcher Kevin Beaumont says the breach of the British operations of American multinational ticket sales and distribution company Ticketmaster, that has led to the possible leak of tens of thousands of credit card details, was caused by the incorrect placement of a single line of code... Beaumont said Inbenta was providing a chat bot for website developers "by providing a single line of HTML which calls a JavaScript from Inbenta's Web server...." He pointed out that while Inbenta had provided Ticketmaster a customised JavaScript one-liner, the ticketing company had placed this chatbot code on its payment processing website without informing Inbenta it had done so. "This means that Inbenta's webserver was placed in the middle of all Ticketmaster credit card transactions, with the ability to execute JavaScript code in customer browsers," Beaumont said. This code had been altered by some malicious person back in February and the problems began at that point, he said. Beaumont warns businesses to be cautious with third-party JavaScript code in sensitive processes. "Check your supply chain. Because attackers are." And he also highlights how anti-virus tools started flagging the the script months before Ticketmaster announced the breach. "I can see the Javascript file being uploaded to a variety of threat intelligence tools from April through just before the breach announcement, so clearly somebody was looking into it."

Read more of this story at Slashdot.





Hope you like this please comment your view and share to your friends thanks for visiting bye guys meet you in next post
One Misplaced Line of JavaScript Caused the Ticketmaster Breach One Misplaced Line of JavaScript Caused the Ticketmaster Breach Reviewed by Kartik on June 30, 2018 Rating: 5

No comments:

Ad

Powered by Blogger.