You are here: silicon.com > Software > Security Strategy

Security Strategy

M&S error sparks fears of hack attack

Retail giant Marks & Spencer has mistakenly exposed confidential systems information on its website that security experts claim could open the door to a cracker attack on customer data.

By Pia Heikkila

Published: 20 October 2000 00:10 BST

silicon.com viewer Stuart Hillston discovered the security hole last Saturday when he was surfing the marksandspencer.com site. Hillston clicked randomly on a broken link, which created an extensive error message. The message contained confidential material such as passwords, credit card dummies and other log-in information.

Speaking exclusively to silicon.com, Hillston said: "I clicked on one of the links and my screen was swamped with data. I figured out it was something that should not have been there once I looked at the information."

Neil Barrett, technical director at security consultancy IRM, who has worked on projects with the police, HM Inland Revenue, Customs & Excise and DERA, said: "The error message was created because of work being carried out on the site. Instead of the error message being a standard 'page cannot be found', the broken link created an extensive log file from Marks & Spencer's server."

Barrett - who has seen the error message - claims it contained information that could easily lead a cracker to confidential customer details. "The message gives out enough information for a nasty hacker attack. Information such as server passwords, log-ins and credit card dummies brings the attacker a lot closer to the back door - and therefore access to customer databases," he said.

Spencer Pratt, security specialist at Defcom, a hacking prevention company, backed up Barrett's claim. "The information should have never been available on the internet. It gives user names, system log-ins, operating system information, IP addresses, credit card limits - all of which gives anyone easy access into their systems. If the back end systems are holding customer data, it could have been easily accessed," he said.

Steve Wind-Mozley, research and development manager for marksandspencer.com, admitted that there was an error, but claims customer details were never at risk.

He said: "We don't believe credit card details were exposed on that file because they are not stored there. At no time do we believe the security of our customers' information was compromised."

SILICON SAYS: Marks and Spencer is one of the UK's most well-known and respected retail brands. Any online security lapse by such a 'big name' company is seriously damaging to consumer confidence. It should be setting standards in web security, not damaging ecommerce for every e-tailer in the land.

silicon.com is currently campaigning to give the Data Protection Commission the resources necessary to enforce the protection of consumer data on the internet. We want ecommerce companies to Back the Act. If you want to lend your support, mail us at backtheact@silicon.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Ecommerce Java Developer Java, J2EE, EJB, JSP, SQL

Division/Department Location 64 Clarendon Road, Watford, Hertfordshire Job Title Ecommerce Java Developer Java, J2EE, EJB, JSP, SQL Reports to ...

PHP / MY SQL / Java Script

Involved in developing PHP websites, content management systems, database backend and ecommerce systems for clients as well as site maintenance, the ...

Test Manager/APACS/ISO8583/Card Payments

Test Manager/APACS/ISO8583/Card Payments APACS/ISO 8583/Card Payments/Finance Background/EPOS knowledge/EFT/Internet protocol My client is based in ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: