Security flaw exposed in Cahoot bank accounts

'So simple the hackers didn't even think to look for it', says one security expert...

NEWS Internet bank Cahoot, owned by Abbey, has been exposed for a flaw in its online security which enabled users to move freely in and out of other customers' accounts.

The problem was a result of an upgrade 12 days ago and was discovered by a customer who had bookmarked areas of his online bank account. He then discovered he was able to access those areas on future visits to the site without entering any more than his user name.

When he began tinkering with the site he discovered he was also able to access other customers' accounts simply by guessing user names and then moving to a bookmarked page.

The process of guessing user names is far from rocket science given the likelihood of there being a number of variations on popular names - such as John Smith or John Brown.

Security consultant Neil Barrett told silicon.com this morning that he had witnessed a number of tests of this method in a controlled environment and confirmed one such common name, written in surname and first initial format, yielded instant access to one account.

Barrett told silicon.com he was shocked at how easy it was.

He added: "I think the ease with which it was possible to access these accounts may have been Cahoot's saving grace. It was so very simple it is likely it fell below the radar of the hackers."

It's not uncommon for wannabe hackers to surf secure sites removing and replacing parts of a URL in an attempt to gain access to accounts, but Barrett confirmed there was no specialist knowledge required in this instance.

However, a spokeswoman for Abbey told silicon.com this morning that the customer who discovered the flaw has been in touch regularly with the bank in the past "raising various security issues, all of which have been answered to his satisfaction".

But this time it would appear his concerns over the latest discovery were justified.

Cahoot was forced to take the site down for 10 hours while it fixed the flaw.

The Abbey spokeswoman said during that time the previous system was put in place and independently tested by Qinetiq and found to prevent this particular breach - confirming it was the systems upgrade which was responsible.

Barrett believes Cahoot may not be only bank affected, warning that others who have adopted the same system could "be open to the same level of exposure".

Comments

There are 2 comments. Join the discussion

  1. 1. tim newton

    Best online banking security has to be here in Hungary. You log in with user name and password, and the system then sends an SMS to your mobile with a further access code, which is only valid for 4 minutes. Brilliant !

    • 5 November 2004 12:46
    • Add comment
  2. 2. John Robinson

    Are you taking the mickey with Cahoot ads at the foot of the page?

    • 5 November 2004 13:15
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters