News: 1598508307

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

'My wife tried to order some clothes tonight. When she logged in, she was in someone else's account ... Now someone's charged her card'

(2020/08/27)


"At the moment some stranger is in her account as they keep adding things to her basket and she keeps taking them out."

A Reg reader last night spoke of the horrifying moment he realized an online store used by his wife was mixing up some of its online customers, allowing people to gain access to some strangers' personal information and order carts. In what appears to have been a server-side caching blunder, it was possible on Wednesday to click around the site, and whether logged in or not, see pages belonging to others, complete with their details and orders, we're told.

What's more, during the security lapse, at least one person placed an order as another customer, charging that stranger's credit card, it was claimed. The website in question, we're told, belonged to uber-trendy fitness clothing e-shop Fabletics, operated by the TechStyle Fashion Group, previously known as JustFab Inc.

The glitch, which was said to have affected desktop and mobile versions of the site, now appears to have been fixed. The Register has obtained screenshots of web pages containing strangers' details, including names and phone numbers, served at random from the not-strictly-safe-for-work dotcom.

"My wife has an account with Fabletics," our reader, who asked to remain anonymous, told us. "She tried to order some items tonight, but it turned out when she logged in, she was in someone else's account. At the moment some stranger is in her account as they keep adding things to her basket, and she keeps taking them out.

My wife's credit card was hit with transactions tonight

"By clicking around in their site I can access random customer personal details. Name, email, telephone number, address, account details, order history, etc. I could change someone's address if I wanted and maybe get stuff delivered. My wife informed them by phone but they didn't seem to think it was that serious. Not sure they realize how much their site is messed up."

Soon, their worst fears came true. "My wife's credit card was hit with transactions tonight from Fabletics," he added. "Clearly other people had access to her account. The bank phoned to check if they should block them as they flagged them as suspicious. Well done, Fabletics."

Meanwhile, another Reg reader, who also wished to remain anonymous for privacy reasons, alerted us after their daughter noticed something strange.

"She had been on the site and got someone else's details," our informant told us. "So I tried it myself: if you go on the site on mobile and browse any page other than homepage, it will log you in, you can then go to the customer details page, and see everything."

Cloudbleed: Big web brands 'leaked crypto keys, personal secrets' thanks to Cloudflare bug [1]READ MORE

Here's a third Reg reader's experience of the privacy blunder. "I saw a YouTube advert for a pair of men's shorts on Fabletics so I googled them, clicked the main page link, and it appeared as if I was logged-in as a user – I've never used them before," our anonymous tipster explained. "I clicked around and got to see a whole bunch of strangers' details."

This whole affair reminds us of the time Three UK's website [2]accidentally revealed to visitors other customers' names, postal addresses, phone numbers, email addresses and more – all without asking for a login.

Valve's Steam store also once [3]spewed players' private profiles to strangers, due to a caching issue. This tends to happen when a website employs a cache to serve previously generated pages quickly, thus avoiding building them on the fly every time they are requested. However, it all goes a little pear-shaped if the cache hands out the wrong pages to people.

California-based TechStyle Fashion Group did not reply to requests for comment. Messages from its customer service team, seen by The Register , confirmed the multimillion-dollar online souk was aware of reports of data leaking from its pages, and was treating the kerfuffle as a matter of urgency.

We'll let you know as and when we get more info. ®

Tell us something we don't know: [4]Tip us off securely .

Get our [5]Tech Resources



[1] https://www.theregister.com/2017/02/24/cloudbleed_buffer_overflow_bug_spaffs_personal_data/

[2] https://www.theregister.com/2019/02/01/three_uk_data_breach_no_authentication_blunder/

[3] https://www.theregister.com/2015/12/30/steam_security_blip_explained/

[4] https://www.theregister.com/about/company/contact/

[5] https://whitepapers.theregister.com/

Louis Schreurs

stupidity all around

I hate modern times

I must be getting passed a certain age and nearing another certain age.

Methinks

Anonymous Coward

Past do, past do...

Matches.

JimPoak

This sounds familiar. Three were doing the same thing. I hate organizations who deploy systems without proper support or understanding of the pitfalls they maybe exposing their customers to . It's like giving an infant a box of matches and expecting not to get burned ! If you cannot make them understand try deleting accounts that would get their attention.

Sgned angry mob

British Gas

Andy Non

When I used to pay my bill online by card it always gave me the amount paid by a random stranger paying their bill and their name on the final screen. They were obviously losing track of customers online sessions at the final page. Tried contacting BG about the issue but they weren't interested and this problem carried on for a year or more! Wouldn't surprise me if it was still doing the same thing, but I'm no longer with BG anyway. The issue wasn't too serious in terms of what was leaked but their site shouldn't be leaking or mixing up different users sessions at all.

Someone refresh my memory

Tessier-Ashpool

Wasn’t there a UK government website quite a few years ago that got up to these kind of tricks? It got pulled sharpish. But damned if I can remember what it did.

Cache at your peril

tiggity

Seen (and read about) caching go wrong so often.

Obv it can give a big performance improvement, but needs great care on how its setup (depending how your website(s) work) and an awful lot of proper multi user testing on a test system before doing it live.

Re: Cache at your peril

David Lewis 2

... an awful lot of proper multi user testing on a test system before doing it live.

No, they are just following the modern trend of using live users as their test environment.

Well if it is good enough for Microsoft ...

Fabletics?

Mage

Sounds like a title for a book about magical blood sucking insects?

Apart from the incompetent server mangelment why do they think it's a good name for selling fashion sportswear aka athleisure?

step one: ring your card provider

Cederic

The moment I see anything like this it's straight on the phone to my card provider to tell their fraud department that any transactions with that site did not come from me.

From that point on the Financial Services industry wheels will start to grind the site into oblivion. Which is how it should be.

Walmart?

Chairman of the Bored

I do not use their online ordering / delivery service.

Imagine my surprise when a Walmart box shows up at my door, properly addressed. I opened it and found four large boxes of incontinence briefs. I'm getting old, but not that old!

Called Wally world and they had no idea how it was ordered and didn't seem to care that I had them... "just drop it at a store, or keep it"

Other boxes appearing from the void this past year: 4 large tubes of personal lube, a box of relatively edible food, and a box of junk food.

Credit Card theft

Flak

So wrong when it comes to political correctness, but still makes me smile:

"My wife's credit card was stolen a few months ago - I didn't report it because the thief is spending less than she did!"

Even Outlook

Manolo

On two seperate occasions, arriving at work and logging in to my Microsoft 365 account, I found myself in a coworker's email.

Notified Microsoft, never heard back from them. Must have been some caching issue as well.

Credit card? What credit card?

ThatOne

I never ever leave my credit card details on shopping sites. If "don't remember" isn't an option, I simply delete it from my profile after my purchase. And if they really, really insist on having one, they get fed a dead credit card number instead (old, now blocked card), which obviously won't work if used. I change it back when/if I actually need to pay for something again.

Inconvenience? Not for me, my credit card details are in my password manager, and I can fill them back in in 2-3 clicks.

Cost is king

Trollslayer

By that I include the customers which means the sellers cut every corner they can.

If you float on instinct alone, how can you calculate the buoyancy for
the computed load?
-- Christopher Hodder-Williams