Halfords suffers a puncture in the customer details department
- Reference: 1655973007
- News link: https://www.theregister.co.uk/2022/06/23/halfords_data_leak_vulnerability/
- Source link:
Like many, cyber security consultant [1]Chris Hatton used Halfords to keep his car in tip-top condition, from tires through to the annual safety checks required for many UK cars.
In January, Hatton replaced a tire on his car using a service from Halfords. It's a simple enough process – pick a tire online, select a date, then wait. A helpful confirmation email arrived with a link for order tracking. A curious soul, Hatton looked at what was happening behind the scenes when clicking the link and "noticed some API calls that seemed ripe for an IDOR" [Insecure Direct Object Reference].
[2]
Armed with an email address, Hatton was able to extract all manner of information about his booking, including his telephone number, car details, and the exact location of his home.
[3]
[4]
A few months later, Hatton decided to book a service and received, once again, an email exposing another exploitable endpoint. This time an email wasn't required. Just an ID. "It is simply an ID that increments with each order," he said.
Again, all customer details associated with that ID could be retrieved. He tried incrementing the ID and other customers turned up. "Through the Order ID," he said, "it seems likely that hundreds of thousands (if not millions) of different orders can be found, each containing [personally identifiable information]."
[5]Okta says Lapsus$ incident was actually a brilliant zero trust demonstration
[6]Info on 1.5m people stolen from US bank in cyberattack
[7]1Password's Insights tool to help admins monitor users' security practices
[8]Voicemail phishing emails steal Microsoft credentials
In January, Hatton responsibly contacted Halfords to warn the company of the vulnerability. Sadly, his efforts were rewarded mostly by a stony silence until The Register got in touch.
A spokesperson told us: "Halfords takes the security of our customer data very seriously.
[9]
"In this case we've been made aware of a potential vulnerability in one of our customer-facing systems. No bank or payment details have been at risk.
"We've removed the vulnerability and we'll be implementing an immediate review of our screening protocols to help ensure this doesn't happen again."
The Register contacted UK watchdog the Information Commissioner's Office (ICO) and was told: "We do not appear to have received a data breach report from Halfords on this matter.
[10]
"Not all data breaches need to be reported to the ICO. Organizations must notify the ICO within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people's rights and freedoms."
The incident is reminder of the need for organizations to provide an open channel of communication for researchers and, for goodness' sake, to stop ejecting customer details upon the slightest prod. ®
Get our [11]Tech Resources
[1] https://twitter.com/hattonsec
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrQ5xNOGAK@59Il-NlQmWgAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrQ5xNOGAK@59Il-NlQmWgAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrQ5xNOGAK@59Il-NlQmWgAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2022/06/22/okta_lapsus_zero_trust_explanation/
[6] https://www.theregister.com/2022/06/21/flagstar_bank_breached_ssn/
[7] https://www.theregister.com/2022/06/21/1password_trots_out_insights_tool/
[8] https://www.theregister.com/2022/06/21/phishing-voicemail-microsoft-zscaler/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrQ5xNOGAK@59Il-NlQmWgAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrQ5xNOGAK@59Il-NlQmWgAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: Subhead
Also The Cars:
You can't go on. Thinking nothing's wrong, but now. Who's gonna dox your home. Tonight?
In January, Hatton responsibly contacted Halfords to warn the company of the vulnerability. Sadly, his efforts were rewarded mostly by a stony silence until The Register got in touch.
A spokesperson told us: "Halfords takes the security of our customer data very seriously.
I'm not sure those two statements agree!
every company has this template now...
Yep, I saw some warning signs to this effect booking an MOT last Dec.
For "unknown" reasons their booking system slapped completely the wrong address on the order. It is as well I took the car in in person or it could have been returned to completely the wrong location.
Looks like they'll have to write some postcode to address these problems...
Wassat, then?
Halfords supplies tires now?
1,$s/tire/tyre/g
:wq!
Interestingly [1] , searching halfords[dot]com for "tires" produces the same 8041 results as for "tyres", but not categorised into car tyres, bike tyres, etc.
[1] For certain small non-integer values of Interesting
Is this the same Halford....
... that ask you for your email details so they can send you a receipt of something you just bought in the shop....
Yes, yes it is.
Also remember folks, these details will be shared across the AA group.
Re: Is this the same Halford....
I sometime use Halford to get the odd things; however I always refuse to give my e-mail address and insist on a paper receipt at the cash desk. When asked "why?" I just state that I don't trust Halford's cyber-security measures with my personal data.
Re: Is this the same Halford....
All the times I've gone to Halfrauds for anything I've never been asked why when I say no to the email.
I have noticed on their website though that if you try to use the wildcard email thing (as in, putting + after your name on the email to fill it with any identifiable garbage to you) that while they accept it they won't send an email to it. Three times now I've been screwed out of a £5 voucher after buying oil from them.
That said, in defence of Halfrauds, their Advanced tools are fantastic. I'll always go to Halfrauds for that, but not much else.
Re: Is this the same Halford....
Three times now I've been screwed out of a £5 voucher after buying oil from them.
After they screwed you out of the voucher the first time, why did you try again? And again?
Re: Is this the same Halford....
Because Petronas Syntium is a rather good oil at a reasonable price, and every time I've needed it Halfrauds have had them at the cheapest price.
A disclosure like this in the US would have landed a prosecution under CFAA
I can't find it now, but I remember reading about a case where a customer of Comcast or Verizon reached out to them about a similar problem with an insecure API involving a sequential ID number and they were ignored. So after a responsible length of time they went public with it and were then prosecuted and actually convicted. Just ridiculous.
Subhead
Thumbs up for the sub-head.