« February 21 - 27, 2005 Weekly Summary | Main | Tour of Hope to Ride Again in 2005 »

T-Mobile Patches Vulnerabilities in My.T-Mobile.Com

Last week I reported that the My.T-Mobile.com Website still had some potentially dangerous vulnerabilities. I concluded this because I was able to repeat some of the HTML and JavaScript modifications to the My.T-Mobile.com login screen illustrated in the article Secret Service Hacker, How Did He Do It? that was published on the Ethical Hacking and Computer Forensics weblog.

I'm happy to report that these vulnerabilities appear to have been fixed by T-Mobile's system administrators. I re-checked the vulnerabilities after reading Wired News' article called Known Hole Aided T-Mobile Breach.

The Wired News article indicates that sources close to the Federal case against Nicolas Jacobsen reported that the exploit Jacobsen used to gain access to T-Mobile customer information was a vulnerability in the Weblogic application server that was discovered in 2003. The patch for this vulnerability has been available for most of that time, but T-Mobile reportedly failed to apply it until now.

The Wired News article goes on to quote Peter Dobrow, a spokesman for T-Mobile, who reportedly said that the company closed the holes that Jacobsen exploited. This is a very good development for T-Mobile customers around the country, and I felt that it was important to discuss it in detail here on Operation Gadget.

TrackBack

TrackBack URL for this entry:
http://www.operationgadget.com/spamfw.php?tb_id=392

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Got a tip for Operation Gadget?

Copyright © 2003-2006, Chatham Township Data Corporation. All Rights Reserved.

"Operation Gadget" is a service mark of Chatham Township Data Corporation.

All other products and company names mentioned on Operation Gadget may be trademarks of their respective owners. Any comments posted to Operation Gadget are the legal responsibility of the person that posted them. Comments may be removed from this system at any time, at the sole discretion of Chatham Township Data Corporation or its authorized agents.

Powered by
Movable Type 3.2

Site designed by Weblog Improvement