racoma.com.phJ. Angelo Racoma on technology, economics, writing, problogging, and getting things done

  • Home
  • About
  • Archives
  • Consultancy
  • Contact

Subscribe to Articles

Vulnerability in Xoom’s Password Retrieval Procedure?

Author: J. Angelo Racoma Category: security Tags: bank, E-Commerce, Philippines, security, social_engineering, xoom Views: 8871

Monday
Oct 23, 2006

xoom.gifAfter reading my post about online payment systems “not being as easy to implement as we think,”:http://racoma.com.ph/archives/electronic-payments-in-the-philippines-it-may-not-be-as-simple-as-we-think/ Marhgil earlier emailed me about how he discovered “Xoom”:http://www.xoom.com accounts are potentially vulnerable to cracking. He “details in his blog”:http://kaluskoskuskos.com/marhgil/technology/xoom-accounts-easy-target-for-hackers/ how a user’s password can easily be changed if a malicious hacker (or “cracker” in this case) correctly figures out three things: the user’s email address, bank account number and ZIP code.

Not really easy, but can be done

I tried it out myself, and it was so shockingly simple. Of course, you would need to correctly input the email account that a person uses for Xoom, and since people usually give out their email and IM addresses on their blogs or email/forum signatures, it won’t be too difficult to guess. Xoom makes it even easier by helping you out. The system even tells you when you’ve guessed incorrectly!

Bank account numbers aren’t as easily guessed, however. But with a bit of social engineering or stalking, you can easily figure out a person’s bank account details. For instance, some ATMs print receipts with the full bank account included. Or perhaps you can call or email a potential victim posing as a bank employee (don’t get any ideas here).

ZIP codes might not be readily available, but you can check out any zoning references (available online), and if you know where a person lives, you can easily guess his ZIP code.

The point here is that a combination of an email address and bank account number are difficult to correctly guess. But it’s not impossible to do so. And to the determined thief, any effort exerted would be worth it, if only to get into the e-wallet of an individual.

Level of risk

You have to consider the level of risk and the vulnerability here. What exactly does access to another person’s Xoom account entail? Xoom doesn’t serve as an e-wallet like PayPal does (you cannot load it up with funds, like PayPal). However, if you have already registered a credit or debit card on your profile, then the cracker can use your Xoom account to transfer funds to his own account (by using the _Send Money_ feature) or pay for merchandise online.

How to mitigate this risk / A simple change of procedure

Marhgil suggests you change your ZIP code to a different value to make it difficult for a potential attacker to reach the _change password_ screen. This is only a stop-gap measure, though. Xoom should make its password retrieval procedure more secure by either sending the retrieval link to the user via email or requiring another form of verification, such as via SMS.

The fact that Xoom directly allows you to change your password once the correct detials are keyed in adds to the risk. Perhaps if Xoom emails the user a link to a password-reset form, the system would be more secure. It’s easy enough to acquire an email address, but it’s not as easy to enter a user’s inbox.

Around the blogosphere

As of this posting, here’s what other people think about this issue:

* “Yugatech”:http://www.yugatech.com/blog/?p=1282
* “Techno Pinoy”:http://www.technopinoy.com/?p=233
* “PinoyTechBlog”:http://www.pinoytechblog.com/archives/does-your-bank-mask-your-account-number

  • Tweet
  • "&title=""">
J. Angelo Racoma is a technology journalist and blogger. See more of his blog posts here at racoma.com.ph, commentaries at racoma.net, and Twitter feed at @jangelo.
Share:
image image image image

Comments via Facebook:

Comments

jhay

October 23rd, 2006 at 9:25 pm

Well, another reason why we need PayPal in all its functionality here in the Philippines.

Reply

Anya

October 24th, 2006 at 4:52 pm

Whoa… I was close to making an account…

I Y!PM-ed you but you signed out. Hehe. I received your PM though. Offline lang kasi ako :)

Reply

Mike

October 25th, 2006 at 1:04 pm

Has Xoom been informed of this vulnerability? I’m concerned because I also use Xoom.

Reply

J. Angelo Racoma

October 26th, 2006 at 1:05 am

@jhay, yes. Paypal does have its quirks, too, but I don’t think the security vulnerability is as bad as Xoom’s.

@Anya, I don’t think creating an account would give you a problem. Just make sure you mitigate the risks by using an alternate ZIP code. At least that would minimize the possibility of people correctly guessing.

@Mike, I don’t think so. Have you contacted them?

Reply

Click here to cancel reply.

Comment Form

Smallville Season 6 Episode 4: Arrow
Looking For A Used Car

About This Blog

I'm a technology blogger and journalist. I contribute to CMSWire and TFTS. I also run a content writing and VA service at WorkSmartr.com.

Do check out my profile and resume to learn more about me.

Please feel free to leave a response to any of my articles, using the forms provided at the bottom of each post.

Subscription

If you have an RSS reader, you may add my feed to your subscriptions. You can also subscribe to updates by email.

Quoting and License

In case you would like to quote, cite, or refer to articles I have written here, please refer to my site license page, for information on fair use and copyright. You can also refer to my comment policy for any questions regarding copyright and ownership of comments by readers. For media and blog interviews, please refer to my interview policy.

I hope you enjoy your stay!

Blog hosted by AccuWebHosting.Com - Leading Windows VPS Hosting Provider.

Search

Summer Savings! $7.49 .com

Recent Comments

  • reynald on Globe Super Combo 20 offers 1-day unlimited texting plus 50 minutes voice call
  • engelbert on Is Globe’s Supersurf unlimited Internet promo really “unlimited”?
  • Dane on Smart Bro Plugit Prepaid Kit Review
  • Jinai on Globe Super Combo 20 offers 1-day unlimited texting plus 50 minutes voice call
  • pat ramirez on Globe Super Combo 20 offers 1-day unlimited texting plus 50 minutes voice call

Recent Posts

  • Twitter, China Censorship & Why Everything Seems to be Made in China
  • Microsoft to Merge Mobile, Desktop Operating Systems With Windows 8?
  • Windows Phone 7.5 Mango is Out, Samsung & Intel Release New Mobile OS; Microsoft to Collect Android Royalties & More Mobile News
  • Essential Apps for the Mobile Worker [Check Out Our Suggested Apps for iPhone, iPad, Android & Other Important Online News, Such as SSL Security, HTML5 App Creation & Linux]
  • Adobe Flash Now Works on iPhone, iPad Through Flash Media Server 4.5

Projects

  • Green Liter
  • Star Tripping
  • Study Digital Photography
  • Study Driving
  • Technology & Computers – Top Blogs Philippines
  • Work Smartr

Resources

  • Free Twitter Followers
  • Las Vegas Discount Shows

  • email hosting.
  • colocation hosting.
  • windows hosting.
  • coldfusion hosting.
  • asp hosting.
  • Audi Car Technology Upgrades to Consider

More Resources

  • Free Mouse Cursors
  • Mobile OS

Copyright 2012 racoma.com.ph - All Rights reserved.

Wordpress theme by: WPUnlimited