All the latest UK technology news, reviews and analysis

RSA 2009: Businesses at risk from e-commerce vulnerabilities

by Iain Thomson

24 Apr 2009

Be the first to comment

  • Tweet this
e-commerce
Faults in e-commerce systems can cost firms dear

E-commerce vendors need to tighten up their systems to avoid being ripped off by canny scammers, the RSA 2009 conference was told.

In his address to the conference, Trey Ford, director of solutions architecture for WhiteHat Security, explained how simple faults in procurement systems could cost companies hundreds of thousands of dollars.

Some of these techniques required little or no technical skill at all, he said. For example, a woman in North Carolina found that by making an order and then cancelling it before the browser had reloaded she would still be sent the products but not billed for them.

She sold more than $400,000 of these goods on eBay before being caught – not because the company identified her but because buyers of the products became suspicious.

The reload function of the browser could also be used by "pump and dump" scams – where stock prices are manipulated by online information – by interfering with Google News rankings, he said.

It would be easy to write code that reloaded a certain news page many thousands of times and shift it up into the Google News top stories page, he said, and this could be very profitable for a pump and dump scam.

“Pump and dump is highly profitable,” he said. “In a good stock market you can make seven-figure sums by gaming the market correctly.”

He gave the example of United Airlines, which lost 75 per cent of its stock price temporarily after an outdated and inaccurate Bloomberg report about the airline jumped into the Google News rankings.

While he said this wasn't the activity of pump and dump scammers as far as anyone knew, it showed how the savvy scammer could make huge sums by manipulating online information.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

2%

14%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Project Manager (FATCA)

A client, a major financial services organisation, is...

Sharepoint Administrator, Birmingham, West Midlands

Sharepoint Administrator, Sharepoint 2010, Sharepoint...

PLC Control Engineers Wanted!

Proteus Europe, operating as an employment business...

Salesforce.com Senior and Leads

Salesforce.com Senior Consultants and Leads Salesforce...

To send to more than one email address, simply separate each address with a comma.