CGISecurity Logo

Virgin security flaw exposes customers’ details

"It appears that, instead of using random SMS codes, Virgin Mobile’s codes were sequential so simply changing the
last character allowed access to a new set of personal details.

For example, someone who received the code "00XM7Z" could view another customer’s details by entering "00XM7Y" or
"00XM7X", etc."

Article Link http://www.smh.com.au/news/security/virgin-exposes-customers-details…