Solved

Security Issue with Financial Site

Posted on 2014-04-29
4
246 Views
Last Modified: 2014-05-18
My company deals with a outside company for 401k. We just noticed a security hole in the password reset process on their company site.There is no second layer of authentication to verify the user such as a security question to reset the password (it clearly exposes the current password by clicking on a redirected link once you retrieve the email from your account). If the email is forwarded or someone has access to my account my account is now open to compromise with this method. I am looking for some official documentation to prove my point. Any suggestions?
0
Comment
Question by:jaxon_b
4 Comments
 
LVL 10

Accepted Solution

by:
Rafael earned 500 total points
Comment Utility
One thing you can do is have the site scanned for vulnerabilities using a 3rd party vendor.

A couple of sites that may have the tools and or information you need are as follows:



Hope this helps.
0
 
LVL 33

Expert Comment

by:paulmacd
Comment Utility
Report it to the company in question.
0
 

Author Comment

by:jaxon_b
Comment Utility
rcaballerojr-got anything more current perhaps a white paper from sox or pci?
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
I wonder what you need to prove, it seems so simple. If that mail was sent unencrypted, anyone in between might have read/copied it. So if clicking on the link does not require an authenticated VPN connection in the first place, then anybody could use that mail. Of course some sender insert a small protection by making the link expire - simply try it out from another machine.

But of course: normally, password reset processes work exactly like this. Sending to a registered mail address is seen as quite secure, because intercepting e-mails is everything but easy and if (as you proposed) someone setup a mail forwarding rule, he should really know what he is doing and fully trust the one he is forwarding to.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now