No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

ANZ, eStatement, critical, flaw
Today's release of the report "In the Crossfire: Critical Infrastructure in the Age of...
A critical vulnerability in Microsoft's VML (vector markup language) used to produce graphics, that...
Patch Tuesday has come and gone with Microsoft dutifully patching three flaws, one of...
Last week, Microsoft flagged that there would be another 12 holes in its Windows...
eEye Digital Security, the security company which specialises in finding flaws in the products...

ANZ eStatement critical flaw

Business IT - Security

ANZ Bank has disabled the use of all online bank statements until a critical flaw is fixed.

The ANZ Bank's online bank statement functionality (called eStatement) has a serious flaw related to the browser history.

The flaw was discovered a week ago by
SC Magazine, who gave the Bank a week to address the issue before going public (which they did at 6:30 Thursday morning).

Of interest is the very generous statement that "The outsourcer was understood to be considering fixing the bug."  A Salmat [the identified outsourcer] spokesperson told iTWire that the company strongly denied any involvement in the development of this system, insisting that the ANZ Bank was the developer.

The issue with the online statements relates to browser histories - the problem being that the statement remains in the browser history after the page is closed.  If this is a PC in your own home, it's probably not a problem; but if it's an Internet café computer, there can be a problem, as the information is easily accessed by the next person using the computer and scanning the recent pages visited.

All parties have recommended that browser histories be deleted after viewing a statement, but this is really only a partial fix.

It was only later that ANZ announced they would disable the service.