<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vidar's Musings &#187; information leakage</title>
	<atom:link href="http://www.kongsli.net/nblog/tag/information-leakage/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kongsli.net/nblog</link>
	<description>Deep thoughts on shallow topics</description>
	<lastBuildDate>Fri, 27 Jan 2012 07:36:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Norwegian sites leaking information</title>
		<link>http://www.kongsli.net/nblog/2007/07/31/norwegian-sites-leaking-information/</link>
		<comments>http://www.kongsli.net/nblog/2007/07/31/norwegian-sites-leaking-information/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 07:52:00 +0000</pubDate>
		<dc:creator>vidarkongsli</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[information leakage]]></category>

		<guid isPermaLink="false">http://www.kongsli.net/nblog/?p=15</guid>
		<description><![CDATA[Norwegian tabloid Dagbladet revealed yesterday that several commercial and non-commercial sites can be exploited to perform identity theft. In Norway, all persons get assigned a unique number (&#8216;f&#38;oslash;dselsnummer in Norwegian), similar to the US Social Security Number. Altough law restrictions apply, several sites use this number for uniquely identifying a person. In this particular case, [...]]]></description>
			<content:encoded><![CDATA[<p>Norwegian tabloid <a href="http://www.dagbladet.no">Dagbladet</a> revealed yesterday that several commercial and non-commercial sites can be exploited to perform identity theft.</p>

<p>In Norway, all persons get assigned a unique number (&#8216;f&amp;oslash;dselsnummer in Norwegian), similar to the US Social Security Number. Altough law restrictions apply, several sites use this number for uniquely identifying a person.</p>

<p>In this particular case, a hacker created a tool that could reveal identity information by collecting information from several sites, including the following steps:</p>

<ul>
    <li>Generate a random identifier. The format and the algorithm for creating one is publicly known.</li>
    <li>Use site 1 to test whether the generated identifier is in use. This is possible because site 1 uses the number as user name. The logon procedure acts differently depending on whether the user name exists.</li>
    <li>Use site 2 to get personal details about the person to which the generated identifier belongs. (Surname, given name, address)</li>
</ul>

<p>This is of course possible because the sites are designed poorly and leak information (<a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top Ten</a> vulnerability #6). Second mistake is that site number two use the unique number for authentication.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.kongsli.net%2Fnblog%2F2007%2F07%2F31%2Fnorwegian-sites-leaking-information%2F&amp;title=Norwegian%20sites%20leaking%20information" id="wpa2a_2"><img src="http://www.kongsli.net/nblog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.kongsli.net/nblog/2007/07/31/norwegian-sites-leaking-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

