WHID 2006-16: AstraTel customer call records leaked

Attack Information
WHID ID: 
2006-16
Date Occured: 
10 Apr 2006
Attack Method: 

A security hole in Sydney internet provider Astratel's LiveBilling online account management system has seriously compromised its customers' privacy.

The service redirected users to a different server and propagated the user information in a hidden field without re-authenticating.

Additional information: