T-Mobile bug let anyone see any customer's account details

  • 24 May 2018
  • 0 replies
  • 174 views

Userlevel 7
Badge +54
The exposed lookup tool let anyone run a customer's phone number -- and obtain their home address and account PIN, used to contact phone support.
 
24th May, 2018 By Zack Whittaker
 
A bug in T-Mobile's website let anyone access the personal account details of any customer with just their cell phone number.
 
The flaw, since fixed, could have been exploited by anyone who knew where to look -- a little-known T-Mobile subdomain that staff use as a customer care portal to access the company's internal tools. The subdomain -- promotool.t-mobile.com, which can be easily found on search engines -- contained a hidden API that would return T-Mobile customer data simply by adding the customer's cell phone number to the end of the web address.
 
Full Article.

0 replies

Be the first to reply!

Reply