You are here  IT Management Risk Management

O2 blocks online security hole which allowed customers to read other users’ messages

Antony Savvas
Wednesday 20 February 2008 03:00

O2 has blocked asecurity holethat allowed its customers to view text messages sent by other UK subscribers online, reports The Register.

The problem involved O2's Bluebook application, which allows subscribers to save text messages they send or receive for viewing online.

But O2 coding errors in Bluebook allowed registered users to view other customers' messages and phone numbers, by simply changing the message ID number in URLs used to access messages on the site.

O2 told The Register it had fixed the problem.