https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures


Booking com

Salt Security Uncovers Critical Security Flaws in Booking.com

  • Written by Edward Gately
  • January 1, 1970

Salt Security has discovered several critical security flaws in Booking.com, one of the largest online travel agencies.

According to new threat research from Salt Labs, the flaws were found in the implementation of the Open Authorization (OAuth) social-login functionality utilized by Booking.com. It had the potential to affect any users logging into the site through their Facebook account.

The OAuth misconfigurations could have allowed for both large-scale account takeover (ATO) on customers’ accounts and server compromise, enabling bad actors to:

  • Manipulate platform users to gain complete control over their accounts.
  • Leak personal identifiable information (PII) and other sensitive user data stored internally by the sites.
  • Perform any action on behalf of the user, such as booking or canceling reservations, and ordering transportation services

Popular across websites and web services, OAuth lets users log into sites using their social media accounts, in one-click, instead of via traditional user registration and username/password authentication.

Yaniv Balmas is vice president of research at Salt Security.

“OAuth has quickly become the industry standard and is currently in use by hundreds of thousands of services around the world,” he said. “As a result, misconfigurations of OAuth can have a significant impact on both companies and customers as they leave precious data exposed to bad actors. Security vulnerabilities can happen on any website, and as a result of rapid scaling, many organizations remain unaware of the myriad of security risks that exist within their platforms.”

Any Booking.com user configured to log in using Facebook might have been affected by this issue, according to Salt Security. Given the popularity of using the “log in with Facebook” option, millions of users could have been at risk from this issue.

Kayak.com (part of the same parent company, Booking Holdings) could have also been affected, as it allows users to log in using their Booking.com credentials, increasing the number of users susceptible to these security flaws by millions.

Upon discovering the vulnerabilities, Salt Labs’ researchers followed coordinated disclosure practices with Booking.com, and all issues were remediated with no evidence of these flaws having been exploited in the wild.

Photo courtesy Casimiro PT/Shutterstock

 

 

 

Tags:

Edward Gately

Edward Gately

As news editor, Edward Gately covers cybersecurity, new channel programs and program changes, M&A and other IT channel trends. Prior to Informa, he spent 26 years as a newspaper journalist in Texas, Louisiana and Arizona.

Related Content

  • Mergers and acquisitions
    Latest Channel M&A: HPE, TBI, Cisco, Pax8, Sumo Logic, Trend Micro, More
  • Making Waves
    7 Channel People Making Waves This Week at Datto, Zoom, CrowdStrike, Zscaler, More
  • handshake
    New Zscaler Channel Leader Won't 'Boil the Ocean' in Partner Program Expansion
  • A Data-First Approach
    SAP Expands Data Warehouse Into Data Fabric with SAP Datasphere

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Lumen Channel Leaders: Activation Incentives ‘Resonating’ with Partner Community

March 21, 2023

Channel Partner Awards: SolarWinds, GoTo, Darktrace, Juniper Networks, IGEL, More

March 21, 2023

Vernick, Jones Join Upstack Leadership Team, Reject ‘Roll-Up’ Stereotype

March 21, 2023

Industry Perspectives

View all

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

How Hybrid Work Poses Major Cybersecurity Risks

March 1, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

🤔 What if we told you that DE&I could help you stay competitive and propel your business forward? Join us on April… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

In recent months, @cytracom appointed a 30-year industry veteran, formerly with Level Platforms and CompTIA, as cha… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@SolutionsLg rolls out expanded LG Pro Channel Partner Program for U.S. resellers. dlvr.it/SlGPYg https://t.co/lzWGCZsNc8

March 21, 2023
ChannelFutures

When it comes to cybersecurity 🔒, these 20 leaders represent the future of the channel. Who do you think made the l… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@Vonage has introduced two new tools (Vonage Meetings API and Proactive Connect) to help facilitate digital transf… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

Upstack's newest CX leaders say their appointment is a sign of Upstack's agent-friendliness. dlvr.it/SlDvMV https://t.co/srsiKpzJ7K

March 21, 2023
ChannelFutures

With the @awscloud Migration Competency, @IngramMicroInc will help partners to “accelerate the customer cloud adopt… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@HPE acquiring @OpsRamp to add capabilities to @HPE_GreenLake. #cloud dlvr.it/SlCFz9

March 20, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X