warning: Aurigny's web site / PBX hacked

I just tried to buy tickets from airline Aurigny.

Instead of being under Aurigny.com like normal, it went to videcom.com, which I'd never heard of.  I pasted in my email and password before noticing, so may have sent them to the hacker by mistake!  The fake web site said my login had failed, even tho I put in the right password:



Note that the options are "login" and "I forgot my password".  If this wasn't a fake web site, then it would be another case of the web site operator not bothering to preserve customer passwords, and then forcing password resets by email by lying to customers and telling customers that it's the customer who's forgotten the password.  This happens a lot.  I thought I had a tag for it, but can't find.  So projection_of_forgotten_password_from_web_site_to_user it is.  Ah yes, I think it's forced_bogus_account_rescue.

If Aurigny are doing this deliberately, then it's obviously bad.  The domain is all the user can be expected to have, to confirm who they're dealing with.  You do not send them off to other domains.

Then I called Aurigny, during working hours.  During a 30 minute period up until the end of their working hours, my position in the queue increased from 5th to 6th.  So it's possible that their PBX has been hacked as well.

Comments

Popular posts from this blog

the persistent idiocy of "privileged ports" on Unix

google is giving more and more 500 errors

Guernsey Waste in incorrect bag-rejection horror May 6th, 2024