发布于: iPad转发:4回复:13喜欢:0
携程安全支付日志可遍历下载 导致大量用户银行卡信息泄露(包含持卡人姓名身份证、银行卡号、卡CVV码、6位卡Bin) | WooYun-2014-54302 | WooYun.org 网页链接 $携程(CTRP)$ 大量关键信息泄露,cvv码都漏了。绑了信用卡的务必留意。

全部讨论

JasonHK2014-03-22 22:45

还好,paypal的交易马山就用gmail通知给我了。我立即交涉,paypal迅速处理,没有一点损失。

Dear XXX,

Recently, you told us that you didn't recognise a payment sent from your
PayPal account. We are currently investigating the following transaction:

-----------------------------------
Details of disputed transaction
-----------------------------------

Seller's Name: netlink computer inc.
Seller's Email: paypal@ncix.com
Seller's Transaction ID: 9Y652786SA0647648

Transaction Date: 4 Mar 2014
Transaction Amount: -$396.08 CAD
Invoice ID: 1076384701
Your Transaction ID: 27F05245N1265070L
Case Number: PP-002-997-793-971

Buyer's Transaction ID: 27F05245N1265070L

The seller has been asked to provide more information about this
transaction. During our investigation, the funds will not be available in
your PayPal account. If the case is decided in your favour, we will refund
you for the amount of the transaction.

To see the details of this case, log in to your PayPal account and go to
the Resolution Centre.

Thanks,

PayPal

Please do not reply to this email. This mailbox is not monitored and you
will not receive a response. For assistance, log in to your PayPal account
and click the Help link in the top right corner of any PayPal page.

BC:PP-002-997-793-971:R1:CAD396.08:04/03/2014:27F05245N1265070L

----------------------------------------------------------------
Copyright © 1999-2014 PayPal. All rights reserved.

Consumer advisory- PayPal Pte. Ltd., the holder of PayPal’s stored value
facility, does not require the approval of the Monetary Authority of
Singapore.
Users are advised to read the terms and conditions carefully.

PPID PP933

以上是其中的一个交易。。

速度来袭林2014-03-22 22:39

我们单位还是携程的VIP啊。。。

速度来袭林2014-03-22 22:37

乌云都知道了的东西,都不知道在外面暴露了多久了,早说了中国的互联网公司不靠谱,都TM只知道让员工加班加班加班,软件开发流程也是以补文档为主,隐私大规模泄漏只是迟早的事情。

达达fred2014-03-22 22:32

据乌云网白帽说携程的安全架构有问题。洞不好补

达达fred2014-03-22 22:31

肯定全额赔付

chuhui2014-03-22 22:21

不只是卡号,都泄漏了。

介绍一下2014-03-22 22:11

有的赔吗?

速度来袭林2014-03-22 22:02

SB携程,连hash都不用一下的,老纸的招行卡算是废了,尼玛我们单位指定的出票公司只有携程和外航,还好只是信用卡,要是个人身份证号,手机号,地址什么的都一并泄露出去了,携程有的赔了。

JasonHK2014-03-22 21:38

信用卡很容易就会被盗了,支付宝之类的也不安全。本人曾经就因为paypal关联的信用卡被人盗用了几万大洋。。

onedot2014-03-22 20:18

哇我打算换卡