Showing posts with label Nasdaq. Show all posts
Showing posts with label Nasdaq. Show all posts

Wednesday, 18 September 2013

Security company says Nasdaq waited two weeks to fix XSS flaw

A Swiss security company said the Nasdaq website had a serious cross-site scripting vulnerability for two weeks before being fixed on Monday, despite earlier warnings.

Ilia Kolochenko, CEO of the Geneva-based penetration testing company High-Tech Bridge, said he repeatedly emailed Nasdaq and warned of the XSS flaw.

[ The Web browser is your portal to the world -- and the gateway for security threats. InfoWorld's expert contributors show you how to secure your Web browsers. Download the free PDF today! | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

"I can basically say I have spammed them," Kolochenko said in an interview.

Nasdaq.com lets users create accounts and build a profile to monitor stocks and news. Nasdaq said it did not believe the flaw was used by an attacker, and no personal data was compromised.

"We responded to his concerns immediately," Nasdaq said in an email statement. "We take all information security matters seriously. We work with leading security vendors and have a trained and professional team that evaluates all credible threats across our digital assets."

Cross-site scripting is an attack on a website in which a script drawn from another site is allowed to run that shouldn't. The attack can be used to steal information or potentially cause other malicious code to run.

Kolochenko said the flaw could have been used by an attacker in several ways, including stealing users' browser histories and their cookies. It could also have been used to inject HTML into a Web page and ask for people's personal details, a request that would appear to come from Nasdaq.

In another kind of attack, Kolochenko said the XSS flaw could be used to plant a link within the Nasdaq site to a malicious website.

Kolochenko said XSS flaws are common, and he has found ones in websites belonging to the BBC, Bloomberg and the Financial Times. Those organizations acknowledged the issues, but it was often a month or so before the websites were fixed, he said.

He found the Nasdaq flaw after noticing some suspicious URLs and conducting a harmless test. At that point, he stopped probing the website and notified Nasdaq by email on their support, abuse and security addresses.

"I didn't want to take it further," he said.

Nasdaq's trading halted on Aug. 22 after a technical problem with a core data feed that distributes market data for securities listed on its exchange. A connectivity issue degraded the ability of the Securities Industry Processor (SP) system to consolidate and disseminate quote and trade information on Nasdaq listed securities.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here

Monday, 16 September 2013

Security company says Nasdaq waited two weeks to fix XSS flaw

September 16, 2013 12:55 PM ETIDG News Service - A Swiss security company said the Nasdaq website had a serious cross-site scripting vulnerability for two weeks before being fixed on Monday, despite earlier warnings.

Ilia Kolochenko, CEO of the Geneva-based penetration testing company High-Tech Bridge, said he repeatedly emailed Nasdaq and warned of the XSS flaw.

"I can basically say I have spammed them," Kolochenko said in an interview.

Nasdaq.com lets users create accounts and build a profile to monitor stocks and news. Nasdaq said it did not believe the flaw was used by an attacker, and no personal data was compromised.

"We responded to his concerns immediately," Nasdaq said in an email statement. "We take all information security matters seriously. We work with leading security vendors and have a trained and professional team that evaluates all credible threats across our digital assets."

Cross-site scripting is an attack on a website in which a script drawn from another site is allowed to run that shouldn't. The attack can be used to steal information or potentially cause other malicious code to run.

Kolochenko said the flaw could have been used by an attacker in several ways, including stealing users' browser histories and their cookies. It could also have been used to inject HTML into a Web page and ask for people's personal details, a request that would appear to come from Nasdaq.

In another kind of attack, Kolochenko said the XSS flaw could be used to plant a link within the Nasdaq site to a malicious website.

Kolochenko said XSS flaws are common, and he has found ones in websites belonging to the BBC, Bloomberg and the Financial Times. Those organizations acknowledged the issues, but it was often a month or so before the websites were fixed, he said.

He found the Nasdaq flaw after noticing some suspicious URLs and conducting a harmless test. At that point, he stopped probing the website and notified Nasdaq by email on their support, abuse and security addresses.

"I didn't want to take it further," he said.

Nasdaq's trading halted on Aug. 22 after a technical problem with a core data feed that distributes market data for securities listed on its exchange. A connectivity issue degraded the ability of the Securities Industry Processor (SP) system to consolidate and disseminate quote and trade information on Nasdaq listed securities.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Saturday, 24 August 2013

Connectivity issue caused trading problems, Nasdaq says

Nasdaq blamed the unprecedented trading halt Thursday on a "connectivity issue" between an exchange participant and its core Securities Industry Processor (SIP) system, used to consolidate and disseminate quote and trade information on Nasdaq-listed securities.

The connectivity problems degraded the ability of the SIP to disseminate consolidated quotes and trades, Nasdaq said in a statement. It added that the cause of the problem has been identified and addressed.

[ For quick, smart takes on the news you'll be talking about, check out InfoWorld TechBrief -- subscribe today. | Find out what topics and issues affect tech's biggest names and news makers in the IDGE Insider CEO interview series. | Read Bill Snyder's Tech's Bottom Line blog for what the key business trends mean to you. ]

The Nasdaq OMX Group today halted trading on all Nasdaq-listed securities at 12:14 p.m. because of the glitch. Trading did not resume until after 3:10 ET.

The outage affected more than 2,000 companies, including Google, Amazon, Microsoft, and Cisco. The Wall Street Journal's Market Watch described the trading freeze as affecting companies with a combined worth of about $5.7 trillion.

The SIP is part of system that enables other exchanges such as the New York Stock Exchange, Chicago Stock Exchange, and BATS Global Markets to trade in Nasdaq-listed securities. It is the single source of consolidated market data for Nasdaq-listed securities and provides continuous quotes and last sale information from all markets trading in Nasdaq-listed securities.

When Nasdaq ran into the connectivity problem Thursday afternoon it immediately issued a regulatory halt on all trading in Nasdaq-listed securities in order to protect the integrity of the markets, the statement noted.

It went on to add that the technical issues with SIP were identified and resolved within 30 minutes. "For the remaining period of time, Nasdaq OMX, other exchanges, regulators and market participants coordinated with each other to ensure an orderly re-opening of trading in Nasdaq-listed securities," the statement noted.

Trading resumed and finished in normal course at the end of the trading day, Nasdaq said. "Nasdaq OMX will work with other exchanges that are members of the SIP to investigate the issues of today, and we will support any necessary steps to enhance the platform," it said.

This is not the first time that Nasdaq has run into problems with the SIP. In January, the exchange briefly shut down trading while it investigated the cause for stale data on the system. The problem resulted in Nasdaq-listed trades not being recorded in real time.

The latest glitch comes even as the system is being modified to accommodate two new data sets, which are scheduled to go live in October.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed. His e-mail address is jvijayan@computerworld.com.

See more by Jaikumar Vijayan on Computerworld.com.

Read more about networking in Computerworld's Networking Topic Center.


View the original article here