FlyerTalk Forums - View Single Post - [Updated] 2018 data breach : BA fined £20 million
Old Jul 8, 2019, 2:44 am
  #46  
7oh7
 
Join Date: Aug 2018
Location: LHR
Programs: BAEC
Posts: 6
XSS vulnerabilities feature in the OWASP Top 10, and are trivial to identify using free web application scanners.

BA are clearly accountable for this. They simply did not care enough to protect our data - and sadly nor do many other major UK organisations...

Recent research published suggests the average FTSE250 organisation exposes 35 different attack surfaces, which when fingerprinted were often found to be using outdated or unsupported web server software.

To reiterate another posts point - if BA have this level of appetite for risk i.e. "Surely that won't happen to us" - What can we expect from their aircraft engineering programme?
7oh7 is offline