---
title: American Express Leaves a Door Wide-Open
description: Technology is often discussed as a trade-off between convenience and security.
image: https://email.networksgroup.com/hubfs/Images/cyber-security-1784985_1280%20(1).png
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/american-express-leaves-a-door-wide-open#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

# American Express Leaves a Door Wide-Open

Posted by [NetWorks Group](https://email.networksgroup.com/author/networks-group) on Nov 2, 2011 10:17:00 AM

![](https://email.networksgroup.com/hubfs/Portraits/NWG.png)

Find me on:

[Facebook](https://www.facebook.com/networksgroupinc/) [LinkedIn](https://www.linkedin.com/company/networks-group) [Twitter](https://twitter.com/networksgroup)

- [Tweet](https://twitter.com/share)

Not to be left in the dust for instances of confusingly-bad security practices by industry friends such as [Citibank](http://seattletimes.com/html/businesstechnology/2015320091_bankhackers15.html) and [Bank of America](http://business.time.com/2011/10/05/was-bank-of-america-hacked/), [American Express served up their own face-palm of security today](http://qnrq.se/full-disclosure-american-express/). In this case, it appears that a breakdown between application developer ease-of-debugging didn't quite mesh-up with operations security and access restrictions. To summarize the link, American Express failed to effectively restrict a developer interface which provides debugging functionality for developers working on their web site. These sorts of administrative interfaces are certainly not uncommon, but they should be by design restricted to people with proper credentials or at least blocked from the public Internet for accessibility.

Interestingly enough, the American Express 'robots.txt' file, often used to tell search engine indexers not to bother certain portions of a web site, list these unrestricted URLs plain-as-day. Again, using robots.txt is not a bad thing alone, but if that points to otherwise 'hidden' directories which provide functionality not intended for the general public, you've got a new problem to fix.

Technology is often discussed as a trade-off between convenience and security. I don't think this concept could be anymore obvious in this situation of a security blunder. American Express provided developer access to easily debug the web site and test functionality. In doing so, they removed a large amount of security into private processes that should not otherwise be exposed. Beyond just being 'bad practice' and exposing information not suitable for public access, they actually introduced a cross-site scripting (XSS) vulnerability into americanexpress.com due to this situation. That then opens the door for an attack to potentially phish accounts of unassuming users.

In this case, the above link's poster went the 'full disclosure' route and made a scene on Twitter and elsewhere to talk about what he found. While this certainly left American Express exposed for the half-a-day that they were publicly vulnerable, who knows if other attackers had found this and were actively utilizing it for their own ends prior.

To that end, it's up to a company like American Express to do simple vulnerability assurance testing on not just public pages, but also on (assumed) private pages. Having a XSS vulnerability should not be acceptable even if the page is never intended to be public. Defense in depth could have prevented this XSS situation at various levels: access controls for the developer panel; network restrictions to the developer panel; not placing administrative pages in robots.txt; vulnerability testing internal application. If one of these had been true, the entire situation would have never arisen.

Luckily in this situation, no direct customer data was at risk (as reported thus far). Still, financial institutions should never be prime examples of failing information security practices in so many drastic ways.

 Topics: [Information Security](https://email.networksgroup.com/topic/information-security)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group