Heroku plugs password security hole
Vulnerability could have let hackers change passwords and hijack accounts.


Platform-as-a-Service (PaaS) provider Heroku has patched a security flaw that could have given hackers access to customer accounts.
The company was told about the problem on 19 December 2012 by security researcher Stephen Sclafani.
However, it chose not to go public with news of the vulnerability until it had been patched.
Heroku encrypts its user passwords with non-recoverable bcrypt hashes, but hackers were able to bypass this security measure and gain access to users' accounts via a malicious HTTP request.
We are confident in the steps we have taken to protect our customers from this vulnerability
Potential hackers were never able to see users' passwords, but could use the malicious code on the service provider's account creation system to change them and take control of the account.
A preliminary patch was developed and deployed on 20 December and the company claims it found no evidence that the vulnerability was exploited by anyone prior to Sclafani's research.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Oren Teich, Heroku's chief operating officer, said in a blog post: "We are confident in the steps we have taken to protect our customers from this vulnerability and will continue to improve our internal processes in order to provide our customers with a trusted cloud platform.
"We would also like to reaffirm our commitment to the security and integrity of our customers' data and code. Nothing is more important to us," he added.

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd