January 2025
Intermediate to advanced
71 pages
1h 9m
English
There have been a number of high-profile attacks by the threat group Magecart, including major breaches of British Airways and Ticketmaster UK. In both incidents, a script was used to intercept cardholders’ details as they entered them into a browser on the cardholders’ own computers:
• In the British Airways breach, Magecart got a modified script onto the web server and application itself.
• In the case of Ticketmaster UK, Magecart got a substitute script onto a service provider’s server. The malicious script was then called from the Ticketmaster website and captured card details.
In the case of British Airways, server and application access controls should have prevented the script ...
Read now
Unlock full access