Login     Register
Select Website 

Recruitment Directory's Blog - Australia's #1 Recruitment Technology Blog!

Back to Menu Back to Menu

Is your Job Application Form redirecting candidate applications to identity thieves?

Posted By: Thomas Shaw, 1:52pm Wednesday 10 February 2010    Email Article    Print Article

Did you know on some application forms you can manipulate the URL and have the candidate’s job application redirected to someone else’s email address? Job boards, career/recruitment websites are already a haven for identity thieves and this "oversight" on your application form is fueling their business!

You would think by now that recruitment technology providers, job board developers, risk management experts would be able to identify security risks in the candidates job application process. But alas, no - there are still many examples of this security risk present on application forms. 

So what exactly am I talking about?

When a candidate applies for a job, they are usually redirected to an online application form. The application form URL may contain the destination email address (usually the recruitment consultant or inbox email address).

This is BAD!




If you change the email address in the URL you maybe able to redirect the candidate’s application to another email address. Guess what? You would not even be aware this may be happening on your application forms already!

This is not an issue which is going to go away. If your application form has an email address in the URL you need to immediately fix this problem!

Job boards can minimise their exposure to redirecting candidates to insecure websites by restricting URLs that contain an email address. It is better to be safe than sorry.



Article URL: http://www.recruitmentdirectory.com.au/Blog/is-your-job-application-form-redirecting-candidate-applications-to-identity-thieves-a330.html

Article Tags: security risk url email address 3rd party application form candidate details application form recruitment agency job boards hacking url manipulation identity theft hijacking job application forms

Comments Hide Comments (7)

Feel free to join in on the conversation. All comments are moderated before publishing. Comments posted by subscribers don't necessarily reflect the views of Recruitment Directory.

 Jamie (2:03am Thursday 11 February 2010)

Tisk tisk. How could programmers get away with this.


 Najara V. (2:13am Thursday 11 February 2010)

Shame on the whole recruitment industry for not taking security seriously.

It's only a matter of time before a recruitment agency gets exposed for a lack of online security.

What about the poor candidate? I feel sorry for them.

Name and shame.
Name and shame.


 J (10:38am Thursday 11 February 2010)

Would these recruiters be part of the RCSA?


 Tony B. (2:59pm Sunday 14 February 2010)

This is probably one of the best information sources for recruiters. Well done to Recruitment Directory for providing this. I can't wait to see what blog post is next?

Thomas, are you currently working fulltime for a job board or still freelancing? Drop me an email I have some work for you on our job board.

Keep up the good work.

Tony.


 John (11:31am Monday 15 February 2010)

I'm not sure what you think the security risk is. Who are you saying would change the URL? The candidate? Why would they do that? The job board? That seems like a pretty average way to protect your revenue stream.


 Irini Cavalliotis (12:22pm Tuesday 16 February 2010)

I agree - name and shame! Employment Office application forms definately do not have an email address in the URL. Thanks Thomas for brining it to the attention of candidates.


 Application Forms (4:42pm Monday 26 April 2010)

I too agre with Irini Cvlliotis without any url, why Employment Office application forms does not have an email address?


Your Name: * Required
Your Email Address: * Required
Website URL:
Comments: * Required
 


Back to Menu Back to Menu



Random Blog Articles

How secure is your Recruitment website? Part 4 - SQL Injection
Published: 11:17am Wednesday 19 August 2009

Federal Government adopts Gershom Review
Published: 2:59pm Tuesday 25 November 2008

So you want to run a job board...
Published: 11:41am Thursday 09 December 2010

Australian Job Board Statistics - August 2010
Published: 9:00am Sunday 01 August 2010

Segmenting Data using Google Analytics
Published: 2:00pm Tuesday 25 August 2009


Newsletter Mailing List

Stay informed of current news, upcoming events and promotional offers.

Top 25 Most Influential

Latest Blog Comments

Mark Van Goosen - 2:20am Thursday 12 April 2012
More jobs than SEEK?

Brett Iredale - 3:50pm Friday 06 April 2012
More jobs than SEEK?

Poo on U - 10:16am Thursday 22 March 2012
10 Things We Hate About Recruitment Companies

Yolk Recruitment - 2:29am Friday 16 March 2012
For bonus points, apply using the API

Jimi - 6:40pm Saturday 11 February 2012
SEEK mobile

Cavin - 7:25pm Monday 16 January 2012
What is an Applicant Tracking System? Who are the main providers?

Campus Recruitment Company - 10:25pm Tuesday 20 December 2011
HR Daily launches

Spider Personnel - 10:19am Tuesday 20 December 2011
NZ Public Service Workforce Data

ITRIS - 11:49pm Tuesday 13 December 2011
What is an Applicant Tracking System? Who are the main providers?

brett gammon - 7:29am Tuesday 25 October 2011
Applying for jobs using your mobile phone

Upcoming Webinars