Afrihost's insecure client portal

A few very valid points have been raised, and we are aware of the concerns that have also been raised.

Many of our users are not as technology savvy as most of the users on MyBB, and for them being able to access their Clientzone directly from their email notifications is not only a significant convenience, but also a way for them to load top-ups quickly and easily.

This notifications emails can be disabled in the Clientzone, if you do not feel comfortable receiving these notifications I would recommend disabling them. If anyone has any safety and security concerns, you are more than welcome to send me a PM so that we can discuss these concerns.
usually its those very usere who have no clue what can be gleaned from a simple static url. ;)
 
It's blanked out.
It's pointless arguing with the likes of you, please - stop spamming the thread with your idiocy.
I see you have no retort for the rest of my post, which points out if someone can access your email then they could simply go to Afrihost's or ANY other website and "Forgot password".
Done and dusted.
Except that any other website would at least send a mail confirmation which would in my case appear on my phone and alert me... not so with Afrihost. Changing password and email address can be done without alerting anyone.

About it being blanked out, youre probably referring to credit card. I'm on debit order.

Don't worry, they don't forward emails with their login link/details to other people. :wtf:

And how would they or you know? Or do they make it a habit of clicking every URL they receive? It's not that unreasonable to assume that service providers don't send insecure urls.
 
Last edited by a moderator:
I'm just going to add that these are the responses I got from Afrihost...
Just a nudge to up the support effort guys. Don't expect the client to do all the work.

After my initial email alerting to the issue
Afrihost support said:
Hi there ,
I trust you are well :)
Well we sorry to hear that ... but they shouldn't be able to login as it will require the password .
You can however for safety reasons change your clientzone password .
You can change it by going to your clientzone .
Its clientzone >>My account >> change my access details >> there you should be able to update your password .
Have a great day further and please do not hesitate to contact us for any further assistance .
That says nobody actually tested anything, they simply replied to the message. My response below:

Me said:
I wish it were so… try for yourself (click the link, then click ‘client zone’ at the top right). No password required. Very insecure!
Followed by:

Afrihost Support said:
Hi ,
I cant on my side as i haven't logged in .
You can however on your end because your browser still has the password saved .

But you can update/change it on your clientzone ...just to be safe :)
Still haven't actually tried it yet??! And no, changing the password doesn't make a difference.

me said:
No offence, but I’ve just tested it on my phone by entering the URL manually and I’ve NEVER logged in to the client zone from my phone. It’s NOT COOKIES.
Please, go try it again and make sure you’re using the right URL – just copy and paste this into your browser:
http://clientzone.afrihost.com/tiny/***********
Once there – you can see the client zone link to the top right – no password required.
---

AfriGenie said:
And the link is no longer valid, please do not send this mail out to your fellow office works again :)

Me said:
Thanks. I seriously recommend this system be changed to request the password. It's very insecure. Proxy logs and sniffers will easily record the URL.

AfriGenie said:
I will definitely take this under advisement.
This was primarily implemented as many users do not have an innate understanding of technology and its workings that MyBB users do, this allows us to have a more or less secure log-in whilst still allowing the user an easy to use top-up option.

Most sniffers and proxy logs filter through emails looking for specific usernames and passwords, most HTTP / HTTPS links are complete ignored.

But thank you for taking the time to bring this to my attention.

No offence, but you really should have omitted the bold statement. I'm not going to start a technical discussion, but you have many clients who actually know their stuff. Regardless, it's only worth contradicting the client if they are going to benefit. It's easy to see from the transcript that by the time your PM reached me, I felt like I either wasn't being listened to or was being taken for a fool, in which case contradicting me is not going to help... especially since this isn't my first experience of this kind with AH. I'd say it's my main issue with their support - you leave feeling like nobody actually listened or cared.
 
Last edited by a moderator:
You can see they really don't take security seriously.

The emails should be disabled by default and you can opt if you want (After reading and agreeing to a security notice about how insecure it is)

Makes me wonder how secure the rest of their site is!
 
You can see they really don't take security seriously.

The emails should be disabled by default and you can opt if you want (After reading and agreeing to a security notice about how insecure it is)

Makes me wonder how secure the rest of their site is!

To be fair, you don't have to receive those notifications, but that's besides the point IMO:
8660e6af81dc7a686cd3d40d65e4b48d.png


I'm turning those off until it's resolved.
 
Many of our users are not as technology savvy as most of the users on MyBB, and for them being able to access their Clientzone directly from their email notifications is not only a significant convenience, but also a way for them to load top-ups quickly and easily.

Read, "Let us disregard security so we can make more money."

Seriously, Afrihost, you guys need to up your game.

Most likely wishful thinking, but now that they're owned by MTN I hope that a thorough security audit is done on Afrihost's systems - who knows how many other innocuous-seeming "conveniences" there are that has gone unnoticed until now?
 
I've been an AH client since 2009.

I like the ability to top up via the sms they send or through the clientzone which my browser has the password already. I've never used the link in the email, but have never had an issue, but then again, I don't forward on my emails :whistle:

p.s. My credit card details are blanked out, but my ID number is visible.
 
Last edited:
I've been an AH client since 2009.

I like the ability to top up via the sms they send or through the clientzone which my browser has the password already. I've never used the link in the email, but have never had an issue, but then again, I don't forward on my emails :whistle:

p.s. My credit card details are blanked out, but my ID number is visible.

Your username, password, address, name etc. are also available for gleaning. Products can be ordered, username and password changed, bandwidth stolen, identity theft, etc. And this can be done by anyone who can get that link... Your email provider or administrator, anyone who has access to your phone if you receive mail on it, any proxy administrator if you receive mail or click that link while connected via proxy, etc. Again, why would you assume you are sent an insecure direct link to your account in that email to start with? And did you know that before you read this thread? At the very least, afrihost should declare that in the mail and warn users to opt out of the messages if they don't want to risk sharing that info with others.

You don't have to forward the mail to share that info.
 
Last edited by a moderator:
The direct link to the Clientzone in the contained in the Email is intended to add convenience, if you would wish to top-up your account.

What you meant to say was: "Our total disregard for your account security is totally justified when we want to make it as easy as possible for you to give us more money."
 
What you meant to say was: "Our total disregard for your account security is totally justified when we want to make it as easy as possible for you to give us more money."

No, they are saying: "A thief will only be able to steal your money if you give him your card and PIN". Very ignorant of Afrihost to assume that email is secure, especially with the excuse that "quicklink" will help inexperienced users (the same demographics of users who have no clue about internet security, antivirus and their computers are infested with trojans and bots".
 
I've read through several comments, I see also some are now raising this on other social media platforms.

We are very aware of security concerns and we are looking into this. From a service provider perspective, we have our business objectives to balance, and we try to ensure that we keep client information as secure as possible while balancing ease of use.

We'll take this under review and work with management to find the best solution.

I do have one comment about raising these kind of concerns over public media under the guise of safeguarding the privacy of the public. If you do find a vulnerability that can potentially compromise other people, surely making it public for potential fraudsters to exploit is not the best way to deal with this. Not that we are wanting to hide anything, but I think there is also a responsibility from those claiming to be within the web security field to deal with certain issues responsibly (and appropriately) for the good of the whole industry and the clients of that market.

Just my 2c - Use/Don't Use :)
 
I've read through several comments, I see also some are now raising this on other social media platforms.

We are very aware of security concerns and we are looking into this. From a service provider perspective, we have our business objectives to balance, and we try to ensure that we keep client information as secure as possible while balancing ease of use.

We'll take this under review and work with management to find the best solution.

I do have one comment about raising these kind of concerns over public media under the guise of safeguarding the privacy of the public. If you do find a vulnerability that can potentially compromise other people, surely making it public for potential fraudsters to exploit is not the best way to deal with this. Not that we are wanting to hide anything, but I think there is also a responsibility from those claiming to be within the web security field to deal with certain issues responsibly (and appropriately) for the good of the whole industry and the clients of that market.

Just my 2c - Use/Don't Use :)

Perhaps... but with a response like;

A few very valid points have been raised, and we are aware of the concerns that have also been raised.

Many of our users are not as technology savvy as most of the users on MyBB, and for them being able to access their Clientzone directly from their email notifications is not only a significant convenience, but also a way for them to load top-ups quickly and easily.

This notifications emails can be disabled in the Clientzone, if you do not feel comfortable receiving these notifications I would recommend disabling them. If anyone has any safety and security concerns, you are more than welcome to send me a PM so that we can discuss these concerns.

Maybe a bit of social media pressure might result in this being assessed with a bit more urgency than the previous comment seemed to suggest... from business as usual and this is how it is, to working with management, under review to find solution.

/just sayin' like
 
Then don't be like the City of Joburg. Somebody finds a security flaw on your website and notifies you about it. Ignore it, and when he makes it public you blame him. Almost everybody that has commented here has said that it is bad practice, and you keep saying that is is for ease of use. There are better ways of doing that. Fix the security problem, then people won't go more public with the info to force you to change.
 
I've read through several comments, I see also some are now raising this on other social media platforms.

We are very aware of security concerns and we are looking into this. From a service provider perspective, we have our business objectives to balance, and we try to ensure that we keep client information as secure as possible while balancing ease of use.

We'll take this under review and work with management to find the best solution.

I do have one comment about raising these kind of concerns over public media under the guise of safeguarding the privacy of the public. If you do find a vulnerability that can potentially compromise other people, surely making it public for potential fraudsters to exploit is not the best way to deal with this. Not that we are wanting to hide anything, but I think there is also a responsibility from those claiming to be within the web security field to deal with certain issues responsibly (and appropriately) for the good of the whole industry and the clients of that market.

Just my 2c - Use/Don't Use :)

Oh no, I posted your naive response which you shared on MyBB on Twitter (https://twitter.com/Afrihost/status/529145575351287808) - guess what, it was already in the public domain for some time on this very forum, and yet you decided not do anything about it and brushed it off as a "non-issue" / "convenience-function" for inexperienced users (the very same users you should actually protect).

Dealing with security issues is a two-way street. If you acknowledge the problem, but then openly refuse to do something about it (and only announce days later that you will have your IT to look into, because an international security expert was copied on Twitter), than this is not a responsible approach to follow.

I think it is fair to warn users about such issues and it is VERY naive to refer to email as "secure" (whatever that actually means, as you do not use PGP/encryption and TLS is pointless as hardly any ISP supports it).

With every security leak companies have given ample lead-time to resolve the issue. CoJ for example was informed about this issue 2 weeks before it went public and decided not do anything about it.

Other companies deal with such issues responsibly and on time - case in point is the Nike Soweto Marathon registrations - the organisers were informed about a security issue on 24th October at 2pm and the problem was resolved within 3 hours and within a few minutes their social media team and tech team responded to the reported issue.

TBH - there is no "balancing" act required between keeping information secure and making access to functions easy. Every user is aware that his/her information should be protected and as such is used to confirm access via OTP, userid/password etc - this is hardly an unexpected inconvenience for anyone.
 
Perhaps... but with a response like;



Maybe a bit of social media pressure might result in this being assessed with a bit more urgency than the previous comment seemed to suggest... from business as usual and this is how it is, to working with management, under review to find solution.

/just sayin' like

I understand wanting to put pressure for a fix. I'm just raising the issue that if someone were to be affected due to this being raised publicly and then exploited, rather than giving us the opportunity to review this, it would be very unfortunate and not good for the industry.
 
Then don't be like the City of Joburg. Somebody finds a security flaw on your website and notifies you about it. Ignore it, and when he makes it public you blame him. Almost everybody that has commented here has said that it is bad practice, and you keep saying that is is for ease of use. There are better ways of doing that. Fix the security problem, then people won't go more public with the info to force you to change.

This was the first instance that we were aware of this issue, and this is something which has been in place for some time. To be honest this is the first time I've heard of someone sharing their emails and in most of our mailers we do warn clients not to share their email links (especially for promos).

We are very happy to stand behind our practices if we feel it's in our clients best interests, or to change them for the same reasons. We'll review this with our management and decide what we feel is best for our clients as we understand their needs and priorities.
 
Oh no, I posted your naive response which you shared on MyBB on Twitter (https://twitter.com/Afrihost/status/529145575351287808) - guess what, it was already in the public domain for some time on this very forum, and yet you decided not do anything about it and brushed it off as a "non-issue" / "convenience-function" for inexperienced users (the very same users you should actually protect).

Dealing with security issues is a two-way street. If you acknowledge the problem, but then openly refuse to do something about it (and only announce days later that you will have your IT to look into, because an international security expert was copied on Twitter), than this is not a responsible approach to follow.

I think it is fair to warn users about such issues and it is VERY naive to refer to email as "secure" (whatever that actually means, as you do not use PGP/encryption and TLS is pointless as hardly any ISP supports it).

With every security leak companies have given ample lead-time to resolve the issue. CoJ for example was informed about this issue 2 weeks before it went public and decided not do anything about it.

Other companies deal with such issues responsibly and on time - case in point is the Nike Soweto Marathon registrations - the organisers were informed about a security issue on 24th October at 2pm and the problem was resolved within 3 hours and within a few minutes their social media team and tech team responded to the reported issue.

TBH - there is no "balancing" act required between keeping information secure and making access to functions easy. Every user is aware that his/her information should be protected and as such is used to confirm access via OTP, userid/password etc - this is hardly an unexpected inconvenience for anyone.

You're speaking about general leaks here, and I don't believe that this was the case. Again, I'm simply stating that now that we are aware of this issue, we can do what we feel is necessary to address this. But if someone reads your public post on how to exploit another clients details and now does so, do you take no responsibility whatsoever? Just asking out of curiosity here.
 
I do have one comment about raising these kind of concerns over public media under the guise of safeguarding the privacy of the public. If you do find a vulnerability that can potentially compromise other people, surely making it public for potential fraudsters to exploit is not the best way to deal with this. Not that we are wanting to hide anything, but I think there is also a responsibility from those claiming to be within the web security field to deal with certain issues responsibly (and appropriately) for the good of the whole industry and the clients of that market.

Just my 2c - Use/Don't Use :)

And I have a comment about being fobbed off by support staff when I've taken MY time to help YOU resolve YOUR issue. If I feel I won't be heard any other way, I'm going to vent in here... in the hope that the issue will be resolved.
Just follow the original script as it unfolded. It should have been dealt with right after my first message to Afrihost Support. By the second reply, nobody had bothered to even test it and I was being told that I should reset my password (which BTW did nothing to sort my personal issue - not to speak of the bigger issue).

If people's accounts are being hacked after this thread started, it's collateral damage in an effort to resolve the issue that I wasn't confident was being dealt with in the first place.

Just my 2c - Use/Don't Use.
It's now 4 days later. Has the issue been sorted yet?
 
Last edited by a moderator:
To be honest this is the first time I've heard of someone sharing their emails and in most of our mailers we do warn clients not to share their email links (especially for promos).

Forwarding is a feature of most mail clients.
Either you do or don't warn clients not to share their email links...
As far as I can see you don't, here is the full mail:

Afrihost said:
Dear *******
We trust that you are well!
Please note that your account (********** 150 GB) has reached 90.03% of the total available bandwidth. Here are the details of the current account status:
• Total bandwidth limit: 300.000 GB
• Total bandwidth used: 270.096 GB (90.03%)
• Total available (limit minus used): 29.904 GB

What does this mean for you?
Once you have reached 100% of your bandwidth your account will be
capped and you will no longer be able to connect to the internet until
the 1st of next month.

What can you do to avoid being capped when you reach your limit?

If you wish to keep connecting to the internet after you have reached
your limit you need to buy a Top-Up. You can do this by logging in to
your Client Zone , clicking on the 'MyConnectivity' link in the 'My Products'
section and then clicking on the 'TopUp' link to purchase a TopUp Bundle
before you run out of bandwidth.

Please note that your TopUp bundles do not carry over into the new
month - any unused bandwidth expires at the end of the month.
(You will also receive a notification for your "TopUp Bundles")
You can also check your bandwidth that your site has moved at any
time by logging into your Client Zone at http://clientzone.afrihost.com

If you have any questions regarding any of this please let us know

Have a great day further!

Afrihost.com Support


Afrihost.com - The Best Web Hosting...Ever !!!

No indication that the mail includes information that shouldn't be forwarded. That mail may as well have included all the details from my profile. At least then I would have known not to forward it. The URL has been removed, but the insecure link is the first one. The second one requires a login. All I see in that mail is benign information, and one could be forgiven for assuming the first link was secure if one clicked the second link to check. Why is the second link different anyhow?

My advice? Let the thread die a natural death and solve the issue - we'll soon forget about it.
 
Last edited by a moderator:
You're speaking about general leaks here, and I don't believe that this was the case. Again, I'm simply stating that now that we are aware of this issue, we can do what we feel is necessary to address this. But if someone reads your public post on how to exploit another clients details and now does so, do you take no responsibility whatsoever? Just asking out of curiosity here.

No, I would not take responsibility for it. You yourself said that this issue existed since the beginning of time and that your company and security IT staff "relies" on people not sharing information. Email is not secure unless it is encrypted which I doubt you do. If I come across issues, I contact the company involved and hope that they will fix the issue.

In this scenario someone else found it, and I was perplexed (and honestly annoyed) by your ignorance and responses (especially considering that you had a security leak last year and I would have thought that when this happens a company would go through thorough checks to cover the whole IT landscape).

It is a very naive assumption to think that just because a company was alerted about a security issue, that the threat only starts to exist at that point in time. In your case for example, the possibility of peoples email accounts being compromised and then access gained to their AH was and is a real threat since you implemented this functionality. Worst of all is that you would not have auditing in place to figure out if the information was accessed by the legitimate user.

I honestly would have by now revoked the convenient access function until you have implemented proper access controls. Companies should be thankful for people reporting issues like that and not trying to persecute them - everyone knows that the real hackers are the people who have been abusing your system and bypassing your security controls for years and would obviously not alert you to those issues.
 
Top
Sign up to the MyBroadband newsletter
X