CoJ: exposed bills due to "malicious hack"

He should send them a lawyers letter requesting for the accusation to be withdrawn and a apology made on the same mediums or face a suit for damaging his reputation.
 
Please help. I live in a block of flats... My postbox number is 304.... but I accidentally opened 305 as there was no lock on it and it was next to mine.. Is it really my fault? Can the police open an investigation against me? Or is it the owner of 305 that should of put a lock on his box?
 
Please help. I live in a block of flats... My postbox number is 304.... but I accidentally opened 305 as there was no lock on it and it was next to mine.. Is it really my fault? Can the police open an investigation against me? Or is it the owner of 305 that should of put a lock on his box?

Papa wag vir jou.
 
Does anyone have a link to the podcast about yesterday's show with Sanral and the CoJ? I can not find it online (702 website or Soundclod).
 
I'm not sure which of the website's terms and conditions they profess to him breaking. You can read the terms of use here: http://www.joburg.org.za/index.php?option=com_content&view=article&id=486&Itemid=80

At best point 3 applies: "3. You agree that your use of this website is for lawful purposes only. You agree that you will not use this website for any unlawful purpose, including but not limited to: the commission of a criminal offence; to gain unauthorized access to other computer systems; or for the transmission of unlawful material."

In the event of the website owner displaying information that you are not legally meant to read in an open fashion, is your accidental access to it considered a criminal offence? Surely the issuer of that information is the one that is criminally (and civilly) responsible for the breach? Further, did the person who accessed the data do so maliciously, "to gain unauthorized access to other computer systems"? I think not.

You cannot pursue someone criminally for accessing content that is openly accessible on your website (else they really should be pursuing Google for Googlebot's scraping of many of the statements). You can pursue someone civilly (not criminally) for breach of the website's terms of use, but I fail to see any evidence that website terms were breached. The CoJ's reaction is going to cause a Streisand Effect - they would have been better off patching the issue and apologising for their mistake like EVERYONE else does.
 
This is the only way they know to respond to matters of this nature. Tact is not a concept they are familiar with.

Also they have zero knowledge of the technical terms they bandy about in their ludicrous allegations. They don't even know what the internet is...
 
Am sure a few people ran a script to iterate through all the numbers and downloaded all the invoices.
The funny thing about this, is that its such an obviously closable hole in the system that noone would have thunk it would expose everything, and so not many people would have tried anything before.

The pertinent question is to the database design, and if there is any actual link between an invoice and a user defined in their database? And if so, why that is not checked before a invoice is able to be viewed. If there is in fact no link.....then they are using just session details to check if any user is actually logged in before giving him any information he wants
 
I'm not sure which of the website's terms and conditions they profess to him breaking. You can read the terms of use here: http://www.joburg.org.za/index.php?option=com_content&view=article&id=486&Itemid=80

Those are the T&Cs for the general website. The T&Cs for the eservices site (Where the statements are accessible from) are in this PDF document. Point 7.1 makes me laugh
7.1 The COJ has used its best efforts to ensure that proper security controls are in place around the Website.
and
7.2 Whilst the COJ does facilitate the use of security features, processes and procedures on the Website which are in accordance with or higher than accepted industry standard, the COJ cannot guarantee the security of the information that is
transmitted by the User to the COJ. Notwithstanding various precautions taken by the COJ, the User accepts that by transmitting information over the Internet, such information may be subject to unlawful access or monitoring and that the COJ is accordingly not liable for any loss, harm or damage which the User may suffer as a result of this.
 
http://www.news24.com/Technology/Web/City-of-Joburg-opens-case-against-hackers-20130822

The city acknowledged the problem and froze the website.

But the CoJ’s Abraham Mahlangu says the e-billing system was not faulty and Hillbrow police are investigating.

“We do not have any suspects right now, but we do have IP addresses of those who accessed personal information of account holders.”

Information Technology expert Gerd Naschenweng blew the whistle.

He says the breach exposed the private details of account holders to anyone with an internet connection.

“It shows how much money one has paid and someone can use that for all types of fraud like opening up bank accounts and rica cellphones”

EKHURULENI e-SERVICES ALSO VULNERABLE

Its emerged Ekhuruleni could also be dealing with a security hole in its online billing service.

Tech blogging site Htxt Dot Africa says users logged onto the Ekhuruleni user account system can access other people's invoices by entering a direct url link to the files.

The website’s editor Adam Oxford explains how the site has been compromised.

“If you logged into that system and change a few digits in the URL, it takes you to the PDF invoices. So basically, you can download someone else’s invoices.”

He says he doesn't believe the CoJ’s account was hacked.

“It looks much more like a security oversight because the software company have already begun rolling out a fix for it already.”

SANRAL ACCOUNT VIEWED

The South African National Roads Agency (Sanral) says one of its 350 accounts with the CoJ was among those accessed.

Eyewitness News had sight of Sanral's account which showed it owed the city R55,000.

However, the roads agency says it’s disputing the municipal charges and has tried numerous times to resolve the matter with the council.
 
Those are the T&Cs for the general website. The T&Cs for the eservices site (Where the statements are accessible from) are in this PDF document. Point 7.1 makes me laugh

and

Well, this whole spectacle shows that they added NO BASIC security. That should be punishable.
 
:-) how do you know its been maliciously hacked and not just a bad service like many other council relations?
like... "The council workers are on go-slow protest."... howz that different to how they normally work :-)
 
This is probably going to be their defence in corruption trials.

"Well yes we did leave the safe open and all the bank account passwords are password, we are however shocked that someone has stolen all the monies"
 
The City of Joburg’s (COJ) Abraham Mahlangu should be fired because instead of identifying the problem and resolving it he would rather start accusing the person that informed him of it of "hacking".

Browsing the internet is not hacking when you enter a url with one digit changed to get somebody else's account details is not "hacking".Abraham Mahlangu you don't belong in this age especially not in a top position if you don't know how to use the Internet,learn to use it and how to identify "hacking" or make way for somebody who knows what the hell is going on because clearly you do not.

Seriously he should be fired for trying to blame this on the whistle blower and I wonder if Gerd could lay criminal charges against him for allowing other people to have access to his municipal rates statement.

If anything the CITY of Johannesburg should give GERD a reward for identifying and reporting the flaw in the sites security openly instead of using it for criminal activities.Come on ANC elections are coming soon don't make yourself look even more incompetent give Gerd a medal instead of laying criminal charges against a responsible citizen.
 
The City of Joburg’s (COJ) Abraham Mahlangu should be fired because instead of identifying the problem and resolving it he would rather start accusing the person that informed him of it of "hacking".

Abraham Mahlangu should be charged as well. Is it not a criminal offense to lie to the police to start a investigation?
I mean, it's an obvious blatant lie, as there was no security configured for that server.
 
Top
Sign up to the MyBroadband newsletter
X