DigiTech "app store" runs on outdated software and uses R925 website template

Waiting for the "sophisticated hacking unlike any seen before" statement from them.
 
So how much did it cost the taxpayers ? Have any figures been released yet ?
 
It is actually an excellent business model if you take into account that the average comrade can't count.

Imma send Guavament a fake invoice of R925'000'000.00, call them, and say they must pay me. It is actually nine hundred and twenty five rand. The zero's are just place holders. They have to input it like that on their banking app.

I will be Zuma-laughing all the way to the Bahamas.
 
Well, it also doesn't take a security researcher to see that it runs on Drupal and PHP 5.6 (which depreciated only in 2018, not 2014 as per article - https://endoflife.date/php).
It was running PHP 5.3 a few days ago. Unsure what happened there.

And yea, couldn't even be bothered to run sudo certbot --apache or whatever the Windows Server :sick: equivalent is...
This seems to be a general issue on .gov.za sites. They always launch without certs. I wonder if there's some policy about getting certs from government's own CA rather than using Let's Encrypt.

Lol, this article is now featured on the CyberSecurityHub (https://www.cybersecurityhub.gov.za/) website under "latest news".
Hah! I think they pull the RSS feed from our Security category.
 
This seems to be a general issue on .gov.za sites. They always launch without certs. I wonder if there's some policy about getting certs from government's own CA rather than using Let's Encrypt.
Doubt there's a policy - https://www.gov.za/ itself runs on a Let's Encrypt cert...
 
  • Like
Reactions: Jan
Dude this is SA. Nobody does corruption like us. Have some respect for our policiticans, they are capable of way more than a mere 500% markup.
I'm not sure the South African government ranks very high in this activity. Globally corruption runs into trillions of Dollars per year. The US is one of the major players in providing the means to hide and launder ill-gotten gains.
 
Why use such outdated software when it is free to upgrade. Actually, if youn install it today, it defaults to the latest version. I'm a very casual website manager (my own website) and I managed to upgrade from each major release of Drupal. This is really sad, and one wonders how it passed the government's Cybersecurity Hub requirements (https://www.cybersecurityhub.gov.za/). Maybe no-one checked, as a non-SSL link for private information must surely be a no-no.
The company this was tendered to almost certainly just copy pasted an existing (old) setup and did some re-theming.

Not only is not having a Cert/HTTPS a big no no, at the very least, the entire log in/registration process is done in plaintext and wide open for eavesdropping. They are leaking credentials. The Contact Us form is also leaking details (submitted in plaintext).

The only responsible way forward is to take the site down, HTTPS added (with appropriate TLS versions/ciphers) and all registered have their passwords reset and notified their details have potentially been leaked.

These are just surface level issues. If this is what the front door looks like, you can be certain that its a total **** show behind the scenes.
 
Cadres has to eat people! Don't be so negative toward the cadres. lol!

Yea. this is going to be costing millions of ZAR.
 
Top
Sign up to the MyBroadband newsletter
X