FNB website exposed private information

fnb said:
“Whilst we have not received complaints until this point and the details are only available to the individual [who reported the issue to MyBroadband], FNB is committed to ensuring that customers are comfortable with the facility,” Klaassen said.
Now that's a bit of an assumption.
 
/waits for bank's contact

Given that they took that long to acknowledge the problem, I might be waiting indefinitely. Reckon I'll drop my banker a line tomorrow for comment.
 
/waits for bank's contact

Given that they took that long to acknowledge the problem, I might be waiting indefinitely. Reckon I'll drop my banker a line tomorrow for comment.

FNB Business banking is slowly driving me gatvol in regard with outstanding queries, their branch desks and service (online / HQ) desks are never on the same level, how their correspondence and inter-branch communication is done are beyond me, or their CRM application sucks.
 
lol, I had to IP block fnb from spamming my courier tracking


IP : 196.11.134.77 Neighborhood
Host : mxincontact.fnb.co.za OK
Country : South Africa

196.11.134.77
RC008671333ZA
2014-06-28 08:30:56
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601417ZA
2014-06-28 08:30:43
Track Once SouthAfricanPostOffice
196.11.134.77
RC008600592ZA
2014-06-28 08:30:37
Track Once SouthAfricanPostOffice
196.11.134.77
RD971201708ZA
2014-06-28 08:30:35
Track Once SouthAfricanPostOffice
196.11.134.77
RC008671364ZA
2014-06-28 08:30:26
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601425ZA
2014-06-28 08:30:18
Track Once SouthAfricanPostOffice
196.11.134.77
RC008600487ZA
2014-06-28 08:30:17
Track Once SouthAfricanPostOffice
196.11.134.77
RC008596685ZA
2014-06-28 08:30:15
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601394ZA
2014-06-28 08:30:03
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239120ZA
2014-06-28 08:30:01
Track Once SouthAfricanPostOffice
196.11.134.77
RC008670063ZA
2014-06-28 08:30:00
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601567ZA
2014-06-28 08:29:55
Track Once SouthAfricanPostOffice
196.11.134.77
RC008596751ZA
2014-06-28 08:29:54
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601536ZA
2014-06-28 08:29:38
Track Once SouthAfricanPostOffice
196.11.134.77
RC008597068ZA
2014-06-28 08:29:37
Track Once SouthAfricanPostOffice
196.11.134.77
RC008600439ZA
2014-06-28 08:29:35
Track Once SouthAfricanPostOffice
196.11.134.77
RC008600411ZA
2014-06-28 08:29:17
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601403ZA
2014-06-28 08:29:14
Track Once SouthAfricanPostOffice
196.11.134.77
RC008665179ZA
2014-06-28 08:29:09
Track Once SouthAfricanPostOffice
196.11.134.77
RC008600898ZA
2014-06-28 08:29:02
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239116ZA
2014-06-28 08:29:02
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601540ZA
2014-06-28 08:28:50
Track Once SouthAfricanPostOffice
196.11.134.77
RC008596677ZA
2014-06-28 08:28:48
Track Once SouthAfricanPostOffice
196.11.134.77
RC008600650ZA
2014-06-28 08:28:47
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601377ZA
2014-06-28 08:28:12
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601482ZA
2014-06-28 08:28:09
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601519ZA
2014-06-28 08:27:54
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601377ZA
2014-06-28 08:27:53
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239147ZA
2014-06-28 08:27:52
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601187ZA
2014-06-28 08:27:44
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674502ZA
2014-06-28 08:27:40
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601385ZA
2014-06-28 08:27:33
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674493ZA
2014-06-28 08:27:25
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601071ZA
2014-06-28 08:27:25
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601350ZA
2014-06-28 08:27:13
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674476ZA
2014-06-28 08:27:11
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601085ZA
2014-06-28 08:27:06
Track Once SouthAfricanPostOffice
196.11.134.77
RC008597037ZA
2014-06-28 08:26:59
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601363ZA
2014-06-28 08:26:57
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674480ZA
2014-06-28 08:26:57
Track Once SouthAfricanPostOffice
196.11.134.77
RD971199709ZA
2014-06-28 08:26:48
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674462ZA
2014-06-28 08:26:44
Track Once SouthAfricanPostOffice
196.11.134.77
RC008597045ZA
2014-06-28 08:26:44
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239147ZA
2014-06-28 08:26:42
Track Once SouthAfricanPostOffice
196.11.134.77
RD971200132ZA
2014-06-28 08:26:28
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601346ZA
2014-06-28 08:26:25
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674459ZA
2014-06-28 08:26:24
Track Once SouthAfricanPostOffice
196.11.134.77
RD971200177ZA
2014-06-28 08:26:06
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674459ZA
2014-06-28 08:26:01
Track Once SouthAfricanPostOffice
196.11.134.77
RD971200203ZA
2014-06-28 08:25:49
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239439ZA
2014-06-28 08:25:40
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239195ZA
2014-06-28 08:25:40
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674445ZA
2014-06-28 08:25:39
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674431ZA
2014-06-28 08:25:25
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239221ZA
2014-06-28 08:25:22
Track Once SouthAfricanPostOffice
196.11.134.77
RC008601814ZA
2014-06-28 08:25:22
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674428ZA
2014-06-28 08:25:11
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239456ZA
2014-06-28 08:25:03
Track Once SouthAfricanPostOffice
196.11.134.77
RC008674414ZA
2014-06-28 08:24:55
Track Once SouthAfricanPostOffice
196.11.134.77
RD971239456ZA
2014-06-28 08:24:42
Track Once SouthAfricanPostOffice
 
whats a big fail here for FNB is that they were alerted about this in July but only acted on it now because mybb queried it.

not too big on security are they ?

out of interest can someone sue them if they were able to prove fnb knew about the issue early on and said person was a victim of identity theft or similar based solely on the information they were able to get from this flaw ?
 
This is really shocking news, thanks for letting us know about this security breach!
 
I really don't understand how this happens.

Do the developers who wrote these services just not care?

The first thing I think of when writing anything that will expose personal details online is security. Yes, it takes a bit of extra time but that's what good developers do.
 
Now that's a bit of an assumption.

It is also untrue that they have had no other complaints. I have been unsuccessfully trying for some weeks to get answers re poor security relating to the online card debacle(amongst other security issues). FNB's biggest sin is that they are neither open nor honest about their security.
 
lol, I had to IP block fnb from spamming my courier tracking


IP : 196.11.134.77 Neighborhood
Host : mxincontact.fnb.co.za OK
Country : South Africa

Dude, that's the outgoing NAT for pretty much the whole bank's web browsing.
 
Another OWASP-A4 (https://www.owasp.org/index.php/Top_10_2013-A4-Insecure_Direct_Object_References) - this is just sloppy development and inexperience. And when it happens you man up and fix it.

You will be surprised how man websites have this issue. You will probably find that in al OWASP-A4 cases, hackers have exploited this already and data-mined it. Once a site allows insecure direct object references it will be fairly easy for an intruder to SQL inject into other systems.
 
You can never be too busy for security especially for a bank. I would like to hear the explanation for this
 
You can never be too busy for security especially for a bank. I would like to hear the explanation for this

Devs probably spent too much time on MyBB's Current News and PD section and did not pay due diligence to security.
 
Let me tell you all how this happens!

BEE. These companies and banks are forced to use BEE companies. It is a fact that all these BEE IT companies hire only ****! It is only the owner making money and no one else. So, you hire these companies and along comes the so-called 'experts' with no experience and puts a website like this together.

This is how your personal identifiable information ends up in the hands of hackers, proudly sponsored by your own Bank!
 
Let me tell you all how this happens!

BEE. These companies and banks are forced to use BEE companies. It is a fact that all these BEE IT companies hire only ****! It is only the owner making money and no one else. So, you hire these companies and along comes the so-called 'experts' with no experience and puts a website like this together.

This is how your personal identifiable information ends up in the hands of hackers, proudly sponsored by your own Bank!

Thats a bit of a stretch considering pretty much ALL of FNB's online presence is dev'ed in house and not by some random BEE IT company.

This is nothing more than piss poor coding and very lax code review and security review standards.
 
Thats a bit of a stretch considering pretty much ALL of FNB's online presence is dev'ed in house and not by some random BEE IT company.

This is nothing more than piss poor coding and very lax code review and security review standards.

Well, according to my experience with the bank, they outsource a number of IT functions. In fact, in-house staff focus more on PC problems.

In fact, WesBank, part of the group, also outsource all development to another company. Their staff are situated inside the bank though and Wesbank also have their own IT department that works mainly on staff PC issues. But, hey, that is just me.....
 
Last edited:
Well, according to my experience with the bank, they outsource a number of IT functions. In fact, in-house staff focus more on PC problems. But, that is just me.....

As far as I'm aware all the major banks have in house dev teams for most of their online presence. Yes they will outsource the design aspect possibly, but then it comes back in house to be dev'd and completed.

They do definitely outsource a number of IT Functions.. pretty much every company does that these days.
 
I disagree.. I think passing the buck to their vendors is complete and utterly disingenuous because the vendors will develop stuff according to spec.

When working with vendors, you either work with industry specific player (eg. Financial or telecoms systems expert vendor) or a general vendor. Since this is not exactly a financial specific application I reckon maybe, if it wasn't in house dev then it was a general IT vendor.

While secure code/practices are things that must be done.. People tend to be lax/lack experience when they do not work with sensitive data (non-financial) and then the ownership & risk needs to be addressed on the client side. So whatever before might be guilty.. But the proper person to hound is the it product owner on FNB side who approved it.

Ps. This usually happens when u use multiple vendors and/or in house ones who have not done thorough training on secure coding. To claim is BEE related is short sighted.. It's training issue as well as product owner responsibility and client to verify its compliance to security standards.
 
Top
Sign up to the MyBroadband newsletter
X