Who purchases a card online? Don't you just buy one ofr 10 bucks at the station? :wtf:
 
I actually used this site 2 days ago... I bought the Gold card at the station, but when I found this site I got the impression that I could like the card to my personal profile.

One of the things that made me think this was that the site says registering your card is the only way to get a refund of the money you've loaded onto your Gautrain card.

The links I followed to get to this website were on the official Gautrain website, so that's a big worry!!!
 
Contacted for comment, the Bombela Operating Company disavowed all knowledge of the site, saying that websites and marketing are not their domain and directed all queries to the Bombela Concessions Company.

But then why are you specifically named on the site???
 
Another company linked to the GautrainCard site is 3G’s Digital, which is credited in the footer with the site’s design and development.

3G’s lists Ricardo Pieterse as its contact person, and the 3G’s website is also registered in Pieterse’s name.

Queried about Gautraincard.co.za, Pieterse confirmed that he had designed and developed it under contract by Bombela. He requested that further questions be sent to him by e-mail.

MyBroadband asked about the privacy concerns raised, but Pieterse directed further queries to Errol Braithwaite at Bombela.

Braithwaite is the person at Bombela who the Gautrain Management Agency alerted about the issue, but feedback from Bombela was not immediately forthcoming at the time of writing.
So if the site is not an official Bombela site, then something fishy is going on if the trail leads to Errol Braithwaite.
If it is official, then Bombela should be honest about it.

Either way, it is a poor design if info is so easily retrieved from it.
 
Just checked my email and seems I registered with the site in 2011 :/ Feck.
 
im also registered for this and when i went to get my card at Gautrain station, they could pick up my details. that tells me that this is linked to their systems.
 
Anyone know how they managed to access this information?

Any of the OWASP issues - most likely SQL injection or having files being indexed by Google. If the full data-set leaked (including ID numbers), people will have a field day. And it's POPI month (or at least I expect that POPI will either be delayed or become active).
 
Last edited:
I blame MagicDude and his "hacking" skills :p

Oh I wonder if House will be along shortly to rap us all on the knuckles :whistle:
 
I blame MagicDude and his "hacking" skills :p

Oh I wonder if House will be along shortly to rap us all on the knuckles :whistle:

Yes! :mad:

I was just about to tell Magic it does not work like that in law... careful now!
 
I blame MagicDude and his "hacking" skills :p

Oh I wonder if House will be along shortly to rap us all on the knuckles :whistle:

ECT bla bla bla. TBH, any sensible user visiting that site would have thought of it being a scam site. Still quite bizarre that it allows to capture data, store it somewhere centrally for other systems to retrieve and only 1 person seems to know about it. No HTTPS, hardened IIS or anything. So bizarre that in today's age server- and application security is disregarded.
 
Top
Sign up to the MyBroadband newsletter
X