Joburg billing leak not a hack: whistle blower

Lol.

All that happened was this:

To open a statement, ie www.123.co.za/statements/fetch.php?id=0123456 you need to be logged in. That worked fine.

However, it did not check that you are user 0123456 before allowing you to fetch statement 0123456. That's where their bug came in. It's a bug, not a hack.
 
Lol.

All that happened was this:

To open a statement, ie www.123.co.za/statements/fetch.php?id=0123456 you need to be logged in. That worked fine.

However, it did not check that you are user 0123456 before allowing you to fetch statement 0123456. That's where their bug came in. It's a bug, not a hack.

You did not need to be logged in.
The location that held the pdfs was completely unsecured.

Best analogy I can think of:
You go to a council office. You ask to see your statement. They check your id and details and tell you "ok, your statement is in the building across the road, on the fourth floor, on table 27.
The building across the road has no entry control, no guards, and everybody's statements laid out on tables, not even in envelopes. Anyone can walk in off the street and look at anyone's statement because they're all laid out for the world to see.

No hack here at all.
 
You did not need to be logged in.
The location that held the pdfs was completely unsecured.

Best analogy I can think of:
You go to a council office. You ask to see your statement. They check your id and details and tell you "ok, your statement is in the building across the road, on the fourth floor, on table 27.
The building across the road has no entry control, no guards, and everybody's statements laid out on tables, not even in envelopes. Anyone can walk in off the street and look at anyone's statement because they're all laid out for the world to see.

No hack here at all.

I tried it that day, wouldn't let me view it if I hadn't logged in beforehand, and this was before they took it down.
 
I have never logged into eservices from my phone. I have 5 pdfs on my phone that say you are mistaken ;)
 
I tried it that day, wouldn't let me view it if I hadn't logged in beforehand, and this was before they took it down.

I'm not a CoJ customer and have never visited their website, let alone logged in. I too had full access to all statements. There was no login required whatsoever...
 
Changing source code is a hack. Changing the URL is not a hack.

BTW does that site use SSL?
 
7 years later I notice the exact same vulnerability with another municipality that recently switched systems/providers. Is there a recommended way to report these things or is it not worth bothering (TIA)?
 
Top
Sign up to the MyBroadband newsletter
X