Possible Security Breech at SARS

webslave

Well-Known Member
Joined
Dec 23, 2005
Messages
148
Reaction score
0
This posting is for the geeks and anyone interested in personal information security. I do hope I am wrong.

The TAX dept it seems is possibly unwittingly trying to access your computer, if this ie due to poor programming or poor understanding of how to programe the PDF doctype for security, however those who have more familiarity can look into this.

What is happening is when you are not using Windows version of the PDF and you have a tight firewall the PDF from SARS is not downloading the information even with the right PDF viewer version installed.

IF this is poor programming then that needs to be sorted, however the other alternative is far more sinister and this part is something your IT people can look into....

1.Check for data leakage when downloading PDF's from the SARS site.

If the document as I suspect is possibly acting as an access /tracking/targeting conduit lock down your firewall to block it, set up a virtual container with no access to your actual system or data, reroute through a VPN to an external server with no access to your tracks ( preferably one in the Germany) and use that container to open the document.

What I suspect is possible is that this might be opening a backdoor into the system that this document is opened on.

I could be wrong, however if I was I would have this same problem with all the banks PDF documents.... I really do hope I am wronmg about this.

There is no rational reason to have to wait for the contents of a secure pdf to download after the document has been opened.

Please share this and get your IT departments to do a thorough clean and firewall NTOP and HTOP check for data leakage...

Also check if your computer suddenly has "USB DRIVES" attached when booting.... even when your actual USB drives are not connected....

These are observations that have just happened to me, having used teh efiling system before without this I know from personal experience that this is new behaviour.


This is the message you get
"Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF
viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by
visiting http://www.adobe.com/products/acrobat/readstep2.html.
For more assistance with Adobe Reader visit http://www.adobe.com/support/products/
acrreader.html.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark
of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other
countries.
"
http://www.theregister.co.uk/2010/04/06/wormable_pdfs/
Please look into this and let me know what you find. I am using Ubuntu 12.04 linux with the latest PDF reader plugins etc. installed.
 
You are being paranoid.
I'm familiar with the tech being utilised by SARS.
They fetch data from their secure severs to dynamically build the form as you populate data.
If all this data is built into the form, then the form becomes huge.
i.e. Data is fetched from the server on a need-to-have basis.


A typical example of this is filling in address details using multiple drop boxes.
Once you select country from dropbox 1, data is fetched from the server to populate dropbox 2 with available provinces in the country selected in dropbox 1.
If they stored the data in the form, they would have to store all provinces in all countries of the world, making the form huge.
 
This posting is for the geeks and anyone interested in personal information security. I do hope I am wrong.

The TAX dept it seems is possibly unwittingly trying to access your computer, if this ie due to poor programming or poor understanding of how to programe the PDF doctype for security, however those who have more familiarity can look into this.

What is happening is when you are not using Windows version of the PDF and you have a tight firewall the PDF from SARS is not downloading the information even with the right PDF viewer version installed.

IF this is poor programming then that needs to be sorted, however the other alternative is far more sinister and this part is something your IT people can look into....

1.Check for data leakage when downloading PDF's from the SARS site.

If the document as I suspect is possibly acting as an access /tracking/targeting conduit lock down your firewall to block it, set up a virtual container with no access to your actual system or data, reroute through a VPN to an external server with no access to your tracks ( preferably one in the Germany) and use that container to open the document.

What I suspect is possible is that this might be opening a backdoor into the system that this document is opened on.

I could be wrong, however if I was I would have this same problem with all the banks PDF documents.... I really do hope I am wronmg about this.

There is no rational reason to have to wait for the contents of a secure pdf to download after the document has been opened.

Please share this and get your IT departments to do a thorough clean and firewall NTOP and HTOP check for data leakage...

Also check if your computer suddenly has "USB DRIVES" attached when booting.... even when your actual USB drives are not connected....

These are observations that have just happened to me, having used teh efiling system before without this I know from personal experience that this is new behaviour.


This is the message you get
"Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF
viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by
visiting http://www.adobe.com/products/acrobat/readstep2.html.
For more assistance with Adobe Reader visit http://www.adobe.com/support/products/
acrreader.html.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark
of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other
countries.
"
http://www.theregister.co.uk/2010/04/06/wormable_pdfs/
Please look into this and let me know what you find. I am using Ubuntu 12.04 linux with the latest PDF reader plugins etc. installed.

You are wrong about it. Myself and a few people on here worked on the systems at SARS and you cannot access core client information from the PDFS. Lol.
 
You are wrong about it. Myself and a few people on here worked on the systems at SARS and you cannot access core client information from the PDFS. Lol.

Glad you are sure about that.... I had to open my firewall for the darn things to work... very annoying. Done now I can close it again..

Thats the problem using closed source products.... you never know.do you? really...


Thanks for the feedback... PDF's are so different from what they started out as....
 
Last edited:
And yes I am paranoid... especially about security on the web.
 
Top
Sign up to the MyBroadband newsletter
X