Voda Joke [portal security flaw - RESOLVED]

Trib

Active Member
Joined
Sep 10, 2007
Messages
35
Reaction score
6
So you want to laugh...

So I found a flaw on vodacoms website by accident and thought i would be the good samaritan and notify them. I proceeded to the Contact US on the website and wrote the following:

Please contact me if you wish to know about a security flaw I have found in your vodacom.co.za website. In my opinion this is a serious security flaw. Regards, Paul

The response I got was:

Thank you for your e-mail.

Kindly be advised that you may contact our IT Department on 082 191(charged call) and they will be able to assist you in this regard.

Alternatively you may contact our Head Office on +27116535000 (charged call) during office hours only and they will direct you to the relevant department for further assistance and feedback.

Regards

Jacqueline De Morney

Anyway... I don't have the time and effort to sit talking to someone at a call centre trying to explain a technical glitch to them on THEIR website.
 
Anyway... I don't have the time and effort to sit talking to someone at a call centre trying to explain a technical glitch to them on THEIR website.
Never mind the fact that both numbers are charged calls.
 
Just post what the flaw is here,... its a vodacom section so their rep can note it down and forward it to the relevant dept. :erm:
 
Companies love passing the buck onto their customers these days apparently.
 
Jacqueline De Morney, I.M.O, does not have the technical expertise to assess the technical details on the email, and therefore redirects you to IT. Seems like Vodacom needs technical personnel rather than a public relations officer to reply to queries.
 
Maybe you should have explained to them in laymans terms in a way they can understand:
Your website has a disastrous security flaw and will be hacked by every teen geek in South Africa so please fix it up.This is your final warning.
 
Maybe you should have explained to them in laymans terms in a way they can understand:
Your website has a disastrous security flaw and will be hacked by every teen geek in South Africa so please fix it up.This is your final warning.
-Anonymous

Fixed :p
 
Jacqueline De Morney, I.M.O, does not have the technical expertise to assess the technical details on the email, and therefore redirects you to IT.
You think the email was read by a person? I thought it was just an automated response.
 
I would not post the flaw here, even though I would like to, just to spite them.

Here is my laymans definition :P
Basically the flaw involves logging in to vodacom.co.za as someone else and being able to do anything on vodacom.co.za as that person (like transfer airtime etc).

Serious? I think so...
 
I would not post the flaw here, even though I would like to, just to spite them.

Here is my laymans definition :P
Basically the flaw involves logging in to vodacom.co.za as someone else and being able to do anything on vodacom.co.za as that person (like transfer airtime etc).

Serious? I think so...

In March this year I by accident stumbled upon a IT firm's site an noticed a vulnerability so I traced it back to a prominent SA web development studio. Not surprised all the sites developed by the web design studio exhibited the same programming mistake, even the sites developed in ASP.

So I thought it well to inform the studio of the vulnerability via e-mail, after about a day and still not receiving a reply from them I proceeded to contact them by telephone and informed the gentleman there about the flaw and how it could be used to compromise their sites. About two weeks later, one of the sites developed by this studio was defaced and made the papers. I was shocked and proceeded to browse the defaced site, only to find that the flaw that I reported twice, still wasn’t patched, however I’m not sure if this hole was used in defacing the site.

So my conclusion here is, you can take a horse to the water, but you can’t be sure that it will drink.
 
Last edited:
You think the email was read by a person? I thought it was just an automated response.

I also thought the same, but do you think they would assume all web related queries were IT related, and provide an automated response directing the person to their IT dept?
 
So you want to laugh...

So I found a flaw on vodacoms website by accident and thought i would be the good samaritan and notify them. I proceeded to the Contact US on the website and wrote the following:
The response I got was:
Anyway... I don't have the time and effort to sit talking to someone at a call centre trying to explain a technical glitch to them on THEIR website.

Let it go Viral, and after they have seen the "O shlt" - Factor at work they should fix it soon enough :p:D


Maybe you should have explained to them in laymans terms in a way they can understand:
Your website has a disastrous security flaw and will be hacked by every teen geek in South Africa so please fix it up.This is your final warning.

+1. Haha, I also feel that maybe sending something like this would be more urgently received :)

I would not post the flaw here, even though I would like to, just to spite them.

Here is my laymans definition :P
Basically the flaw involves logging in to vodacom.co.za as someone else and being able to do anything on vodacom.co.za as that person (like transfer airtime etc).

Serious? I think so...

Sell it to the highest bidder and let them rob Vodascum blind
 
perhaps you should change your email to make it sound like they could lose money:

"after much synergistic deliberation and a quantative analisys, the decline in vodacom's revenue could be devastating and would have to be absorbed by the stockholders."

everyone understands it better if you fill it with buzzwords that make almost no sense.
 
So you want to laugh...

So I found a flaw on vodacoms website by accident and thought i would be the good samaritan and notify them. I proceeded to the Contact US on the website and wrote the following:



The response I got was:



Anyway... I don't have the time and effort to sit talking to someone at a call centre trying to explain a technical glitch to them on THEIR website.


Pm sent , need to know more about the flaw.
 
Top
Sign up to the MyBroadband newsletter
X