{"id":134946,"date":"2015-08-13T13:58:05","date_gmt":"2015-08-13T11:58:05","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=134946"},"modified":"2015-08-17T11:56:54","modified_gmt":"2015-08-17T09:56:54","slug":"big-sa-websites-exposed-by-basic-security-flaw","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/134946-big-sa-websites-exposed-by-basic-security-flaw.html","title":{"rendered":"Big SA websites exposed by basic security flaw"},"content":{"rendered":"<p>Several prominent South African websites appear to be vulnerable to cross-site scripting (XSS) vulnerabilities, according to the online open bug bounty community XSSposed.<\/p>\n<p>Established in 2014 as an XSS archive, <strong><a href=\"https:\/\/www.xssposed.org\/search\/?search=.co.za&amp;type=host\" target=\"_blank\">XSSposed\u2019s listings for SA<\/a><\/strong> websites grew substantially\u00a0during July 2015.<\/p>\n<p>XSS vulnerabilities occur when a web application uses input from a user within the output it generates without validating or encoding it.<\/p>\n<p>An XSS attack is a type of injection, and may be used to send a malicious script to a user whose browser has no way to determine that the script should not be trusted.<\/p>\n<p>In this way, attackers can access cookies, session tokens, or other sensitive information retained by the browser and used with that site.<\/p>\n<h3 class=\"my-4\">Prominent SA websites exposed<\/h3>\n<div id=\"attachment_106441\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/07\/E-commerce-SA.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-106441\" class=\"size-full wp-image-106441\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/07\/E-commerce-SA.png\" alt=\"E-commerce SA\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/07\/E-commerce-SA.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/07\/E-commerce-SA-250x166.png 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-106441\" class=\"wp-caption-text\">E-commerce SA<\/p><\/div>\n<p>Among the websites listed on XSSposed are South African e-commerce players Takealot, Makro, Game, OLX, Spree, Zando, and Raru.<\/p>\n<p>Some of the vulnerabilities reported are already listed as fixed, while others are still in the \u201chold\u201d phase, allowing sites to patch issues before they are\u00a0disclosed.<\/p>\n<p><strong>Takealot.com<\/strong>\u00a0had a vulnerability in its search system reported on 14 July 2015 which was patched on 4 August. A new vulnerability was reported on 27 July, which is still \u201con hold\u201d.<\/p>\n<p>Takealot was asked for feedback about the security flaws, but the company did not respond by the time of publication.<\/p>\n<p><strong>Raru\u00a0<\/strong>had a vulnerability reported on 22 July which was\u00a0patched on 24 July, and has already been publicly disclosed.\u00a0Raru director Neil Smith said they patched the issue on the day they were alerted to it.<\/p>\n<p>\u201cFrom a technical side, the vulnerability wasn\u2019t in the original site code, but introduced via changes we deployed later on,\u201d said Smith. He said\u00a0it\u00a0shows how important it is to test new code for security holes before deployment.<\/p>\n<p>Smith said their experience with XSSposed has been positive.<\/p>\n<p>\u201cIt helps alert website owners to potential problems on their sites. We also appreciate having enough time to close the vulnerabilities before the info goes public.\u201d<\/p>\n<p><strong>Zando<\/strong> said it fixed the vulnerability on its site within a day.<\/p>\n<p><strong>Makro<\/strong> digital executive Paul van de Waal said they recently updated their online store, which included\u00a0security enhancements, which may have resolved the vulnerabilities reported on XSSposed.<\/p>\n<p>The vulnerabilities on Makro\u2019s site were reported on 23 July, when Van de Waal said the previous version of their site was still online.<\/p>\n<p>\u201cUnfortunately, we have not had a chance to contact the researcher who submitted the requests so we cannot validate what issues were detected.&#8221;<\/p>\n<p>He added that the work Makro\u00a0does with its\u00a0third-party security consultants makes it\u00a0confident that there are no major\u00a0security flaws on its\u00a0site.<\/p>\n<h3 class=\"my-4\">News websites, Autotrader, and Cars.co.za<\/h3>\n<div id=\"attachment_131334\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/AutoTrader.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-131334\" class=\"size-full wp-image-131334\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/AutoTrader.jpg\" alt=\"AutoTrader\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/AutoTrader.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/07\/AutoTrader-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-131334\" class=\"wp-caption-text\">AutoTrader<\/p><\/div>\n<p>Other websites with reported vulnerabilities included those for Son, BusinessDay Live, Sunday World, Timeslive, The Daily Sun, and Eyewitness News.<\/p>\n<p>As with the e-commerce sites, many of the bugs have been patched already, while others are still on hold.<\/p>\n<p>Autotrader and Cars.co.za were also reported to have security flaws.\u00a0Asked for comment, <strong>Cars.co.za<\/strong> said it\u00a0has\u00a0implemented checks for XSS vulnerabilities.\u00a0<strong>AutoTrader<\/strong>\u00a0did not give comment by the time of publication.<\/p>\n<h3 class=\"my-4\">Standard Bank<\/h3>\n<div id=\"attachment_81513\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/07\/Standard-bank.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-81513\" class=\"size-full wp-image-81513\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/07\/Standard-bank.jpg\" alt=\"Standard bank\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/07\/Standard-bank.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/07\/Standard-bank-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-81513\" class=\"wp-caption-text\">Standard bank<\/p><\/div>\n<p>Of some concern is the XSS vulnerability reported on the website for Standard Bank, which is still listed as unpatched.<\/p>\n<p>The bank said it is aware of the issue and is deploying measures to mitigate any\u00a0risk.<\/p>\n<p>\u201cWe would like to emphasize that this is limited to the <strong><a href=\"http:\/\/www.standardbank.co.za\" target=\"_blank\">Standard Bank home<\/a><\/strong> page, which is essentially Standard Bank&#8217;s marketing interface,\u201d a spokesperson said.<\/p>\n<p>\u201cStandard Bank\u2019s Internet Banking portal is not impacted by this in any way. As such the integrity of our client information remains intact.&#8221;<\/p>\n<h3 class=\"my-4\">Eskom<\/h3>\n<div id=\"attachment_115377\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/12\/Eskom-broken-2.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-115377\" class=\"wp-image-115377 size-full\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/12\/Eskom-broken-2.png\" alt=\"Eskom broken\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/12\/Eskom-broken-2.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/12\/Eskom-broken-2-250x166.png 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-115377\" class=\"wp-caption-text\">Eskom<\/p><\/div>\n<p>Eskom\u2019s website was listed as vulnerable to XSS attacks on 14 September 2014, and according to reports it is still vulnerable.<\/p>\n<p>The utility was asked about the listed security problems with its website, but has not responded to requests for comment.<\/p>\n<p><strong>Update:<\/strong> Takealot has provided the following statement from its\u00a0Co-CEO and CTO\u00a0Willlem Van Biljon.<\/p>\n<blockquote><p>At Takealot we take the security of our website extremely seriously.\u00a0We have ongoing technology\u00a0processes in place to monitor and repair any security vulnerabilities identified by our team or the wider technology community.<\/p>\n<p>The security flaws reported on the website XSSposed\u00a0on the 14th and 27th of July have been fixed by our technology team and we continue\u00a0to take steps to improve the security of our website.<\/p>\n<p>We are very grateful to the developer community who help us to identify any security flaws and remain committed to provide a safe environment where our customers can enjoying shopping with us.<\/p><\/blockquote>\n<h3 id=\"related\">More information security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134820-cognition-holdings-responds-to-security-concerns.html\"><strong>Cognition Holdings responds to security concerns<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134544-heres-how-easy-it-is-for-criminals-to-break-into-your-car.html\"><strong>Here\u2019s how easy it is for criminals to break into your car<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134584-super-cellphone-spying-machine-in-sa-used-to-rig-government-tenders.html\"><strong>Super cellphone spying machine in SA used to rig government tenders<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/132665-175000-cheating-south-africans-may-be-exposed-in-ashley-madison-hack.html\"><strong>175,000 cheating South Africans may be exposed in Ashley Madison hack<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/131822-how-the-anc-sent-encrypted-messages-in-the-fight-against-apartheid.html\"><strong>How the ANC sent encrypted messages in the fight against apartheid<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A number of prominent South African websites are vulnerable to cross-site scripting attacks.<\/p>\n","protected":false},"author":15,"featured_media":104499,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[32118,8967,35,849,18506,25321,28294,995,32116,14835],"class_list":["post-134946","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cross-site-scripting-xss-attack","tag-game","tag-headline","tag-makro","tag-olx","tag-raru","tag-spree","tag-takealot","tag-xssposed","tag-zando"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134946"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=134946"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134946\/revisions"}],"predecessor-version":[{"id":135008,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134946\/revisions\/135008"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/104499"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=134946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=134946"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=134946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}