{"id":96127,"date":"2014-02-04T11:16:29","date_gmt":"2014-02-04T09:16:29","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=96127"},"modified":"2014-02-05T12:25:49","modified_gmt":"2014-02-05T10:25:49","slug":"mweb-website-security-flaw","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/96127-mweb-website-security-flaw.html","title":{"rendered":"MWEB website security flaw"},"content":{"rendered":"<p>The online invoicing system on Mweb\u2019s website contained a vulnerability that let users that were logged into the system view another person\u2019s invoices, CEO of Mweb ISP Derek Hershaw has confirmed.<\/p>\n<p>A reader contacted MyBroadband about the security flaw at 20:00 on Monday, 3 February 2014 and the details of the vulnerability were sent on to Mweb shortly thereafter.<\/p>\n<p>Hershaw said that the vendor from which they license the system, who he did not name, fixed the issue just after 23:00.<\/p>\n<p>Similar to the security flaws discovered in the Mogale City and City of Johannesburg e-billing systems, users logged into their Mweb accounts that were viewing a PDF invoice could change the invoice number in the URL bar to view another subscriber\u2019s bill.<\/p>\n<p>This potentially exposed details such as contact details, Mweb user-names, and billing addresses.<\/p>\n<p>Hershaw said that the user who reported the flaw was able to see the invoices of other customers, but nothing more than that.<\/p>\n<p>\u201cHe actually accessed 4 other customers invoices and we will contact them during the course of this morning to explain what happened and apologise,\u201d Hershaw said.<\/p>\n<h3 id=\"related\">More SA website security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94883-another-e-billing-security-flaw.html\"><strong>Another e-billing security flaw<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94614-website-security-flaws-in-sa-shooting-the-messenger.html\"><strong>Website security flaws in SA \u2013 shooting the messenger<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94554-e-toll-website-flaw-a-cyber-attack-sanral.html\"><strong>E-toll website flaw a cyber-attack: Sanral<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94332-big-cell-c-security-flaw-uncovered.html\"><strong>Big Cell C security flaw uncovered<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94234-my-vodacom-security-flaw-exposes-subscriber-details.html\"><strong>My Vodacom security flaw exposes subscriber details<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A vulnerability in the MWEB online bill viewing system let subscribers see one another\u2019s invoices, and has been fixed<\/p>\n","protected":false},"author":15,"featured_media":74086,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[559,23505,35,213,437],"class_list":["post-96127","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-derek-hershaw","tag-flaw","tag-headline","tag-mweb","tag-privacy"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/96127"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=96127"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/96127\/revisions"}],"predecessor-version":[{"id":96131,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/96127\/revisions\/96131"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/74086"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=96127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=96127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=96127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}