{"id":98620,"date":"2014-03-13T13:58:13","date_gmt":"2014-03-13T11:58:13","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=98620"},"modified":"2014-03-13T14:25:50","modified_gmt":"2014-03-13T12:25:50","slug":"new-e-toll-website-security-flaw-uncovered","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/98620-new-e-toll-website-security-flaw-uncovered.html","title":{"rendered":"New E-toll website security flaw uncovered"},"content":{"rendered":"<p>There is a vulnerability on the E-toll website that lets any registered user access anyone\u2019s outstanding balance, according to a report on ITWeb.<\/p>\n<p>The report said that exploiting the vulnerability is trivial, and indicated that all that is needed is an E-toll account and a modern browser with built-in developer tools.<\/p>\n<p>This is because the E-toll website billing page embeds the license number as a hidden field, which can easily be accessed and modified.<\/p>\n<p>Instead of preventing the user from querying the balance of a vehicle not registered to their account, the E-toll site reportedly returns the outstanding amount.<\/p>\n<p>It is not the first time an easy-to-exploit security flaw has been identified in the E-toll website.<\/p>\n<p>Earlier this year a security researcher who went by \u201cMoe1\u201d reported a vulnerability that made it possible to get the PIN of many registered E-toll users so long as their usernames were known.<\/p>\n<p>A hacker could then log into the victim\u2019s account and access that person\u2019s private details.<\/p>\n<p>At the time, Sanral\u2019s response to the disclosure of the security flaw in its website was to <a title=\"E-toll website flaw a cyber-attack: Sanral\" href=\"http:\/\/mybroadband.co.za\/news\/security\/94554-e-toll-website-flaw-a-cyber-attack-sanral.html\">threaten legal action<\/a> against Moe1.<\/p>\n<p>Prior to these security vulnerabilities being uncovered, MyBroadband reported that Sanral&#8217;s E-toll website allowed anyone to <a title=\"Check your outstanding e-toll bill online\" href=\"http:\/\/mybroadband.co.za\/news\/government\/93075-check-your-outstanding-e-toll-bill-online.html\">check the outstanding balance of any vehicle<\/a> that had passed under a gantry.<\/p>\n<p>Initially Sanral said that this was a service provided to E-road users, despite the fact that to access this &#8220;feature&#8221; users had to jump through hoops.<\/p>\n<p>The feature eventually disappeared from the E-toll website, but only after it was used to <a title=\"Obama\u2019s e-toll bill\" href=\"http:\/\/mybroadband.co.za\/news\/government\/93391-obamas-e-toll-bill.html\">track the E-toll bill of US President Barack Obama<\/a> during his visit to South Africa for the memorial service of former president Nelson Mandela.<\/p>\n<p>Sanral did not immediately respond to requests for comment on this story.<\/p>\n<h3 id=\"related\">More Sanral security articles<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94807-e-toll-security-hole-dont-shoot-the-messenger.html\"><strong>E-toll security hole: don\u2019t shoot the messenger<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94614-website-security-flaws-in-sa-shooting-the-messenger.html\"><strong>Website security flaws in SA \u2013 shooting the messenger<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94554-e-toll-website-flaw-a-cyber-attack-sanral.html\"><strong>E-toll website flaw a cyber-attack: Sanral<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94446-massive-e-toll-website-security-flaw.html\"><strong>Massive E-toll website security flaw<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Another security flaw has been uncovered on Sanral\u2019s E-toll website that lets a \u201chacker\u201d see the outstanding balance on any vehicle<\/p>\n","protected":false},"author":23,"featured_media":94560,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[6525,35,437,23072],"class_list":["post-98620","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-e-toll","tag-headline","tag-privacy","tag-south-african-national-roads-agency-limited-sanral"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/98620"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=98620"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/98620\/revisions"}],"predecessor-version":[{"id":98624,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/98620\/revisions\/98624"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/94560"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=98620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=98620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=98620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}