WBS hoax email of concern to iBurst users

While I dont condone what they did, maybe they should have put us all on '9 Gig Packages' to hurt WBS.
 
If it were not such a serious flaw it would be extremely funny, but the fact that these guys/gals have managed to hack into the system and gain access to our personal details detracts somewhat from the laughability of it all.

What I want to know is how did this happen? Has it happened in the past? Why have we as subscribers to the service not been notified by WBS as to the flawed security? Why have WBS not issued a press release and last, but by no means least WTF are WBS going to do about it?

So far it seems that they have stuck their head in the sand (as is their usual reaction) and seem to be trying to avoid the issue.

This is an extremely serious situation and once again they have proven that they are unable to handle the fallout with regards their inefficiencies.

We want answers and we want them now, not in two weeks when someone else has hacked in, this time maliciously and with all intents and purposes of getting at our confidential details.

What are the legal implications of this?
 
Well done WBS

Okie dokie,

Fair is fair. We exposed them and now its time to give them their dues.

The URL that was exploited was http://oss.wbs.co.za. The screenshots that you saw were from that URL.

In all fairness, WBS has now secured this URL. WBS: This is something that should've been done from the start. However should this interface really be online? All you have now done is secured it using BASIC AUTH, and somebody somewhere down the line is going to hack it again. I assure you. Although it won't be us. This much you can be sure. Please take this information offline it is not safe.

Furthermore, I would just like to re-assure everyone that nobodies details and information was recorded. We have not and will not exploit this vulnerability.

WBS: PLEASE PLEASE take this as a warning. Ensure that when people entrust you with sensitive information you treat that information with the respect it deserves.
 
iBurst_goes_iBust said:
Fair is fair. We exposed them and now its time to give them their dues.

What dues are we meant to give them?

What they did was pure negligence and I would love to see an argument stand up in court from them should it be proven that someones banking details that were stolen from their site were to be used fraudulently. Just because they have now attempted to secure that portal does not detract from the fact that it should have been done in the first place!

Have people not learnt from all the fraud that abounds with regards internet related commerce and the like?

They must have known that if that specific portal was hosted in the public domain that someone would come across it and attempt to gain access. Unacceptable.
 
iBurst_goes_iBust said:
In all fairness, WBS has now secured this URL. WBS: This is something that should've been done from the start. However should this interface really be online? All you have now done is secured it using BASIC AUTH
And in the process locked everybody out of the support pages. Try accessing your usage or the bandwidth purchase pages. It looks like the whole section is locked behind the http auth. So now what?
 
I have noticed this as well. Solve one problem. Cause another one. The WBS way.
 
fergus said:
And in the process locked everybody out of the support pages. Try accessing your usage or the bandwidth purchase pages. It looks like the whole section is locked behind the http auth. So now what?
It is called a knee jerk reaction. They have obviously implemented the security patch across all areas of the site that they deem to be open to attack.

I would assume that, as they secure the site as it should have been done in the first place, that areas such as the helpdesk will be freed up as soon as they are certain that any hackers are unable to gain access through that section.

Bit too much of closing the barn door after the horse has bolted, but that seems to be the WBS way.
 
The USA recently passed a law that goes something like "If a company finds out their customers information has been exposed in any way they can avoid liability only if they promptly inform ALL their customers of the breach. If they dont and a customer brings a suite against the company, the company loses by default."

We NEED a law like that in ZA!

As more and more of our sensitive information is stored online it is critical that people take all possible steps to secure themselves. If you want to learn more about practical security is a beginner friendly manner I suggest you subscribe to this podcast: http://www.grc.com/securitynow.htm
 
Last edited:
rudids said:
Well now this is interesting, from work I could access this URL perfectly, from home I cant (Host Not Accessible). Are you trying to censor this little mess WBS?

http://www.flickr.com/photos/13287294@N00/

also cant see the URL... but a friend of mine on msn could see it and he is using adsl... interesting.

the below URL works for iburst users but only shows one of the photos... there are 32...

http://static.flickr.com/33/58900880_63316474a6.jpg?v=0

EDIT

if ibursters want the full bunch of pictures you can get them from
ftp.uunet.co.za/pub/incoming/ibust.rar

i somehow doubt wbs will block that URL :D anyways intersting events... and only wonder why the hackers didnt just
upgrade everyones accounts :D
 
Last edited:
Hell it's embarassing seeing my old company's logo on that admin system...
 
Top
Sign up to the MyBroadband newsletter
X