Share

E toll website giving away your personal info

How to hack the site... Thank god i did not register.

Found this on a forum:
 http://mybroadband.co.za/vb/showthread.php/585998-SANRAL-E-TOLL-WEBSITE-VULNERABILITY?p=11839992


Original article taken from http://tny.cz/ef11db01

------------------------------------------------
SANRAL E-TOLL WEBSITE VULNERABILITY
------------------------------------------------
By Moe1
------------------------------------------------
SECURITY ADVISORY
------------------------
DOCUMENT ID: v1.0
--------------------------
RISK LEVEL : CRITICAL
--------------------------

DISCLAIMER
--------------
The information provided in this document is for educational purposes only. The author is in no way responsible for any misuse of the information. The author insists that such information should never be used for malicious purposes.

INTRODUCTION
------------------
The SANRAL e-Tolls website allows users to register their e-tags online and provides a service where by customers can monitor, pay and track their e-toll accounts. The website contains sensitive customer information such as ID numbers, car number plates, postal addresses, payment methods etc. therefore it is crucial that SANRAL ensure it is secured and user data is protected. The purpose of this report is to display the false sense of security the website portrays by highlighting a simple vulnerability which exist due to a lack of basic web application security logic.

OVERVIEW
------------
When a user registers on the website for the first time the account is put into a “pre-registration” state. The account will remain in a “pre-registration” state until the user confirms the account by clicking on a link provided in a confirmation email. This “pre-registration” confirmation link contains a serious security problem where by it provides the users pin number on the confirmation screen. Using this link an attacker can inject another username into it which would result in the confirmation page containing the pin number of another user.

VULNERABILITY DEMO – HACK AN E-TOLL ACCOUNT IN 5 SECONDS
----------------------------------------------------------------------------

1. Browse to the SANRAL e-toll login page. https://www.sanral.co.za/e-toll/portal/default.aspx
2. Okay so you have the USERNAME and the VERIFICATION CODE that is provided. To get the users PIN all you need to do is browse to the “pre-registration” confirmation link and specify the USERNAME.

http://www.sanral.co.za/e-toll/porta...me=jasonbourne
(Notice the pin of that users account is provided! To view it in clear-text simply view the pages source)

3. Now that you have the pin go back to the login screen, enter username, pin and verification code provided.
4. And there you have it an e-toll account hacked in 5 seconds!

PROOF OF CONCEPT EXPLOIT
---------------------------------
http://tinyurl.com/melw4nw

VIDEO DEMO
---------------
https://www.youtube.com/watch?v=cacn2vRWzF8

CONCLUSION
---------------
It is great that SANRAL informs you to keep your pin safe in their “Terms and conditions” but it’s not very great that they give out your pin to anyone that basically requests for it.

-EOF-
We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Voting Booth
Should the Proteas pick Faf du Plessis for the T20 World Cup in West Indies and the United States in June?
Please select an option Oops! Something went wrong, please try again later.
Results
Yes! Faf still has a lot to give ...
65% - 391 votes
No! It's time to move on ...
35% - 214 votes
Vote
Rand - Dollar
19.04
+0.9%
Rand - Pound
23.78
+0.7%
Rand - Euro
20.40
+0.7%
Rand - Aus dollar
12.39
+0.8%
Rand - Yen
0.12
+1.1%
Platinum
917.50
+0.6%
Palladium
985.50
-1.9%
Gold
2,341.77
+1.1%
Silver
27.52
+1.3%
Brent Crude
88.02
-0.5%
Top 40
68,332
-0.4%
All Share
74,172
-0.5%
Resource 10
62,213
+2.9%
Industrial 25
102,238
-1.7%
Financial 15
15,772
-0.4%
All JSE data delayed by at least 15 minutes Iress logo
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE