The article was originally published by The Star at : https://www.thestar.com.my/tech/tech-news/2019/10/17/kpdnhep-suspends-petrol-subsidy-programme-microsite-which-exposed-users-bank-account-details#40WxojjWKRRdZChj.99
Update: The Ministry says the security flaw has been fixed and the Petrol Subsidy Programme microsite is now back online.
The Domestic Trade and Consumer Affairs Ministry (KPDNHEP) has suspended the newly-launched Petrol Subsidy Programme microsite after a tech portal reported that it exposed users’ bank account details.
The Ministry’s head of corporate communication, Yunus Tasim, said the ministry is aware and investigating the issue.
“Once we got the news, we decided to put the website on hold because we don’t want to risk anything. We don’t want users to be sceptical about our system,” he said.
He added that once the issue is rectified, the ministry will restore the system.
Lowyat had reported that once a person’s MyKad number is entered in the portal, it will reveal the last four digits of the user’s bank account number.
However, when it looked into the source code, the full account number was visible.
Yunus said the ministry will be in touch with Lowyat for more information.
“We would like to thank all the users for their patience and feedback given to us,” he said.
Cybersecurity company LGMS director Fong Choong Fook said the security flaw is mostly likely due to the ministry rushing to launch the microsite.
The Petrol Subsidy Programme microsite, which went live on Oct 15, is for users to find out if they are eligible for petrol subsidy, as announced in Budget 2020.
“The bigger concern now is if someone can use the website as a tool to phish out information, just imagine what that person can do with the details,” Fong said.
“They could impersonate a bank officer and call a victim for extortion. A lot of exploitation can be done here.”
Dr Aswami Fadillah Mohd Ariffin, president of Protem Digital Forensics Research Society (DFRS), said web-based development should go through security auditing at the staging level before production to avoid any security issues when the site goes online.
He said that the website developer must ensure secure coding and infrastructure design are followed before giving the go ahead for the launch.
Once the ministry rectifies the issue and rechecks again, it can give users access to the website, he added.
Fong said the issue can be rectified with a “quick fix on the coding side”.
For more, follow us on
LGMS YouTube Channel : LGMS Penetration Testing Expert (LE Global Services)
LGMS Facebook Page: lgms.global
LGMS Linkedin Page : lgms-global
LGMS Instagram ID : lgms.global
您 可 以 通 过 以 下 链 接 找 到 其 他 有 趣 的 LGMS 新 闻：
- Ministry suspends Petrol Subsidy Programme microsite which exposed users’ bank account details
- Almost 200% increase in data breach attacks since 2018
- Imagine Fake Video With Defence Minister Declaring War! Analysts Warn Deepfakes Could Create Chaos
- ONFM – 免费APP不止盗取个人资料，连钱也可以“盗取“？
- AIFM 名师早点 – 资料外泄和诈骗