Import
In this article we will present you with some real facts so that you can draw your own conclusions about how the Security of Information Systems and by extension Personal Data is taken seriously by the respective companies in Greece. We will list the actions that took place for over 3 years with the involvement of well-known public bodies as well as a specific IT company.
Actually, we consider that this whole incident constitutes a representative example of a situation whose protagonists could be a variable X, where you can (almost) put any well-known company you want.

This is a story that repeats itself and will keep repeating as long as it remains in obscurity and as long as private interest outweighs the public. We consider that it is time to make all events public, exactly as they happened, so that it becomes known how the “model” of Web Application Security works and finally, perhaps some responsible parties will become aware and fix their vulnerabilities!
Let's go then!
In January 2013 I received (through a colleague) a report about a security vulnerability in a web application that runs at many Greek universities and is responsible for managing student data. The report said there was a security hole (specifically SQL Injection) in the particular application developed by a certain company. In a study I conducted myself, I found that indeed there was a serious security problem in the application, through which someone could steal the entire database with all personal details of the students as well as anything else it contained.
Because in the past we had seen this “project” before (with other companies), our operations had to be very fine and careful, because you might suddenly be found by a protector, accused. On the other hand “side” could at any moment a perpetrator gain access to the specific data with… unpredictable and not at all pleasant results.
The next move was made 1 month later. I sent an informational email to the Cyber Crime Unit (ΥΔΗΕ) on February 10, 2013. We provide the exact email that was sent to the DHE, having (for obvious reasons) hidden the parts that mention the exact vulnerability…
…
We would like to report a problem we found in the grade display application (and not only) of the company Xxxxxxxxx AE, i.e., the company that built the grading system for most universities in the country.Dork to find which sites are vulnerable, enter into Google: “Design and Development: XXXXXXXX AE”
Problem Analysis
The problem appears on the XXXXXXX.asp page where the student must fill in 5 fields in order to be able to register for the service. We found that XXXXXXXXXXXXXXXXXX is vulnerable to blind SQL injection attacks and when someone presses submit then the XXXXXXXX.asp page is called and this one with the appropriate input can provide information for the entire database as someone can (without even using passwords) download the ENTIRE database locally. We did not try to see if it can change scores but we do not consider it unlikely that it could happen!Attack Tool
A successful attack can only be carried out through sqlmap.
Here is how to use it for a successful attack:1. Analysis and finding the weakness
python sqlmap.py –url=”https://xxxxxxxxxxxxxx” –data=”xxxxxx” -o -p xxxxxxxxxxxx2. Check if it supports executing system commands
python sqlmap.py –url=”https://xxxxxxxxxxxxxx” –data=”xxxxxx” -o -p xxxxxxxxxx3. Retrieve all passwords at SQL Server level
python sqlmap.py –url=”https://xxxxxxxxxxxxxx” –data=”xxxxxx” -o -p xxxxxxxxxxxxALSO:
4.1 Finding the database name:
python sqlmap.py –url=””https://xxxxxxxxxxxxxx” –data=”xxxxxx” -o -p xxxxxxxxxxxx4.2 Find all tables in the current database
python sqlmap.py –url=””https://xxxxxxxxxxxxxx” –data=”xxxxxx” -o -p xxxxxxxxxxxx4.3 How to download all data from a specific table of our choice
python sqlmap.py –url=””https://xxxxxxxxxxxxxx” –data=”xxxxxx” -o -p xxxxxxxxxx
PROOF OF CONCEPT
We are enclosing the log file from the test we did.
We kindly ask for your actions to notify the company that… created it!
Thank you very much for your help and time!!
I can say that the response of this specific service was immediate, and it even showed a particular interest in the report, which we did not expect, since we are not used to such prompt replies from public entities, especially when the matter does not directly fall within their area of responsibility.
Because, yes, prevention is not the job of the Police DIE, but of other agencies (let's not name names) that in the past had not demonstrated the corresponding... immediacy, in similar reports. In fact, we were called and had a meeting with the Police officials, having a very constructive discussion both about the current problem and more generally, specifically with the Director of the service, Lieutenant General Mr. Manolis Sfakianakis. I do not know if there are other agencies in Greece whose Director would call you because you mentioned a weakness to them, which in the end was not their problem. However, to avoid any misunderstanding, I would like to clarify that, personally, I do not bless ANYONE's beard, it is not my style but I do not have anything to gain either, I simply believe that good services should be highlighted by us citizens (at least). I mention this for another reason: To emphasize that in our similar reports, even to ministries, we received the famous civil servant response (even from ministers): “Oh! this is not our responsibility, it is that ministry’s” or the classic “Leave us your details and we will contact you”…
We therefore consider that the ΔΗΕ, took the appropriate actions by informing the specific company about the problem.
After some time, specifically in July 2014, we conducted another check to see if and to what extent this particular vulnerability had been fixed. Unfortunately, the results were negative: The vulnerability still existed. So, the next move was to send a full report with the full history to SecNews.gr. We quote an excerpt from the email, as we sent it to SecNews on Thursday, July 10, 2014.
Dear friends, good evening,
I would like to refer to an event that is a reference point for how it works and how important you consider the security of information systems in this country.
I will give you real facts and evidence that can only cause concern.
In January 2013, a report reached me (through a colleague) about a security gap in a web application that runs in many Greek Universities. The report was that there was a gap (vulnerability - specifically SQL Injection) in a specific application that a specific company had developed.
In a study that I later conducted, I found that there was indeed a security problem in the specific application which could even be considered a 0-day.
So, after the study I conducted, I sent an informative email to the Hellenic Public Security Agency on February 10, 2013. The response of this specific service, I can say, was immediate, calling me to their offices for further clarifications - explanations, which was done.
I also consider it a given that this service informed the relevant authorities about this particular weakness (even though it is not its main duty). For such things there are other services (CERT) etc., in my opinion completely… “deaf”!
Today, approximately 18 months after the first report, this problem unfortunately still exists!
I quote the email as I sent it to the Υ.Θ.Ε.…..
The response from the SecNews team (as we expected) was immediate, even publishing a corresponding alert. There was also communication with the specific company, stating exactly where the problem was located. The final report was never made public in the hope that the problem would eventually be fixed…
Today, November 2016 (4 years after the initial discovery of the vulnerability) the problem still persists…
We should mention that our study was not done in great depth, but enough so that we could extract all the data from the database. The problem is that the site of this particular company states that this particular application runs in 32 universities. We did not test whether this particular weakness exists in many or all of the mentioned universities. This is probably the job of a company that should undertake the Pen Test and not ours. As well as the job of this particular company is to finally correct its weaknesses!!
Below are two screenshots that show the database tables as well as some data that were extracted!

Data with personal details (First name, last name, phone, address, email, mobile, Tax ID, etc.) from the PERSONS table:

Questions instead of conclusions
I now come to some (I think) logical concerns – questions:
1. The Police certainly informed about the problem. Some saw it and thought they shouldn’t bother to “close” it?
2. The problem has been around for several years. It’s just a matter of time before some script-kiddie finds it and we have another young “hacker” hero (at best).
3. Perhaps this problem is already known to other groups (more silent) and have already exploited it. Don’t be “disturbed” by the fact that “tomorrow” we see somewhere in public view all the data of all the students along with their scores and underneath it some people like “Anonymous” or “Lulzsec” or “Happy Ladybugs”.
4. Also, don't be alarmed if we see a post on the DarkNet like this: "Would you like to correct your grade at the Polytechnic? Do you want to pass the course? For 200 euros, I'll do it for you! Send a message to SuperHacker@mail.thief.com"
I really don't understand what's actually happening in our country. Apparently my mind can't grasp it.
- Does anyone care who is in an administrative position or in a position that gives them the right to make decisions?
- Do the programmers not know how to fix the vulnerability?
- Are some CEOs protected by the fact that if someone officially publishes something, they will sue them for defamation of their company's reputation, and with this "fear", they stay quiet?
Unanswered questions…
