A hacker with the nickname “Moe1” has identified a security vulnerability on the website of the South African National Roads Authority (www.sanral.co.za).
The vulnerability allows attackers to obtain the PIN to log into the e-Toll website, only if the attacker knows the user's name.
The hacker claimed that he sent an email that contained a confirmation page which is part of the registration process, where it includes the user's PIN number.
Hacker created a small command-line tool to exploit the vulnerability on the website. Anyone can retrieve the PIN number simply by passing the username to the tool.
The hacker also states that the vulnerability exposes sensitive information, such as ID numbers, vehicle license plate numbers, mailing addresses, and payment methods.

