HomeRapidalertOutrageous: Agency calls on bank staff to declare their personal information via...

Outrageous: Agency calls on bank staff to declare their personal information via an insecure application!!

secunia-disclose-zero-day-vulnerability

In the last few hours, there have been reports via Twitterabout a PARTICULARLY insecure application provided by an insurance company/organization and inviting bank executives to use it to declare specific personal information! This is TAAPTPGA, supervised by the Ministry of Labor & Social Insurance!

fail.gov.gr.2

The details of the news are as follows: The BANKING STAFF SICKNESS FUND (https://www.taapt.gr/) recently issued an application regarding the registration/update of IBAN registry data as you can see on the following page [here]

fail.gov.gr.1

The management officials call bank personnel to download the said application in order to declare the IBAN registry details.

However, as Greek security researchers, who published their findings on Twitter, the application is frankly unacceptable and particularly dangerous in terms of the potential for exposing the personal data to be submitted.

The researchers found that:

  • The creators of the application use a backend Access database for entering data, without having taken any substantial security measures.
  • The way the application is built is extremely outdated and in no way matches the technological background of 2014!
  • Created .exe file (which is even detected by Antivirus as a virus(!)) that they invite every interested party to download onto their corporate computer!
  • The .exe file they distribute was studied by security researchers and it was found to establish a remote connection (RDP) to a server. Using reverse‑engineering techniques they identified both the username and the password that grant access to the server where users provide their credentials! (see related Screenshot)

fail.gov.3Security researchers at Twitter are asking fundamental questions such as (among other things) why a Web application was not created for this specific task to secure the data being submitted, and who they can contact to report the errors.

The data requested by the application from the insured of the banks and which MAY have been put at risk are:

1. Identity card number.

2. Tax Identification Number.

3. AMKA.

4. IBAN.

5. Date of birth.

6. Phone number.

 

Therefore, and according to reports on Twitter, it is clear that:

α) An external attacker can use the credentials that were discovered in the application, gain access to the server and retrieve both the data submitted by bank staff as well as potentially gain entry into the TAAPT network.

β) An external attacker can install malware on the server using the application's credentials, as well as perform defacement (in case the database server is the same as the web server)

γ) An external attacker can tamper with the application's .exe file with malware and spread it to terminal stations of bank officials!

The comments on Twitter are extremely critical (and naturally justified), calling on the responsible authority to issue a relevant announcement or to undertake a fix or redesign of the application. So far, no announcement has been made regarding the issue.

SecNews thanks the anonymous reader for sending the information and also the independent security researchers on Twitter for the details.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS