HomeInvestigations Greek researcher identified a weakness in the 2014 Elections site ekloges.ypes.gr! (+Upd)

[EXCLUSIVE] Greek researcher identified a weakness in the 2014 Elections site ekloges.ypes.gr! (+Upd)

ekloges.ypes_.gr_

The day of the local government elections, apart from the generally unexpected election results and the disaster of the exit polls, seems to be of particular interest from a system security perspective, and mainly with regard to the security of the official website for announcing the results, ekloges.ypes.gr.

[Update] Now the vulnerability has been fixed, clearly demonstrating the vigilance of those responsible even for a low-significance vulnerability. Wemust mention that the reaction was immediate (within a few minutes) from those in charge even for an XSS vulnerability that does not create a problem or data leak! Clearly, the protection system that has been built for the conduct of the elections demonstrated extremely fast reflexes, as it had done in the past with equal success, preventing hundreds of attacks!

According to EXCLUSIVE information shared with the SecNews editorial team, a Greek researcher identified security weaknesses on the Ministry of Interior 's results announcement website !

The information sent to the SecNews editorial team a few hours earlier by a Greek security researcher -whose details remain at the disposal of SecNews- reports the existence of XSS vulnerabilities, which can be used by external attackers to alter data in the user's browser.

As the researcher specifically states, someone with specialized knowledge can alter the content of the user's sessions. We attach the Screenshots - proof of the existence of the vulnerability, as they appear in the browser of the SecNews editor who successfully checked for the existence of the vulnerability according to the researcher's instructions.

The weaknesses indicated by the researcher are:

Allows the would-be attacker to insert a message into the user's session

ekloges.ypes.gr.1

 

Allows redirection of the user to a website of the attacker-hacker's choice (in our example google.com)

ekloges.ypes.gr.2

  • Race Condition (about 50% success rate according to the researcher) with changing the website title to blah

https://ekloges.ypes.gr/may2014/dn/public/index.html#window.addEventListener('load', function(){document.getElementById('ext-comp-1015').innerHTML='blah'})

As is known, XSS vulnerabilities   are low-risk and cannot directly lead to website corruption or server access, but they can be used indirectly to alter content at the user-session level. On websites of a specific category (such as E-shops, Search Engines or websites that allow user authentication) where  Phishing  can result in  visitor redirection , they must be taken seriously and repaired immediately.

The existence of this vulnerability is particularly important due to the nature of the website and the accuracy of the results that are required to be displayed to its users. Therefore, in this specific case, the XSS vulnerability is considered extremely important for the accuracy of the displayed data. As the researcher states

[box_info]

Surely someone with JavaScript knowledge can "play" with the content that appears in the user's session.

Achieving 100% of the tests is up to the person who will be involved and the knowledge they possess (since mine is relatively small in this particular subject).

[/box_info]

We believe that the administrators of the Ministry of Interior and the responsible administrators of the company Singular Logic , which manages the election results system, must immediately fix the weakness indicated by the researcher, at least until next Sunday, the day of the repeat elections and the European elections, for the reliable and unalterable display of data in the user's browser.

It is worth noting that the vulnerability in no way affects the results, the server or the transmission of the results. The only thing that can be affected is the display to the user in case he has been sent a SPAM Phishing message with the links mentioned above. XSS vulnerabilities are generally characterized by experts  as low-risk vulnerabilities.

 SecNews thanks the Greek security researcher for the timely and accurate information

[UPDATE1-15.20-19/5/2014] The vulnerability, according to newer information, is characterized as low importance. It does not create any problems in the server data, as clearly stated in the post and any issues that arise have already been resolved and taken into account during the design of the application.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS