lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 9 Aug 2019 14:48:15 +0200
From: Tim Schughart <t.schughart@...sec-networks.com>
To: Poyo VL via Fulldisclosure <fulldisclosure@...lists.org>
Subject: [FD] Multiple banks - potential risk of an inconsequent client
	separation

Hello together, 

as many of you already know some german banks are sharing the same hoster. 

Via google dorking it is possible to determine some customers of one of those hosters (Fiducia & GAD IT AG). 

The hoster uses a GET parameter called „bankid“ to identify its customers. 

For example: 
https://mobilebanking.gad.de/inm/mobilgad////ptlweb/WebPortal? <https://mobilebanking.gad.de/inm/mobilgad////ptlweb/WebPortal?bankid=8008>bankid=8008 <https://mobilebanking.gad.de/inm/mobilgad////ptlweb/WebPortal?bankid=8008> 

With help of google dorking „inurl:WebPortal?bankid=„ it is possible to enumerate all banks which host their online banking service at Fiducia & GAD IT AG. 
We checked this via whois on the ip net ranges - where another mistake is done - net name „GAD“ in all whois records. 

Another indicator for a shared environment (at least some shared systems) is changing the banking id shown in the following example:
https://www.apobank.de/ptlweb/WebPortal?bankid=8008 <https://www.apobank.de/ptlweb/WebPortal?bankid=8008> 
changed to:
https://www.apobank.de/ptlweb/WebPortal?bankid=8007 <https://www.apobank.de/ptlweb/WebPortal?bankid=8007> 
redirects to https://www.vr.de/privatkunden.html <https://www.vr.de/privatkunden.html> 

In Germany and the EU it is given by law that you have to separate clients data because, e.g. EU-DSGVO. For banks especially BAFIN audits this, too.  

On the following link you’ll find a cleaned list of dork double results, where are around 85 banks are listed with their bankid. 
https://data.prosec-networks.com/d/7cf20ee4b17e44ccb402/?dl=1 <https://data.prosec-networks.com/d/7cf20ee4b17e44ccb402/?dl=1> 

In our oppinion the separation is not given properly, what do you guys think about this? 


Best regards / Mit freundlichen Grüßen 

Tim Schughart 
CEO / Geschäftsführer  

--
ProSec GmbH
Robert-Koch-Straße 1-9
56751 Polch 

Website: https://www.prosec-networks.com 
Phone: +49 (0)261 450 930 90

Sitz der Gesellschaft / company domiciled in: Polch
Registergericht / registry court: Amtsgericht Koblenz, HRB 26457
Geschäftsführer / chief executive: Tim Schughart
USt-IdNr./ VAT ID: DE321817516

“This E-Mail communication may contain CONFIDENTIAL, PRIVILEGED and/or LEGALLY PROTECTED information and is intended only for the named recipient(s). Any unauthorized use, dissemination, copying or forwarding is strictly prohibited. If you are not the intended recipient and have received this email communication in error, please notify the sender immediately, delete it and destroy all copies of this E-Mail.

“Diese E-Mail Mitteilung kann VERTRAULICHE, dem BERUFSGEHEIMNIS UNTERLIEGENDE und/oder RECHTLICH GESCHÜTZTE Informationen enthalten und ist ausschließlich für den/die genannten Adressaten bestimmt. Jede unbefugte Nutzung, Weitergabe, Vervielfältigung oder Versendung ist strengstens verboten. Sollten Sie nicht der angegebene Adressat sein und diese E-Mail Mitteilung irrtümlich erhalten haben, informieren Sie bitte sofort den Absender, löschen diese E-Mail und vernichten alle Kopien.

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Powered by blists - more mailing lists