Major Security Hole Found on the German Finance Agency's Website

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
The Chaos Computer Club (CCC) hacker collective has notified the German Federal Finance Agency (Bundesfinanzagentur) of a serious security hole present on its website for years.

The vulnerability allowed any user to modify the content of the website through a Web-based file manager that was left unprotected.

The German Finance Agency is a state owned financial services company responsible for managing federal debt, as well as issuing Federal securities.

By leveraging the security hole, attackers could have added their own transaction quotes and could have changed the destination of the site's "Internet banking" link.

It's unclear for how long the website was vulnerable, but the unsecured file manager was probably there for years.

More details - link
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top