Task #12968

Support #12933: [SCP ID :##6249##] : Mobile Pentest Remediation

[SCP ID :##6249##] : Mobile Pentest Remediation L1 Missing Function Level Access Control (MFLAC)

Added by Najmi Pasarudin over 2 years ago. Updated over 1 year ago.

Status:Internal TestingStart date:May 10, 2022
Priority:NormalDue date:
Assignee:Nurul Athira Abdul Rahim% Done:

90%

Category:-Spent time:-
Target version:-

Description

Issue: Restful allows Payment and eStatement without password login
Finding: Restful relies on mobile password login popup. LGMS can bypass the popup.
Solution: Add database mobile login status and check at every transaction
Test step:
  1. Access mobile application
  2. Enter login password
  3. Access Payment and Transfer
  4. Make Own account transfer
  5. Expected result, transfer status is successful/pending approval
  6. Repeat testing for Loan, Corporate Card, Third Party, Interbank, DuitNow, RENTAS, Bill Payment and Jompay
  7. Repeat testing for Android and IOS

L1_update20220718.png (22.7 KB) Najmi Pasarudin, July 18, 2022 16:42

L1_result20220718.png (16.4 KB) Najmi Pasarudin, July 18, 2022 16:42

fingerprint_bypasslogin_L6.jpg (32.8 KB) Rahmat Aina Nadia, March 29, 2023 15:01


Related issues

Related to BSN CDB Support - Task #12980: Pentest - L6 - Local Biometric Authentication Bypass Internal Testing May 10, 2022

History

#1 Updated by Najmi Pasarudin over 2 years ago

  • Description updated (diff)

#2 Updated by Najmi Pasarudin over 2 years ago

  • Subject changed from Mobile Pentest Remediation L1 Missing Function Level Access Control (MFLAC) to [SCP ID :##6249##] : Mobile Pentest Remediation L1 Missing Function Level Access Control (MFLAC)

#3 Updated by Najmi Pasarudin over 2 years ago

  • Status changed from New - Begin Life Cycle to Development / Work In Progress

#4 Updated by Najmi Pasarudin over 2 years ago

  • Description updated (diff)

#5 Updated by Najmi Pasarudin over 2 years ago

  • % Done changed from 0 to 50

#6 Updated by Najmi Pasarudin over 2 years ago

  • Status changed from Development / Work In Progress to Pending SIT Deployment
  • % Done changed from 50 to 90

#7 Updated by Najmi Pasarudin over 2 years ago

  • Status changed from Pending SIT Deployment to Finished Development

#8 Updated by Najmi Pasarudin over 2 years ago

  • Status changed from Finished Development to Internal Testing

#9 Updated by Najmi Pasarudin over 2 years ago

  • Assignee changed from Najmi Pasarudin to Nurul Syahirah Md Nawi

Test steps refer to Description

#10 Updated by Nurul Athira Abdul Rahim about 2 years ago

  • Status changed from Internal Testing to Development / Work In Progress
  • Assignee changed from Nurul Syahirah Md Nawi to Najmi Pasarudin

#11 Updated by Najmi Pasarudin about 2 years ago

  • Status changed from Development / Work In Progress to Internal Testing
  • Assignee changed from Najmi Pasarudin to Nurul Athira Abdul Rahim

Hi Athira,
Attached is response image,L1_result20220718.png.

Test steps for the attached error:
  1. Access mobile apk
  2. Login using fingerprint login
  3. Bypass login password page - requires Mobile Team help
  4. Access Own account transfer or any transaction module
  5. Expected result, get error "Please proceed to normal login."

#13 Updated by Nurul Athira Abdul Rahim over 1 year ago

  • Assignee changed from Nurul Athira Abdul Rahim to Rahmat Aina Nadia

Aina and felix o test this issue on local.

To provide another APK to test this item, seperate with other item.

#14 Updated by Rahmat Aina Nadia over 1 year ago

Hi Athira,

mobile has tested this scenario.
However, we didn't get the expected error "Please proceed to normal login."
We get "Service is currently Unavailable". Please refer to the image attached.

#15 Updated by Norhaidah Md Dasuki over 1 year ago

  • Tracker changed from Support to Task

Also available in: Atom PDF