Site navigation

Security Exploit Found on Official HMRC Site

Andrew Hamilton

,

HMRC Blockchain

One of the flaws even allowed potential attackers to view or modify tax and information records belonging to Britons.

An experienced IT researcher has reported that he detected two security flaws on an official UK tax website, only to be rebuffed by authorities when he raised the alarm. In a detailed blog post, the analyst – who goes by the moniker Zemnmez – described how he unearthed two exploitable quirks on the site when attempting to look at his own taxes. The bugs, belonging to the HM Revenue & Customs site, have since been squashed according to the National Cyber Security Centre – but this isn’t to say that Zemnmez’s journey doesn’t make for some worrying reading.

Exploitable weaknesses

The first of the two exploits that he found could be used to harvest personal information and tax details from unwitting victims. Zemnmez claims that by abusing how the HMRC login page interacts with your browser, he could theoretically redirect visitors to a phoney site masquerading as the real thing.  There, more vulnerable users would be none-the-wiser as they entered their personal information or tax details. To catch more in his theoretical web, he speculated further that a phishing email could be used to attract more potential victims to the original, and then his website.

He said: “Imagine you’re a normal person right now. You get an email from Her Majesty’s Revenue and Customs that threatens to send the internet police if you don’t file an emergency tax form and there’s a link that goes to the tax service — you fill in the form with your ID and such, go through to the tax form, fill that in. Now I have your tax details.”

After detecting the weakness, Zemnmez claims that he attempted to email and write to HMRC and the NCSC through Twitter, to avail. After this failed, he decided to delve further. After experimenting with the site’s javascript coding – which according to Zemnmez is used to create a significant amount of the code on the HMRC website – he found that he could potentially read and edit his victim’s tax records by extending the same redirect exploit he initially tried.

He said: “Once loaded (perhaps from a click on a link in an email), this [manipulated page] will ask the user to login to their UK tax account, and then redirect them to the vulnerable page and tell them how much they earn. We can push buttons, fill in forms and make other changes to the user’s tax status. This bypasses all the heuristic checks I’ve seen HMRC employ as we’re operating on the victim’s device.”

Zemnmez noted that such an attack had the potential to be extremely effective if deployed successfully. He said: “…the set of people on whom you might use a sharp, well-honed spearphishing attack armed with a vulnerability that extracts and manipulates financial information directly doesn’t usually include industry professionals and the excessively paranoid. We live in a world where the highest-earning mode of internet fraud (to the tune of $2.3B just in the US) is simply emailing financial officers asking them to make a wire transfer of big $$$ to our bank account which is registered conveniently to a bank in the middle of a volcano dimension that has no extradition treaty to NATO states.”

Delays in reporting

But Zemnmez’s blog post captures only the first three days of what he brandishes a ’57 day trek’ in attempting to report the issues to the relevant authorities. He reports that after his initial attempts via email were automatically deflected by official mail delivery systems, he found a website for reporting vulnerabilities on public sector systems. However, Zemnmez claims that this group is reserved for ‘invited UK-based security practitioners’, which he and many others are not privy to. He notes he also tried to reach out to Gov.UK, the NCSC and HMRC Customer Help via Twitter, to no avail.

Zemnmez claims that only after making a contact in the HMRC Press Office was he successfully able to pass on the vulnerability to the department. Even more striking is his claim that an anonymous friend, already tied to the NCSC, was required to notify them of the exploit. From his initial reporting on the 19th April, Zemnmez notes that 57 days passed before he was assured from the NCSC that the vulnerability was fixed.

He said: “Those 57 days represent the largest river I had to ford, a hurdle I had to personally push myself to jump in order to achieve the simple state of knowing the serious issues I identified were known and in good hands.

“There’s a weight to finding issues and caring about them, a moral load that, as a security researcher you have to carry until the issues are fixed. Sometimes you have to fight people to care, sometimes you have to fight to find people to fight to care.

“The security issues I found were complex. The issues that made fixing them take 57 days are simple, and common. Good security is an invisible luxury most places can’t afford. Security teams are expensive and hard to measure success for.”

Andrew Hamilton

Andrew Hamilton

PR & Content Executive at Hutchinson Networks

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data