AD police have done us a great favor by making it possible to check out our speeding tickets online. In fact they were nice enough to upload your cars picture on their website. You only had to input some information that identifies you as the owner, usually found on your Vehicle License and your in.
You might think now everything is safe, the website asks for information that nobody can fake. Well that's true, but the truth is that EVERYBODY HAS ACCESS TO YOUR SPEEDING RADAR PICTURE.
here is a demonstration of random cars I just came across
Car Number 1\Car Number 2\Car Number 3\Car Number 4\ Car Number 5
surprised? well things are just starting. A 10 year old can easily maneuver around the weak even nonexistent security barriers that SHOULD stop a random net surfer from accessing those pictures.
The people who are in charge of this website and its databases need some simple common sense put into them. What they fail to do is make this picture part of your Vehicle License number that you have to input to check on your tickets, sadly their attempt was only to provide a link to your car's picture which they normally uploaded on their website so a simple change done on the URL of the picture can link you to the whole radar pictures database.
Even though our Government attempt in joining the world wide web was fruitful. Their system needs some security improvements. Or did they think that we locals are idiot enough to figure this Out?
I say go get some good programmers....
Sunday, February 11, 2007
Subscribe to:
Post Comments (Atom)
8 comments:
ADinamorato Is this about you!?? ☆★☆
why everyone makes such big deal on speeding tickets !!!???? i didnt recive one in two years
just drive within speed limits and depend on your experiance of these speed cameras location.....
anyways traffic is everywhere so there is no point of speeding up.!!!
and for the programe, why u guys care about other people tickets !!!! or just curious to show how we are smart by showing off our computer talents!!!
this is made to help us to see how much we have to pay unless u wanna pay for other people!!
It seems you did not get it. Their security is nonexistent. I am not showing my computer talents or anything. I am only showing how stupid the programmers our government hired.
I really dont care bout seeing other peoples pictures.What they have right now is a scrwed up system for showing radar pictures. And thats not the right way to do it. It was not built to make pictures be accessible by everyone a9lan, but due to inexperienced people it turned to be like this.
I even pointed out the mistake itself and talked about the right way of fixing it.
So never think of it as a show off topic :)
Wonderful investigative work, Mr. undercover CID!
I can't find the link to access fines section on the website. I say they should get some decent web developers too.
Look at these snippets from the most recent article:
"53 tickets were issued...for driving in wrong direction."
Whoops, 53 4wds chasing girls again?!
"45 pedestrians were also fined for violating various rod regulations."
What is a rod regulation? I'd be interested to know.
Great topic and a definite breach of security and privacy. Frankly, I have accumulated AED 2600 in various parking and speeding fines this past year and I am NOT looking forward to paying them. But if my information is easily accessible to the general masses now I would think twice about even wanting to get on this website!
You figure with the amount of money they make from violators like myself, they can definitely hire more competent programmers!!!
interesting blog btw
Post a Comment