Subject: | Vital BUG in HDFC Net banking application |
Date: | Fri, 27 Apr 2018 11:00:00 +0000 |
To: | "bug-finance-bank-hdfc [...] rt.cpan.org" <bug-finance-bank-hdfc [...] rt.cpan.org> |
From: | "Odiveti, Maheswara Reddy" <MaheswaraReddy.Odiveti [...] ca.com> |
Hi HDFC,
I have found one major bug in the HDFC net banking application. Please go through the issue details.
BUG Title: After clicking on browser "forward" button without providing password, The HDFC net banking entry page is showed directly.
Steps to Reproduce:
1. Login into HDFC net-banking web application by providing User ID / Customer ID and IPIN (Password)
[cid:image002.png@01D3DE41.CB514DA0]
2. Now you will see the following screen
https://netbanking.hdfcbank.com/netbanking/entry
[cid:image005.jpg@01D3DE44.F8C1A8E0]
3. Now click on browser back button (highlighted in black color of above Image).
4. you will get the following screen (which is Login screen)
https://netbanking.hdfcbank.com/netbanking/
[cid:image007.jpg@01D3DE44.F8C1A8E0]
5. Now click on the browser forward button (highlighted in black color of above Image) without Providing the Password and other details.
6. Observe that the net-banking entry page is displayed.
User should not be allowed to go to entry page from login page directly without giving all the credentials.
This is a bug. Please reproduce the same and let us know about it.
Regards,
Mahesh