Yeah, agents have access to control transactions thru web server. One of the ways you can reverse a transaction..

Sent from my iPhone

On Aug 3, 2009, at 6:06 PM, Peter Karunyu <pkarunyu@gmail.com> wrote:

I am sure that there are some uber evil black hats here in Kenya, but I will believe it when some Kenyan dude or dudette gets extradited to the US for hacking NSA, FBI or the DOD.

I wonder of what benefit hacking MPESA would have, apart from the street cred.

Why would they have a webserver? Kwani can one transact mpesa via HTTP?

On Mon, Aug 3, 2009 at 5:45 PM, Gichuki John Chuksjonia <chuksjonia@gmail.com> wrote:
The mpesa webserver still seems okey to me, though i have never tested it.

On 8/3/09, Joram Mwinamo <joram.mwinamo@gmail.com> wrote:
> However , another rumour has it that Kenyan financial systems have
> questionable security and those with programs developed locally have scripts
> to syphon unnoticable amounts of money from peoples accounts. i wont mention
> names...again,just rumours....
>
> On Mon, Aug 3, 2009 at 4:46 PM, pithon kamau <pitkag@gmail.com> wrote:
>
>> Rumours Rumours Rumours
>>
>>
>>
>> On Mon, Aug 3, 2009 at 12:37 PM, Stephen <ndungustephen@gmail.com> wrote:
>>
>>> Not true,, the shops were operational over whole weekend.. No complaints
>>> reported.
>>>
>>> Sent from my iPhone
>>>
>>> On Aug 3, 2009, at 11:34 AM, richard muteru <richardmuteru@gmail.com>
>>> wrote:
>>>
>>>  Hi skunks,
>>>>
>>>> Rumors are there that the MPESA system has been hacked...its been down
>>>> the whole weekend.
>>>>
>>>> _______________________________________________
>>>> Skunkworks mailing list
>>>> Skunkworks@lists.my.co.ke
>>>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
>>>> Other services @ http://my.co.ke
>>>> Other lists
>>>> -------------
>>>> Announce:
>>>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce
>>>> Science:  http://lists.my.co.ke/cgi-bin/mailman/listinfo/science
>>>> kazi:     http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
>>>>
>>> _______________________________________________
>>> Skunkworks mailing list
>>> Skunkworks@lists.my.co.ke
>>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
>>> Other services @ http://my.co.ke
>>> Other lists
>>> -------------
>>> Announce:
>>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce
>>> Science:  http://lists.my.co.ke/cgi-bin/mailman/listinfo/science
>>> kazi:     http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
>>>
>>
>>
>>
>> --
>> Pithon K. Kamau
>> Mobile: 0723 588705
>> Tel: +254 20 2039220
>> Website: www.pithonkamau.com
>> Website Design, Domain Registration, Website Hosting, Corporate Email
>> Solutions, Website Maintainance, Website Marketing, Logo Design and
>> Branding, Bulk SMS Solutions, Computer Hardware and Maintainance, Network
>> Design and Set Up.............
>>
>> "Love Your Neighbour as You Love Yourself"
>>
>> _______________________________________________
>> Skunkworks mailing list
>> Skunkworks@lists.my.co.ke
>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
>> Other services @ http://my.co.ke
>> Other lists
>> -------------
>> Announce:
>> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce
>> Science:  http://lists.my.co.ke/cgi-bin/mailman/listinfo/science
>> kazi:     http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general
>>
>
>
>
> --
> Sent from my Voice Recognition Watch©
> --------------------------------------------------------------------
> God is not an excuse for lack of discipline
> --------------------------------------------------------------------
> Our greatest fear is not that we are inadequate,but that we are powerful
> beyond measure.It is our light, not our darkness, that frightens us.There is
> nothing enlightened about shrinking so that other people won't feel insecure
> around you.As we let our own light shine, we consciously give other people
> permission to do the same.
> As we are liberated from our fear,our presence automatically liberates
> others.
>


--
--
Gichuki John Ndirangu, C.E.H , C.P.T.P, O.S.C.P
I.T Security Analyst and Penetration Tester
infosigmer@inbox.com

{FORUM}http://lists.my.co.ke/pipermail/security/
http://nspkenya.blogspot.com/
http://chuksjonia.blogspot.com/

_______________________________________________
Skunkworks mailing list
Skunkworks@lists.my.co.ke
http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
Other services @ http://my.co.ke
Other lists
-------------
Announce: http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks-announce
Science:  http://lists.my.co.ke/cgi-bin/mailman/listinfo/science
kazi:     http://lists.my.co.ke/cgi-bin/mailman/admin/kazi/general