Improve Bank cyber security cybersecurity

Improve Bank cyber security

Financial services
Improve Bank cyber security
Location USA
Branch Financial services
Technologies
PT Security Sniff
Solution
Testing
Terms
3 months full complete

Guardians of the digital world

An international commercial bank with total assets of USD 500 million applied to our team of cybersecurity experts. The bank offers a full range of banking services to private and corporate clients. The team was tasked with assessing the current level of security of web and mobile banking applications for a commercial bank in Europe. Although the scope of work was limited to a black box perspective and assumed an external attack scenario where the attacker only knows the customer's name, we were able to exploit application abnormalities, gain access to critical data, gain full access to the bank's customer accounts, and withdraw money as the ultimate goal.

WHAT WAS DONE

TESTING STAGES

Reconnaissance:

It took us a week to study the client’s systems. We gathered information about the software, OS, browsers, antiviruses, email clients, etc. used by employees. We also focused on the email format and other elements of corporate identity, news and events in the company – everything that could make the email, phishing site, and targeted attack credible.

STAGES OF THE TEST

To conduct high-quality comprehensive testing, we used both manual and automated testing tools and techniques.

OTP compromise:

  • During the testing, we found that access to the account via online banking is protected by two-factor authentication using an OTP code. We were able to find a critical vulnerability in the OTP, which allowed us to capture it using a brute force attack (password guessing attack on the login page). In addition, OTP verification was also used for financial or any other asset transactions. Provided that the attacker knew the user’s credentials, he could access any bank account and make an unwanted money transfer, which would completely compromise the security system.

The same OTP vulnerability was confirmed in the mobile application, although a different server was used to process requests, and the web and mobile application APIs were supposed to function separately. Thus, the mobile application contained the same flaw in the session management logic, and the security risk was correspondingly higher.

Authentication compromise:

  • Another critical vulnerability was discovered when authorizing access to user data. By logging into the online banking system and changing the user’s identification token, the hacker could see private data of other bank customers, including their transactions and account balances. Thus, it was possible to select accounts with the desired balances and then – using an automatically generated script – pick up credentials, log in to the victims’ accounts, pick up OTPs, and withdraw money.

Hacking scenario:

  • Gaining full access. A vulnerability in the authentication process allowed access to any user account in the system. The attacker could easily check the account balance, select the desired accounts, pick up the necessary data, and initiate unwanted transactions by exploiting the OTP vulnerability.

RESULT

We conducted a series of tests to analyze the security of the bank’s web and mobile applications. The tests revealed several types of vulnerabilities classified according to the risk levels defined by the OWASP methodology. The combination of two critical vulnerabilities allowed our team to conduct any transaction from the bank’s customers’ accounts without proper authentication.

To help the bank address the identified security gaps, we prepared a comprehensive report covering all the vulnerabilities identified and provided remediation recommendations that were implemented during the remediation phase.

Chat with manager
petani jawa tengah menang 129 juta di poker abc1131mix parlay sensasional abc1131 menang 214 jutamahjong ways abc1131 rahasia kemenangan profesionalgame koi gatemengungkap rahasia maxwin di mahjong wins 3 tips lengkap untuk mendapatkan scatter naga hitamgame naga mahjongmetode jitu kalahkan agen game mahjong dengan robopragma prediksi pola maxwingame modal recehmega spin satu putaran mahjong winsputaran liar situs mpoxokeberuntungan membara mahjong wins 3harta karun kejutan mahjong ways 2jackpot meledak setiap detik di starlight princess 1000xmega spin cuan beruntungame gachor dengan rezeki menggelegarjackpot menggoda dan penuh warna mahjong wins 3best game pragmatic bikin kaya mendadakbonus hadiah tanpa henti mahjong ways 2putaran sakti lucky neko yang mengguncangrezeki berputar di mahjong wins 3 siap guyur dompetmurahasia besar pg soft berikan wdbadai jackpot 500x gates of olympuspeluang emas mahjong ways dengan bonus gila gilaanmember baru abc1131 profit maksimal dengan rtp livepola scatter x5000 tiger fortune abc1131 maxwin cepatsweet bonanza abc1131 spin modal receh auto sultanmahjong ways 3 abc1131 fitur rahasia kemenanganspeed blackjack abc1131 teknik membaca gerakan lawangatot kaca dice abc1131 jackpot 550 juta viralphoenix rises abc1131 rtp tinggi spin cuannyastrategi poker abc1131 mengelola risiko dan profitelik joker legenda turnamen poker abc1131mahjong ways 2 abc1131 maxwin satu layar 1 miliarpola game anti rungkadpola baru banjir scatter mahjong ways 2bocoran pola curang buat menang main game online hari inipola gacor game maxwinpola gacor mahjong wayspola game gacor mahjong wins 3pola gacor mochimonpola gacor lucky nekopola gacor mahjong winspola gacor olympuspola gacor game princesspola gacor sweet bonanzapola gacor sweet bonanza xmasstrategi pro untuk menggunakan pola gacor wild banditobocoran pola gacor zeus gate of olympus x500putaran sakral mahjong wins 3cuan spektakuler mahjong ways 2 untuk pemberanijackpot kilat full wild dalam fsbonus dan hadiah spesial mpoxoakun vip hadiah cuanputaran magis sugar rush 1000xpola jackpot gacor kapten76hoki di setiap putaran mahjong wins 3 jackpot penuh warna mahjong ways 2scatter gates of olympus sapu bersih jackpotgerbang kekayaan gates of olympusbadai jackpot di mahjong waysbonus tiada henti dan cuan melimpah kapten76jackpot liar mahjong wins kapten76puncak kemenangan pyramid bonanza kapten76dari pemula jadi profesional langkah mudah menuju maxwin tanpa ribetrahasia mahjong ways 2 apa sih scatter hitam itu dan kenapa bisa meledak keberuntunganpola rahasia atau kebetulan bagaimana mahjong ways mengundang keberuntunganstrategi terbaru gates of olympus apa yang memisahkan pecundang dari pemenangnyagacor terus 7 strategi baru pgsoft mahjong ways cipta jackpot kilatscatter gates of olympus abc1131 hadiah 450 jutamantan pekerja pabrik sukses dengan gates of olympusstrategi parlay abc1131 menang akurasi lebih tinggiwild berjajar abc1131 free spin buffalo king megawaysjackpot lucky neko abc1131 pola baru kemenanganpemuda jakarta rekor win streak mahjong ways 3 abc1131sweet bonanza candyland abc1131 jackpot live casinowild coaster abc1131 game rtp super gacor jackpotpola starlight princess abc1131 teknik viral maxwinwild bandito dice abc1131 scatter dan free spinABC1131: Situs SLOT DANA & SLOT MPO Terpercaya, Gampang Jackpot!0827 mahjong ways 2 agen profit scatter hitam kejutan besar0828 pola spin treasures of aztec agen profit jackpot0829 sugar rush agen profit teknik spin scatter gratis0830 gates of olympus x1000 agen profit rtp meningkat0831 banjir jackpot maret aws profit member happygame mahjongpola game online gacorpola game koi gatemahjong waysmpoxopemuda asal jakarta berhasil membuat analisis pola game sugar rush 1000 mengungkap potensi maxwin besargame gatot kaca x500prediksi terakurat untuk game starlight princess x1000starlight christmas pragmatic playrahasia 5 shio keberuntungan dalam game mahjong winsbaru mahjong ways 2rahasia trik jackpot akun baru di gates of olympus 1000 bet 2000 perakakun pro thailandgame sweet bonanzaupdate pola terbaru pg softmahjong ways 2rtp live gacorrtp tertinggi game pragmatic awal tahun 2025 spesial ramadhan admin chulo bagi bagi thrciri rtp game online yang update hari inibocoran rtp live pg soft terbaikgame pragmatic playrtp game tertinggi dari server luar negerirtp live tertinggirtp game tinggi1850 mahjong terbangkanlah1855 mahjong teknik sakral1851 mahjong perang santuy1856 mahjong kumpul keboheylink macauklubheylink asiaklubheylink hksbetheylink kapten76heylink mpoxoheylink garuda76garuda76asiaklubmacauklubasiawin189 1asiawin189 2asiawin189 3asiawin189 4asiawin189 5rawit303amp rawit303mpoxl