The majority of e-banking applications are vulnerable to password cracking!

e-bankingOur friends from SecNews.gr published the results of a very interesting survey on e-banking applications carried out by the University of Piraeus. We present the publication.

A new survey of him Safety Systems Laboratory of University of Piraeus recently saw the light of day. Carrying out a series of experiments, the University researchers concluded that the majority of e-banking applications of Greek banks are vulnerable to password interception by local networks. The aim of the research was to evaluate the ability of e-banking applications of Greek banks to deal effectively with sslstrip type attacks.

Discover more articles in search results.

The experiments were carried out by his postgraduate students Department of Digital Systems of the University of Piraeus: Chr. Lyvas, F. Lalagiannis, G. Kontogiannis, G. Valtas, Sp. Mantzouratos and St. Mindylas, under the direction of Mr. Christos Xenakis, assistant professor at the University of Piraeus and Mr. Christopher Dadoyian, researcher and instructor at the University of Piraeus.

It is worth noting that both the competent management of the Bank of Greece and the National CERT were informed in a timely manner about the results of the investigation.

e-banking

Introduction

In this report we present the results of our research on the capability of applications e-banking of Greek banks to deal effectively with press attacks sslstrip. Specifically, we studied six Greek banks: Alpha Bank, National Bank of Greece (NBG group), Piraeus Bank, Eurobank, Citibank and Bank of Chania. The general conclusion is that the majority of applications e-banking of Greek banks are vulnerable to interleaving passwords (username, password, disposable password - token, etc) from local networks (eg, corporate networks, internet cafes - restaurants, hotels, university networks, school networks, airports, stations, ports, etc.). Therefore, it is necessary to take specific security measures from the managers of these applications in order to upgrade the level of security they provide in order to adequately protect their users.

The attack sslstrip and the consequences

The application was used to conduct the survey sslstrip in wired and wireless local networks, implementing the man-in-the-middle attack.

In particular, the intermediate-malicious executing it sslstrip acts as an intermediary in the communication between the victim-user and the e-banking application server.

Under normal circumstances, this communication should always be, encrypted using the protocol HTTPs. However, the malicious user, on the same local network as the user-user, has the ability to force the user, without realizing it, to contact the banking application server e-banking via unencrypted connection, using the protocol HTTP. This is possible because most users start a connection with an e-banking application by typing in their browser only the domain name of the bank (eg, eurobank.gr), without entering the communication protocol , thus using the standard protocol HTTP. Then, after the user chooses the option e-banking, the app has the ability to upgrade complete videos connecting from unsafe on safe using the protocolHTTPs. At this point, the intermediate-malicious intervenes and maintains it unsafe connection and its unsafe protocol HTTP.

ssl-security

 The only indication for the user to understand the presence of the intermediate-malicious and the execution of the attack is to observe that  URL  which appears in the browser starts with http:// and not with me https://. If the user does not see the above and continue navigating by entering sensitive data, such as username, password, one-time password, etc., to connect to the application, c intermediate-malicious is able to intercept the above on the local network as it is transmitted unencrypted. The consequences of such an interception are the breach of banking secrecy and the ability to execute unauthorized banking transactions.

Results

Four popular operating systems (Windows, OS X, android OS and iOS) with the latest versions of known browsers chrome, firefox, and safari. The analysis of the results is summarized in the table below. It is clear that the majority of applications e-banking of Greek banks are vulnerable to interception of passwords by local networks. Unique the exception is the implementation of the National Bank of Greece, which has a protection mechanism.

e-banking

It was also found that in all the applications examined, encryption (HTTPs) is enabled on the password entry page (Login page) and not on the home page of each bank. Finally, all applications use the SSL 3.0 / TLS 1.0 protocol for encryption, which have been discovered several weaknesses.

The SecNews view

SecNews as a strong supporter Full / Partial detail disclosure regarding weaknesses in software, welcomes the research of the University of Piraeus. In each case the DIRECT update of the weaknesses from the University of Piraeus to financial institutions and the Bank of Greece, can only be evaluated ONLY positively since it contributes to the strengthening of infrastructure security in the context of their research work.

It is worth mentioning that most of the time the weaknesses are not due to omissions of the Banks regarding the security measures they observe. The problems that the study mainly mentions focus on the creators of the applications or on third-party commercial (or custom-made) applications which comprise specific modules or parts of the ebanking applications.

Proposed measures

Concluding the research, a series of measures are proposed that should be implemented immediately by banks, in order to strengthen the level of security provided by e-banking applications, protecting their users from malicious actions.

1. Use of the rule HSTS (HTTP Strict Transport Security), which forces all browsers to use it only protocol HTTPs. So any attempt to connect to an application e-banking to protocol HTTP will be automatically upgraded to HTTPs.

2. Use the latest version of the protocol TLS (i.e. the TLS v1.2), which provides powerful cryptographic algorithms.

3. Use encrypted connections HTTPs across the range of banking websites. The use of HTTP should be avoided.


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).