UnSAFE Bank A trial bank vulnerability suite!

Η UnSAFE Bank είναι μια εικονική τραπεζική σουίτα που έχει σχεδιαστεί με σκοπό να ενσωματώσει τους κινδύνους στον and various testing techniques.

It is designed for developers and security analysts to learn, distinguish and evaluate vulnerabilities by doing penetration testing in web applications, Android and iOS.

UnSAFE Bank A trial bank vulnerability suite!

This version of the application is released only for iOS devices. It will follow soon of the application that will support Android devices and Web applications

Features of the application

The application currently supports the following features:

  • Transfer of funds
  • Account information
  • Registration and promotion of beneficiaries

Note: We will have new possibilities and integration of new vulnerabilities in the future

Vulnerability Coverage

Intentionally or not, they have added a wide range of vulnerabilities, ranging from low-risk to high-risk vulnerabilities.

Setting up the application

Prerequisites:

  1. Installing it git in our system.
  2. Installing it docker-compose in our system.
  3. We must not run any other services on port 80 of our machine.
  4. Requires Android or iOS phone for penetration testing.

Server setup

  1. We open a terminal and give the following command git clone https://github.com/lucideus-repo/UnSAFE_Bank.git
  2. Go to the UnSAFE_Bank / Backend directory with the cd command UnSAFE_Bank / Backend
  3. We start the docker service by typing sudo service docker start
  4. We start the docker operations with the docker-compose up -d command

Application installation iOS

  1. Download and install it Cydia Impactor in our system.
  2. Connect the iPhone to our system and open the Cydia Impactor.
  3. We go to the list / iOS.
  4. Drag and drop it UnSAFE Bank.ipa our file in Cydia Impactor.
  5. Follow the steps shown by Cydia Impactor until we complete the installation.
  6. Our application is ready to use.

Note: You can use other methods to install the app on iOS, whichever way suits you.

Connectivity status test

  1. We are sure that iPhone and our system are connected to the same network.
  2. We check the IP address of our system as well as the port on which you are running (Port 80).
  3. Open the iOS Application and give our login details in the upper left to enter the application.
  4. If all goes well, it will display the message on the iPhone that says "You are connected successfully".
  5. If it shows us a message , then we should check that our application is working properly and that we have entered the valid address and port.

Login Credentials

A customer ID and password are required to log in to the application. You can always register as a new user.

Upon successful registration:

  1. You will be given the customer ID that corresponds to your account. Always note your customer ID and keep it SAFE for further use.
  2. Virtual PIIs and your account information will be generated automatically.
  3. Default beneficiaries will be added to your account automatically.
  4. They will be added virtually in your account ranging from 1 to 5 million

Existing users

The following data can be used to perform actions such as adding a beneficiary, transferring money, etc.

Account Holder Account number IFSC code
Vipul Malhotra 003558008876 IFSC00009
Kevin Winkel 270365500638 IFSC00009
Kelly campbell 533074805951 IFSC00010
Krystal Langworth 731258783797 IFSC00006
Margarita Mann 359502423130 IFSC00010
David Mahabir 795554898923 IFSC00002
Boris Gerhold 485064210112 IFSC00006
Nathaniel Runolfsson 518569490010 IFSC00003
Yvette Cooper 841478410516 IFSC00007
Orion Glover 001498029143 IFSC00003

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).