UnSAFE Bank A trial bank vulnerability suite!

UnSAFE Bank is a virtual banking suite designed to integrate cybersecurity risks and various testing techniques.

It is designed for developers and security analysts to learn, distinguish and evaluate vulnerabilities by doing penetration testing in web applications, Android and iOS.

UnSAFE Bank A trial bank vulnerability suite!

This version of the application is only available for iOS devices. An application upgrade that will support Android devices and Web applications will follow shortly

Features of the application

The application currently supports the following features:

  • Transfer of funds
  • Account information
  • Registration and promotion of beneficiaries

Note: New ones and integration of new vulnerabilities we will have in the future

Vulnerability Coverage

Intentionally or not, they have added a wide range of vulnerabilities, ranging from low-risk to high-risk vulnerabilities.

Setting up the application

Prerequisites:

  1. Installing it git in our system.
  2. Installing it docker-compose in our system.
  3. We must not run any other services on port 80 of our machine.
  4. Requires Android or iOS phone for penetration testing.

Server setup

  1. We open a terminal and give the following command git clone https://github.com/lucideus-repo/UnSAFE_Bank.git
  2. Go to the UnSAFE_Bank / Backend directory with the cd command UnSAFE_Bank / Backend
  3. We start the docker service by typing sudo service docker start
  4. We start the docker operations with the docker-compose up -d command

Application installation iOS

  1. Download and install it Cydia Impactor in our system.
  2. Connect the iPhone to our system and open the Cydia Impactor.
  3. We go to the list / iOS.
  4. Drag and drop it UnSAFE Bank.ipa our file in Cydia Impactor.
  5. Follow the steps shown by Cydia Impactor until we complete the installation.
  6. Our application is ready to use.

Note: You can use other methods to install the app on iOS, whichever way suits you.

Connectivity status test

  1. We are sure that iPhone and our system are connected to the same network.
  2. We check her IP of our system as well as the port you are running on (Port 80).
  3. Open the iOS Application and give our login details in the upper left to enter the application.
  4. If all goes well, it will display the message on the iPhone that says "You are connected successfully".
  5. If we get an error message, then we need to check if our application is working properly and if we have entered the valid address and the correct port.

Login Credentials

Customer ID and password are required to login to the app. You can always register as a newbie .

Upon successful registration:

  1. You will be given the customer ID that corresponds to your account. Always note your customer ID and keep it SAFE for further use.
  2. Virtual PIIs and your account information will be generated automatically.
  3. Default beneficiaries will be added to your account automatically.
  4. Virtual money ranging from 1 to 5 million will be added to your account

Existing user accounts

The following data can be used to perform actions such as adding a beneficiary, transferring money, etc.

Account Holder Account number IFSC code
Vipul Malhotra 003558008876 IFSC00009
Kevin Winkel 270365500638 IFSC00009
Kelly campbell 533074805951 IFSC00010
Krystal Langworth 731258783797 IFSC00006
Margarita Mann 359502423130 IFSC00010
David Mahabir 795554898923 IFSC00002
Boris Gerhold 485064210112 IFSC00006
Nathaniel Runolfsson 518569490010 IFSC00003
Yvette Cooper 841478410516 IFSC00007
Orion Glover 001498029143 IFSC00003

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).