Authentication flaw in Automatic Bank Passbook printing machine.

By Indrajeet Bhuyan on 05 Nov 2015 @ Groundzerosummit
🔗 Link
We need help to complete this entry! Missing: presentation, Video
I can help!
#authentication #identity-management #application-pentesting #security-testing #incident-management #data-leak
Focus Areas: 🔒 Data Privacy & Protection , 🔐 Application Security , ⚙️ DevSecOps , 🪪 Identity & Access Management , 🚨 Incident Response , 🌐 Web Application Security

Abstract

With Banks installing automatic passbook printers that update a customer’s transactions without the need to have any authentication or password, it has become easy to fool such machines and get just about anyone’s complete bank account balance and full transaction details. This talk exposes this vulnerability - a concern for all major Indian Banks and their customers whose personal banking details are at risk of being exposed by a simple hack