Monday, April 17, 2017
Online banking vulnerabilities in 2014 Authentication Authorization and Android
Online banking vulnerabilities in 2014 Authentication Authorization and Android

In this article we present some results of the research on OLB vulnerabilities discovered by Positive Technologies experts in 2013 and 2014 in the course of security assessments for a number of the largest Russian banks.
Cases
28 systems for personal (77%) and commercial (23%) online banking were investigated in the course of this research. They included mobile banking systems consisting of server and client components (54%). Two thirds of the systems (67%) were developed by banks themselves using Java, C#, and PHP. The rest were implemented on platforms of well-known vendors. Most OLB systems (74%) were operational and accessible to clients. 25% of the systems were testbeds, but ready for commissioning in the foreseeable future. The severity of the vulnerabilities was graded based on CVSS version 2.
General Findings
Almost half of the OLB vulnerabilities discovered (44%) were classified as High severity. Vulnerabilities classified as Medium (26%) and Low (30%) severity were approximately equal. In general, high severity vulnerabilities were discovered in 78% of the investigated systems.
Most vulnerabilities (42%) were caused by developers bugs in OLB security implementation. This includes flaws in identification, authentication, and authorization mechanisms. The second most common vulnerability (36%) are bugs in the application source code. The rest (22%) relate mainly to misconfiguration.

The most common OLB vulnerabilities found are related to software information disclosure and predictable user ID formats (57%). More than half of the systems (54%) were vulnerable to Cross-Site Scripting (XSS) attacks. Successful exploitation of this vulnerability could allow an attacker to obtain OLB access in the context of the targeted user if the victim navigated to a specially crafted website.
Vulnerabilities that facilitated attacks on user sessions were also very common (54%). These included improper session termination, incorrect cookie settings, multiple sessions under one account, and a lack of association between user sessions and client IP addresses. Successful exploitation of these vulnerabilities could allow an attacker to obtain access to the targeted account with full user rights.
XML External Entity (XXE) vulnerabilities were among the most common high severity vulnerabilities discovered in 46% of the systems. Successful exploitation of these vulnerabilities could allow an attacker to read files on a vulnerable server, reveal open network ports on the host, cause a denial of OLB services or, under certain conditions, impersonate a vulnerable server to perform further attacks on arbitrary hosts.
Half of the investigated OLB systems (52%) were vulnerable to Denial of Service (DoS) attacks.
The most commonly found vulnerabilities are classified as Medium or Low severity. Nevertheless, these vulnerabilities in conjunction with some OLB features could cause critical security flaws like stealing personal data (89%) or money (46%).

The investigated OLB systems also contained a number of severe logic vulnerabilities. For example, a number of systems were vulnerable to attacks involving floating point rounding errors. Lets assume that an attacker wants to convert 0.29 RUB (Russian Ruble) to USD (United States Dollar). If the price of 1 USD is 60 RUB, then 0.29 RUB equals to 0.004833333333333333333333 33333333 USD. This sum is rounded up to the hundredths place, i.e. to 0.01 USD (one cent). Then the attacker converts 0.01 USD back to rubles and gets 0.60 RUB. The attackers bonus is 0.31 RUB. Thus, a malicious user can automate this procedure and obtain an unlimited amount of money, as there are no limitations on the number of transactions per day and on the minimum sum to exchange. Race Condition vulnerability may also facilitate exploitation of this bug.
Vulnerabilities by Developers
High severity vulnerabilities are more common for third-party OLBs (49%) than for proprietary systems OLBs (40%). OLB supplied by dedicated developers contain 2.5 times more source code bugs than OLB developed by onsite programmers. This is due to banks using third-party software and relying on the vendors source code QA. However, as OLBs are cross platform and have complicated architectures and multiple features they do not allow vendors to provide sufficient security at the source code level.

Most common security vulnerabilities
The most common security flaw, found in 64% of OLB identification mechanisms is a predictable ID format. An attacker who knows several valid IDs may predict the algorithm used to generate them. 32% of the investigated systems exposed information on valid accounts by generating different responses depending on whether the user account existed. 20% of OLB systems contained both identification vulnerabilities mentioned above.
58% of the investigated systems contained security flaws in the authentication mechanisms, for example weak password policy, insufficient protection against brute force attacks, CAPTCHA bypass vulnerabilities, and the lack of two-factor authentication.

79% of the investigated systems had insufficient authorization and transaction security and 42% allowed attackers to obtain unauthorized access to user data (personal data, bank accounts, payments, etc.). 13% of the systems allowed direct banking operations on behalf of the targeted user.

Mobile Banking Vulnerabilities
Applications for Android OS are more vulnerable as compared to iOS applications. High severity vulnerabilities were discovered in 70% of Android applications and in 50% of iOS applications.
On average, each Android application contains 3.7 vulnerabilities, while each iOS application contains 2.3 vulnerabilities.

The most common vulnerabilities in mobile banking applications are related to insecure data transmission (73%), insufficient session security (55%), and unsafe data storage (41%).
The most commonly found mobile OLB vulnerabilities were classified as Medium and Low severity, but in some cases, a combination of these vulnerabilities could have a critical impact on the system. For example, one of the investigated applications was broadcasting banks SMS message with a one-time password for the transaction, which could be intercepted by an external application. Moreover, this mobile application logged sensitive data that could allow an attacker to obtain user credentials and perform transactions on behalf of the mobile application user by executing malicious code on the targeted mobile device.

Our Recommendations
To reduce any risks related to OLB vulnerabilities banks should implement secure development procedures, provide comprehensive testing at the acceptance stage, and use preventive protection means like the Web Application Firewall. Additionally banks should use the Application Firewall for third-party productive systems in order to prevent vulnerability exploitation until it is patched by the vendor.
More details from this research will be presented at Positive Hack Days infosec conference (May 26-27, Moscow) were the participants can take part in hacking contests Leave ATM alone (detecting ATM vulnerabilities) and "Snatch" (exploiting an online banking system). See the contests rules and results at www.phdays.com.
Available link for download
Thursday, March 30, 2017
ONDO STATE 2014 SCHOLARSHIP AND BURSARY AWARDS EXTENSION OF APPLICATION PERIOD
ONDO STATE 2014 SCHOLARSHIP AND BURSARY AWARDS EXTENSION OF APPLICATION PERIOD
This is to inform all our students of Ondo State Origin that due to the public holidays and the initial hiccup
encountered by applicants, the closing date for the application for the 2014 Scholarship and Bursary has been extended by two (2) weeks.
The new closing dat will now be Monday 5th May, 2014.
I enjoin our students to take advantage of this extension and complete the process on time.
HOTLINES:
In case of any delay or unsatisfactory service in the bank (UBA), pls call either of these lines: 08033345490, 08033589938.
In case of any difficulty encountered in the online application process, pls call: 08023077160
I thank you all.
Dayo Awude,
Board Chairman.
Available link for download
Monday, February 27, 2017
Oh My Pyo Ji 2014 Punjabi Full WebHD Movie Free
Oh My Pyo Ji 2014 Punjabi Full WebHD Movie Free

|| Oh My Pyo Ji 2014 ||
[ Punjabi | WebHD | 480p]
Ratings: 8.8/10
Genre(s): Comedy
Released On: 25 July 2014
Directed By: Niharika Sahni
Star Cast: Rai Babal, Jaswinder Bhalla, Mehra BhanuShri

Synopsis: Oh My Pyo is a 2014 lighthearted comedy Punjabi film coordinated and created by Niharika Sahni. The film stars Binnu Dhillon, Babbal Rai, Jaswinder Bhalla, Bhanu Sri Mehra, Nirmal Rishi and debutante Dakshita Kumaria.
||Download File Via Torrent||
Click Here To Get File
Oh My Pyo Ji 2014 Punjabi Full WebHD Movie Free Watch Online Links
||Free Watch Full Movie Online Via Single Links||
Nowvideo | Cloudy | Movzap | Sockshare | Hbulk
Oh My Pyo Ji 2014 Punjabi Full WebHD Movie Free Download Links
||Free Download Via Single Resumable Links Size: 653MB||
Nowdown | Click | Upgrand | User | 2Drive | Jumbo | Multi
Click Here To Get Rar File Links
Oh My Pyo Ji 2014 Punjabi Full WebHD Movie Free Splitted Parts Download
||Download Via Resumable Splitted Parts Size: 131MB||
Nowdownload: part-1 | part-2 | part-3 | part-4 | part-5
Direct Files: part-1 | part-2 | part-3 | part-4 | part-5
Clickupload: part-1 | part-2 | part-3 | part-4 | part-5
Sharebeast: part-1 | part-2 | part-3 | part-4 | part-5
Uploadbaz: part-1 | part-2 | part-3 | part-4 | part-5
Solid: part-1 | part-2 | part-3 | part-4 | part-5
Uppit: part-1 | part-2 | part-3 | part-4 | part-5
Zippy: part-1 | part-2 | part-3 | part-4 | part-5
Available link for download
Monday, February 13, 2017
Old timer GP 2014 at the Nurburgring
Old timer GP 2014 at the Nurburgring































Available link for download
Thursday, February 9, 2017
Monday, February 6, 2017
Ondo State 2014 Scholarship Bursary Application
Ondo State 2014 Scholarship Bursary Application
From the chairman of ondo state Scholarship/Bursary Board...
We did announce that the 2014 application for Scholarship and Bursary would commence yesterday but we had some technical issues with opening the
portal to our students, as envisaged.
The problem has now been resolved and students can now begin to apply from tomorrow, Wednesday, while we compensate for the two days already lost. The application will now close on Wednesday 23rd April, as against the initially stipulated date of 21st April.
Thank you.
Dayo Awude,
Chairman.
Available link for download
Friday, January 27, 2017
NYSC 2014 Batch B Mobilization Timetable
NYSC 2014 Batch B Mobilization Timetable
1. Registration of Foreign Nigerian Graduates.14th April, 2014 - 11th July, 2014
2. Batch 'B' pre-Mobilization, Deployment & Relocation Officers' Workshop.6th - 9th May, 2014
3. Submission of Masterlist by Corps Producing Institution/Screening/Vetting by Mob. officers.2nd - 7th June, 2014
4. Delivery of Print-outs to CPIs16th - 18th June, 2014
5. Return of Corrected Printouts by Institutions to Mobilization Dept.25th - 27th June, 2014
6. Briefing of Final year Students/Prospective Corps members in CPIs.7th - 11th July, 2014
7. Delivery of Call-up letters to CPIs.28th - 31st July, 2014
8. 2014 Batch 'B' Orientation Programmes5th - 26th Aug
Available link for download