12.07.2015 Views

How to Rob an Online Bank (and get away with it) - Acros Security

How to Rob an Online Bank (and get away with it) - Acros Security

How to Rob an Online Bank (and get away with it) - Acros Security

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Attacks Against Individual UsersGoal: Ident<strong>it</strong>y TheftMethodsE-B<strong>an</strong>kingServerBack-EndServer• Phishing, Fake secur<strong>it</strong>y alerts• XSS, CSRF• Malware (m<strong>an</strong> in the browser,extraction of certs <strong>an</strong>d private keys)Problems• User awareness• 2-fac<strong>to</strong>r authentication• OOB tr<strong>an</strong>saction confirmations• Add<strong>it</strong>ional passwords/PINs• “Known good” tar<strong>get</strong> accounts5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!