Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Debasis Mohanty
    Defeating Citi-Bank Virtual Keyboard Protection
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Defeating Citi-Bank Virtual Keyboard Protection

    Recently I discovered a method to defeat the much hyped Citi-Bank Virtual
    Keyboard Protection which the bank claimed that it defends the customers
    against malicious programs like keyloggers, Trojans and spywares etc.

    Find the details below -

    Description:
    Early this year, Citi-Bank introduced the concept of Virtual Keyboard to
    defend against malicious programs like keyloggers, Trojans and spywares etc.
    The bank claimed that this concept would improve the security of those using
    its Internet banking facilities. Various features of this Virtual Keyboard
    are -

    .. The Virtual Keyboard is dynamic
    .. The sequence in which the numbers appears will change every time,
    the page is refreshed
    .. The Virtual Keyboard protects you from malicious 'Spy Ware' and
    'Trojan Programs' designed to capture your keystrokes
    .. The Virtual Keyboard eliminates this risk and makes your Citibank
    login that much safer and provides for a secure online banking experience

    However, the Virtual Keyboard concept can be easily defeated by using Win32
    APIs to access HTML documents. Refer the PoC (Proof of Concept) section for
    more details.

    Criticality: High

    Platform: Windows XP (SP2) + IE 6.0

    Note: This PoC is applied only for Internet Explorer users

    Proof of Concept:
    Here I shall demonstrate how easily the Virtual Keyboard can be defeated by
    a simple program. I created a small program in VB 6.0 (called
    CitiPassLogger.exe) which can record not only the 16-Digit credit card but
    also the IPIN even if they are entered using the virtual keyboard.

    Currently, this program has been developed to log only the IPIN details of
    Citi-Bank India but the code can be modified to make it work universally for
    all the Citi-Bank sites with Virtual Keyboard login.

    As per my knowledge, there are no such keyloggers or spywares which uses any
    technique to defeat virtual keyboards. However, the technique that I am
    going to discuss here can be used by malicious program writers to write next
    generation viruses / worms to defeat such virtual keyboard protections.
    Hence, I hope people who are using Virtual Keybords shouldn't stay very
    over-confident.

    Download the complete PoC and the tool from the following link:
    http://www.hackingspirits.com/vuln-r...itibank-vk.zip

    For more vulnerabilities, visit
    http://www.hackingspirits.com/vuln-rnd/vuln-rnd.html


    History:
    3rd August, 2005: Vendor was contacted but no response till today.


    Cheers,
    Debasis Mohanty (a.k.a Tr0y)
    www.hackingspirits.com



  2. #2
    Daniel Bonekeeper
    Defeating Citi-Bank Virtual Keyboard Protection
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Defeating Citi-Bank Virtual Keyboard Protection

    First, seems that this kind of "virtual keybord" is, by design, weak.
    The data posted to the webserver is the same as the content on the
    IPIN field (there is no such a encoding or another thing to mask what
    was typed). A more secure example of a virtual keyboard can be found
    at:

    https://www2.bancobrasil.com.br/aapf/aai/login.pbk

    On this form, the "virtual keyboard" is a java applet that can receive
    a variable ammount of digits, and when a POST is requested, the typed
    data is encoded by someway... So, a PIN like "123456" is sent as
    "EISYWb", as we can see at "senhaConta":

    POST /aapf/aai/login.pbk HTTP/1.1
    Host: www2.bancobrasil.com.br
    Content-Type: application/x-www-form-urlencoded
    Content-Length: 169
    titular=3D01&numeroContratoOrigem=3D431231&depende nciaOrigem=3D3123123123&s=
    enhaConta=3DEISYWb&botaoOk.x=3D&numCod=3D2&valorCo ntr=3D4&botaoEntra.x=3D20=
    &botaoEntra.y=3D8&paginaComErro=3Dfalse

    And after that, if we post the same PIN, we're gonna get something
    different like "EIQTUe", which means that neither looking at the HTML
    source code, look for field values, hook the keyboard of trap the data
    that is being posted will work in that case. It's not a 100% safe
    method, but is safer than the Indian CitiBank virtual keyboard.


    --=20
    # (perl -e "while (1) { print "\x90"; }") | dd of=3D/dev/evil

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics