HomeInvestigationsDISCLOSURE: The majority of banks' e-banking applications vulnerable to password theft!

DISCLOSURE: The majority of banks' e-banking applications vulnerable to password theft!

A new study by the Systems Security Laboratory of the University of Piraeus has recently been published. By performing a series of experiments, the University's researchers concluded that the majority of Greek banks' e-banking applications are vulnerable to password interception from local networks.

The aim of the research was to evaluate the ability of Greek banks' e-banking applications to effectively deal with sslstrip type attacks.

The experiments were performed by postgraduate students of the Department of Digital Systems of the University of Piraeus: Chr. Lyvas, F. Lalagiannis, G. Kontogiannis, Gr. Valtas, Sp. Mantzouratos and St. Mandylas, under the guidance of Mr. Christos Xenakis, assistant professor at the University of Piraeus and Mr. Christopher Dantogian, researcher and lecturer at the University of Piraeus.

It is worth noting that both the competent department of the Bank of Greece and the National CERT were informed promptly of the results of the investigation.

Import

In this report, we present the results of our research on the ability e-banking to effectively deal with sslstrip. Specifically, we studied six Greek banks: Alpha Bank, National Bank of Greece (NBG group), Piraeus Bank, Eurobank, Citibank and Bank of Chania. The general conclusion is that the majority of Greek banks' e-banking applications are vulnerable to password theft (username, password, one-time password - token, etc.) from local networks (e.g., corporate networks, internet cafes - restaurants, hotels, university networks, school networks, airports, stations, ports, etc.). Therefore, it is necessary for the administrators of these applications to take specific security measures in order to upgrade the level of security they provide, in order to adequately protect their users.

The sslstrip attack and its consequences

To conduct the research, the sslstrip on wired and wireless local area networks, implementing the man-in-the-middle attack.

Specifically, the middleman-malicious person executing sslstrip acts as an intermediary in the communication between the victim-user and the e-banking application server.

Under normal circumstances, this communication should always be encrypted using the HTTPs protocol . However, the attacker, who is on the same local network as the victim-user, has the ability to force the user, without realizing it, to communicate with the e- banking application server via an unencrypted connection , using the HTTP protocol . This is possible because most users initiate a connection to an e-banking application by typing only the bank's domain name (e.g., eurobank.gr) into their browser, without entering the communication protocol, thus using the established HTTP protocol . Then, after the user selects the e- banking option , the application has the ability to automatically upgrade the connection from insecure to secure using the HTTPs protocol . At this point, the man-in-the-middle intervenes and maintains the insecure connection and the insecure  HTTP protocol . 

The only indication for the user to realize the presence of the man-in-the-middle and the execution of the attack is to notice that the URL displayed in the browser begins with https:// and not with https://. In case the user does not notice the above and continues browsing by entering sensitive data, such as username, password, one-time password, etc., to connect to the application, the man-in-the-middle is able to intercept the above on the local network, as they are transmitted unencrypted. The consequences of such interception are the violation of banking secrecy as well as the possibility of executing unauthorized banking transactions.

Results

The research conducted used four popular operating systems (Windows, OS X, Android OS and iOS) with the latest versions of the well-known browsers Chrome, Firefox and Safari. The analysis of the results is summarized in the table below. It is clear that the majority of the e-banking applications of Greek banks are vulnerable to password theft from local networks. The only exception is the application of the National Bank of Greece, which has a protection mechanism.

beautiful

It was also found that in all the applications examined, encryption (HTTPs) is activated on the login page and not on the homepage of each bank. Finally, all applications use the SSL 3.0/TLS 1.0 protocol for encryption, for which several weaknesses.

SecNews's opinion

SecNews, as a strong supporter of Full/Partial detail disclosure regarding software vulnerabilities, welcomes the research of the University of Piraeus. In any case, the IMMEDIATE notification of the vulnerabilities by the University of Piraeus to financial institutions and the Bank of Greece can only be evaluated positively, as it contributes to strengthening the security of infrastructures, within the framework of their research work.

It is worth mentioning that most of the time the weaknesses are not due to omissions by the Banks regarding the security measures they adhere to. The problems mainly mentioned by the study focus on the creators of the applications or on third-party commercial (or custom-made) applications that make up specific modules or parts of the ebanking applications.

[box_success]

cyberattack_3

Proposed measures

Concluding the research, a series of measures are proposed that banks should immediately implement in order to enhance the level of security provided by e-banking applications, protecting their users from malicious actions.

1. Use of the HSTS ( HTTP Strict Transport Security) rule , which forces all browsers to use only the HTTPs protocol . Thus, any attempt to connect to an e- banking application with the HTTP protocol  will automatically be upgraded to HTTPs .

2. Using the latest version of the TLS protocol (i.e. TLS v1.2), which provides strong encryption algorithms.

3. Use of encrypted HTTPs across all banking websites. The use of the HTTP protocol should be avoided.

[/box_success]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS