Home
Learn More
Features & Pricing
Success Stories
Contact Us
Search Archives
PRWeb Direct
Submit Release
September 6, 2008
 
Industry Categories  
News by Country  
News by MSA  
Todays News  
Browse by Day  
PR Trackbacks™  
Featured Videos  
ViewNews™  
eBook Digests  
RSS  
PRWeb, a leader in online news and press release distribution, has been used by more than 40,000 organizations of all sizes to increase the visibility of their news, improve their search engine rankings and drive traffic to their Web site.
 
All Press Releases for August 16, 2006 Subscribe to this News Feed      
 

Vulnerability of Passmark Sitekey at Bank of America Reported

A previously unreported vulnerability of Passmark Sitekey at Bank of America was announced today. The vulnerability could permit an attacker to remotely lock out thousands of bank customers from their online banking accounts.

(PRWEB) August 16, 2006 -- Sestus Data Corporation announced today the discovery of a vulnerability of the Passmark Sitekey login approach at Bank of America that could permit an attacker to remotely lock out thousands of customers from their online banking accounts.

The vulnerability announced today is similar to a "denial of service" attack in that it permits an attacker to remotely "lock out" customers from their online accounts, potentially overwhelming the bank's customer support lines with calls from frustrated customers. Sestus Data also warned that this vulnerability is not unique to Passmark Sitekey or Bank of America, but is a vulnerability of the underlying challenge question / response approach to authentication used at many banks.

In the case of Passmark Sitekey at Bank of America, Sitekey requires customers to enter their account login ID first, before the website has been authenticated to the customer. This process has been highly criticized by the FFIEC for its potential to permit fraudsters to use counterfeit websites to gather legitimate preliminary login IDs for use in future attacks.

Next, Sitekey attempts to locate a "device ID" on the customer’s computer. In the absence of a device ID, however, Sitekey prompts the customer to supply the answers to personal questions, such as "What is your mother’s maiden name". If the customer answers the questions incorrectly, BofA will lock up the account and require the account owner to call customer service to have their account "reset" or released.

Originally designed as a security feature, Sestus Data Corporation reports it appears this "lock out" process can be exploited by malicious hackers to remotely lock out customers from their accounts en-masse, or used by fraudsters in a hybrid lock out/phishing attack to access the actual account.

Sestus Data described three scenarios for this lock out attack but cautioned that many more scenarios are possible:

DICTIONARY BASED (AUTOMATED) ATTACK SCENARIO
This attack scenario would involve the use of a dictionary database and a simple scripting program. The attacker would first obtain a database of words used as typical login IDs. Such databases are easily obtainable online.

Next, the attacker would write a simple program to supply the information to a waiting browser. Any high-school computer student could probably write such a program and it would certainly not be beyond the capabilities of an experienced webmaster or programmer.

During the attack, the attacker's program would supply words from the database to BofA’s webpage and test for a response. While it is true that the vast majority of the supplied words would likely be invalid, a small statistical percentage will be valid login IDs. Each time a valid login ID is discovered, since Sitekey would detect no device ID from the attacker's computer, it would prompt for personal information to be supplied in response to challenge questions. The attacker's program would then only need to supply random, nonsensical information. After sufficient invalid answers, BofA will lock the account and the attacker would then move on to the next word.

In this attack scenario, a single attacker could theoretically lock up thousands of BofA accounts, overwhelming the bank's support lines with calls from bewildered customers. Bank of America would likely be unaware of an attack being launched because the attacker would be following the same procedures expected of legitimate website users. Only after the customer support lines started to ring excessively would the bank become aware of the attack. If the bank were to attempt to modify Sitekey to detect multiple invalid IDs being tried from the same IP location, the attacker could simply move behind a legitimate proxy server, such as AOL, and continue their attack.

CASUAL ATTACK SCENARIO
In a less sophisticated version of this attack, a casual malicious attacker could simply go to their public library and begin testing random (or stolen) words against BofA's webpage, and then supply invalid answers for every valid ID discovered.

HYBRID (LOCK OUT/PHISHING) ATTACK SCENARIO
In a more insidious version of this attack, an attacker could combine this lock out attack with a traditional phishing attack to actually gain access to the customer’s account.

First, the attacker would lure the customers to a phishing website and prompt them to supply their login ID. Since this is precisely the same "first step" initiated on the legitimate BofA website, the customer would suspect nothing at this point and the phishing website would simply redirect the customer to the legitimate website to "try again".

Later, the fraudster would use these gathered login IDs to lock out the customers from their accounts as described above.

Finally, after the accounts were locked, the fraudster would re-contact the customers by telephone or by email, posing as a BofA customer support representative, and inform the customer that their account has been locked for security reasons. They might even invite the customer to confirm this for themselves while they wait. The fraudster would then request the customer verify certain confidential information "before we will unlock your account".

Since the customer would naturally presume that only BofA should be able to affect their actual account, the customer would likely believe the fraudster and provide the requested confidential information. Once obtained, the fraudster could either re-direct the customer to the legitimate customer support line, or, using the stolen information, contact the bank themselves to have the account unlocked. Once unlocked, the fraudster could use the solicited information to access the account.

FDIC WARNINGS AGAINST USING PERSONAL INFORMATION
While this lock out scenario was not envisioned by regulators when they cautioned against the use of personal information for authentication, regulators have long warned against the use of personal information for authentication owing to its inherent weakness and unpopularity with consumers.

On June 17, 2005, the FDIC published supplement guidance warning financial institutions to be prepared to meet stiff resistance from customers to any approach that relies on personal information, stating "When banks consider authentication methods for retail customers, they should be aware that these customers value security and the protection of confidential information... Consumers will require a clear explanation of any security mechanism and the use of any personal information required to implement that security mechanism." They also noted that "limitations on the use of personal information” were important elements of consumer acceptance.

ABOUT SESTUS DATA CORPORATION
Sestus Data Corporation’s PhishCops(tm) product represents the next-generation in online security, replacing vulnerable logins and passwords, expensive hardware tokens, difficult-to-manage software, and vulnerable “challenge-question” approaches, with an unbreakable, government-approved, mathematic multi-factor authentication approach.

PhishCops(tm) mathematic algorithms were developed by the National Institute of Standards and Technology (NIST) and the Information Technology Laboratory (ITL) under the authority of the U.S. Department of Commerce and are the current U.S. standard for authentication.

For its ground-breaking multi-factor authentication solution, the United States government named PhishCops(tm) a semi-finalist for the 2005 Homeland Security Award and InfoWorld Magazine awarded it their highest honor, the InfoWorld 100 award.

Company website: http://www.phishcops.com

###

Post Comment:
Trackback URL: http://www.prweb.com/pingpr.php/SGFsZi1QaWdnLVpldGEtTWFnbi1JbnNlLVplcm8=

Technorati Tags

Bookmark -  Del.icio.us | Digg | Furl It | Spurl | RawSugar | Simpy | Shadows | Blink It | My Web


Other Releases by this Member
OPTIONS
Printer Friendly Version
Download PDF Version
Download Reader Version
Email this story to a colleague
CONTACT INFORMATION
Media Contact
Sestus Data Corporation
800 788-1927
Email us Here
ATTACHED FILES

There are no multimedia files attached to this release. If this is your release, you may add images or other multimedia files through your login.

ABOUT PRESS RELEASES
If you have any questions regarding information in these press releases please contact the company listed in the press release. Please do not contact PRWeb. We will be unable to assist you with your inquiry. PRWeb disclaims any content contained in these releases. Our complete disclaimer appears here.
 
Disclaimer: If you have any questions regarding information in these press releases please contact the company listed in the press release.
Please do not contact PRWeb®. We will be unable to assist you with your inquiry.
PRWeb® disclaims any content contained in these releases. Our complete disclaimer appears here.

© Copyright 1997-2008, Vocus PRW Holdings, LLC.
Vocus, PRWeb and Publicity Wire are trademarks or registered trademarks of Vocus, Inc. or Vocus PRW Holdings, LLC.

Terms of Service | Privacy Policy | Copyright