Bratva Files Epi 05
I told john, give me some time and I will call you back and than I visit the bank official website and first I learn about their ui, ux, any glitches and how often they made their security patches to their website and mobile application. For example every social media application, if we login in the website or an application, mostly it didn’t logout, we need to logout manually. Even in some of the social media application, even we close the device or switch off the system, and when we reboot, still the application login remaining and we can see the recent feed on our screen, but when comes to banking application or an website its completely different..
Once we login, we can see the timer running on or below the
screen, so whether we check the previous statement or making some payments, if
we take longer, than the site automatically log out. And we need to login
again, for some people, they told this as headache, but its their level of
security. So attackers cant easily get into their servers. I started to get
deeper into the site and I inspect on which language they write the source code
for the site, also i just saw something in it. There is a third party company,
who give security patches to the site. But it seems to be too old.
When I learn about this bank, at the beginning stage of the
bank, they have less customer and didn’t have much fund, so use their major
part of the fund for marketing for getting more customer to their ban k and
they find some small company who provide security for some startups. But after
the bank growup, they hire more engineers and they ask them to build a own
security for their bank website. But those guys who build security for the
bank, they just overwrite some of the code from those third party company did
many many years before. When I deep dive into it, I just find one more thing,
So now If I find the source code, I can do anything by sitting in my room to
make them panick. But first I need to find where that third party company
located..
Comments
Post a Comment