filmov
tv
Swedbank Estonia Internet bank ID card authentication bypass

Показать описание
The flaw in Swedbank Estonia Internet bank allows to login just by knowing the victim's user ID.
Timeline:
2013.04.19. 15:55 - reported to CERT-EE
2013.04.19. 18:30 - fixed by Swedbank Estonia
The flaw is caused by allegedly misconfigured F5 BIG-IP LTM server's failure to verify signature of the X.509 certificate received in the ID card authentication process. The proof-of-concept video shows how victim's original certificate is retrieved from the public LDAP directory and certificate's public key is replaced with a public key from a freshly generated RSA keypair. The modified "fake" certificate is then imported in the browser and submited in the authentication process.
Timeline:
2013.04.19. 15:55 - reported to CERT-EE
2013.04.19. 18:30 - fixed by Swedbank Estonia
The flaw is caused by allegedly misconfigured F5 BIG-IP LTM server's failure to verify signature of the X.509 certificate received in the ID card authentication process. The proof-of-concept video shows how victim's original certificate is retrieved from the public LDAP directory and certificate's public key is replaced with a public key from a freshly generated RSA keypair. The modified "fake" certificate is then imported in the browser and submited in the authentication process.
Swedbank Estonia Internet bank ID card authentication bypass
SEB Estonia Internet bank ID card authentication bypass
Kaip užsiregistruoti į banką „Swedbank' internetu 💻, jei neturite savo veikiančio SMART ID?...
Bank ID - Beställa nytt BankID Steg för Steg. Swedbank via din mobil eller surfplatta
Estonian Internet bank authentication token cross-site replay
Kā ar Smart-ID veikt maksājumu internetbankā
Swedbank Kundtjänst: Telefonnummer och hemsida
Swedbank Smart-ID
Latvian Internet bank authentication token cross-site replay
Swedbank Appfilm
Så öppnar du ISK i Swedbank och Sparbankernas Internetbank - textat
Swedbank kodu energiatõhususe laen @Ehitame! TV (29.11.2020)
Smart-ID un internetbankas lietošana mobilajās ierīcēs
Mobile-ID identification at Swedbank's call centre
Как со Smart-ID совершать платежи в интернет-банке
How To Fix Swedbank App Not Working (2025)
Kā Swedbank internetbankā noslēgt līzinga līgumu?
Stora problem med internetbanken för Swedbanks kunder
How to Fix Swedbank Lietuva Not Working / Not Open / Loading Problem in Android
Kā sagatavot konta pārskatu no Swedbank internetbankas?
Swedbank SmartID CINEMA
Swedbank 2014 Clear Channel Estonia
Аналитик: скандал со Swedbank — это не причина бежать в банк и снимать деньги...
30 sec pitch: work at Swedbank
Комментарии