Search This Blog

Powered by Blogger.

Blog Archive

Labels

Banks are not interested to fix Man-in-the-Browser (MitB) security flaw

Security Experts claims that banks are not really interested in security . Many banks try to threaten the security experts who expose the security flaws , instead of patching the vulnerability.

Security expert Yash KS, from Red Force Lab, who has demonstrated how Online Banking sites of India are vulnerable, he published a video on YouTube showing how Trojan can breach bank sites.  All these bank removed the video from public domain but failed to enhance the security.

"Citibank has never responded when I contacted them to talk about malware. But when I posted my videos online, they mitigated the risk to some level within 10 days. It’s a good response. (However) Before fixing it, they blocked my video in YouTube saying it is harmful content." MoneyLife quoted as Mr Yash saying.

Mr Yash has been trying to explain to all banks in India about the security flaw but there is no response so far. He demonstrated the vulnerability in front of senior officials from ICCI Bank. However , the bank officials refused to believe his demo and claimed that their systems are more secure(?!).

HSBC Bank tried asked the hosting services provide to disable his site and later forced them to remove the video that showed how HSBC’s online accounts can fall prey to malware attacks. They also send some goons to his residence.

”After failure attempts to bring down content with the help of service provider, HSBC sent goons to my residence. I was not present at that time; they have asked my family members rude questions.”he said.
Share it:

Vulnerability

Web Application Vulnerability