首页> 外文会议>International conference on financial cryptography and data security >Why Banker Bob (Still) Can't Get TLS Right: A Security Analysis of TLS in Leading UK Banking Apps
【24h】

Why Banker Bob (Still) Can't Get TLS Right: A Security Analysis of TLS in Leading UK Banking Apps

机译:为什么银行家Bob(仍然)无法正确获得TLS:英国领先的银行应用中TLS的安全性分析

获取原文

摘要

This paper presents a security review of the mobile apps provided by the UK's leading banks; we focus on the connections the apps make, and the way in which TLS is used. We apply existing TLS testing methods to the apps which only find errors in legacy apps. We then go on to look at extensions of these methods and find five of the apps have serious vulnerabilities. In particular, we find an app that pins a TLS root CA certificate, but do not verify the hostname. In this case, the use of certificate pinning means that all existing test methods would miss detecting the hostname verification flaw. We also find one app that doesn't check the certificate hostname, but bypasses proxy settings, resulting in failed detection by pentesting tools. We find that three apps load adverts over insecure connections, which could be exploited for in-app phishing attacks. Some of the apps used the users' PIN as authentication, for which PCI guidelines require extra security, so these apps use an additional cryptographic protocol; we study the underlying protocol of one banking app in detail and show that it provides little additional protection, meaning that an active man-in-the-middle attacker can retrieve the user's credentials, login to the bank and perform every operation the legitimate user could.
机译:本文对英国主要银行提供的移动应用程序进行了安全审查。我们将重点放在应用程序建立的连接以及TLS的使用方式上。我们将现有的TLS测试方法应用于仅在旧版应用程序中发现错误的应用程序。然后,我们继续研究这些方法的扩展,发现其中五个应用程序存在严重漏洞。特别是,我们找到了一个可固定TLS根CA证书但不验证主机名的应用。在这种情况下,使用证书固定会意味着所有现有的测试方法都会错过检测主机名验证漏洞的机会。我们还找到了一个不检查证书主机名但绕过代理设置的应用程序,导致渗透测试工具检测失败。我们发现,三个应用程序通过不安全的连接加载广告,这可能会被利用来进行应用程序内网络钓鱼攻击。有些应用程序使用用户的PIN进行身份验证,而PCI准则则要求额外的安全性,因此这些应用程序使用了附加的加密协议。我们详细研究了一个银行应用程序的底层协议,并表明它几乎没有提供额外的保护,这意味着活跃的中间人攻击者可以检索用户的凭据,登录银行并执行合法用户可以执行的所有操作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号