Главная
Study mode:
on
1
APPSEC EUROPE
2
Agenda
3
Common attack patterns
4
Clipboard (or memory) manipulation
5
Server vulnerability exploitation
6
How banks mitigate these risks?
7
Vuin examples (functional)
8
Vuln examples (non functional)
9
Transaction authorization best practices
10
make it trusted
11
overwrite data
12
business logic error
13
Trusted recipients Recommendations
14
Limit examples
15
Transaction limits - requirements
16
Notifications - requirements
17
USER AUTHENTICATION
18
Payment Services Directive (revised)
19
Strong Customer Authentication (SCA)
20
Payment Initiation Service
21
Account Information Service
22
Implementation errors - vulnerabilities
23
Precise requirements
24
OWASP to the rescue!
25
Internet banking - proposal
Description:
Explore common attack patterns and vulnerabilities in internet banking safeguards through this conference talk from AppSecEU 2016 in Rome. Delve into clipboard manipulation, server vulnerability exploitation, and how banks mitigate these risks. Examine functional and non-functional vulnerability examples, transaction authorization best practices, and recommendations for trusted recipients. Learn about transaction limits, notification requirements, and user authentication methods. Discuss the revised Payment Services Directive, Strong Customer Authentication, and implementation errors. Gain insights into precise requirements and OWASP's role in improving internet banking security.

Internet Banking Safeguards Vulnerabilities - AppSecEU 2016

OWASP Foundation
Add to list
0:00 / 0:00