Advertisement
Guest User

This man could use your help

a guest
Jun 24th, 2012
3,390
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.57 KB | None | 0 0
  1. Dear people:
  2. Those of you who follow me on Twitter, chat with me in IRC or listen to the casts on Spreaker, know that I am not one to spread much attention to issues outside of the usual "biggies" we all tend to do. However in this case I make an exception.
  3.  
  4. WHAT IS HAPPENING?
  5. A security professional in India, from a small security start up company, has recently discovered another form of MitB attack vector that would affect everyday bank users in India. MitB, stands for Man-in-the-Browser and I suggest you read up on that should you care to. It is not small potatoes. Upon the discovery of this, he, with good intentions, decided to contact the appropriate institutions in hope that they would try to fix the issue. This has not only been tossed out the window, but he is now the target of the financial institutions illegal attempts to silence the discovery. He posted proof-of-concept documents as well as videos on youtube and I believe Vimeo, possibly others, which have been taken down and his accounts blocked in a rather rapid manner. The bank is using highly illegal and unethical (no surprise there) means to quiet the attention. Going so far as to have suspect individuals camped outside this mans home.
  6.  
  7. He has contacted authorities to register complaints and facts and it would appear that someone got there first as they are responding to this with more threats.
  8.  
  9. Let's clarify one thing first, this was NOT an authorized audit. Does that matter here? No. Why? Because he did not audit the banks servers. This is a browser vulnerability that affect the online banking element of average, hard-working citizens of India and elsewhere. Sadly, I don't believe any civilian has one a lawsuit against a bank for loss of funds due to fraud, and even more sadly is the Law in India for financial institutions to protect clients, no matter how small, from fraudulent activities of criminals.
  10.  
  11. WHY IS THIS IMPORTANT?
  12. Well let me start with this. This gentlemen is indeed a White Hat. Similar to myself but I tend to wear shades of grey. A similarity to myself and him is that we are trying to secure the day-to-day, average Joe and Jane and their families. I walked from the big clients and corporate elements for the same reason many of you despise them and in turn despise us sadly. When I hear Anonymous or AntiSec etc.etc. say death to WhiteHats, I am saddened by that. I understand who they are referring to. The very same IT folks that are either silencing this issue for the banks or doing nothing about it. So although I do not wish to shed the title of myself, I do wish to make a separation from the intended recipients of that message. As I don't disagree with you there. I've come to know those who throw morals to the wind for their paycheck. I simply cannot. I am for the small fry. The underdog. The ones without a fighting chance against the big, well funded and much to lose and nothing more to gain.
  13.  
  14. That being said, this is not a request for retaliatory action, after all whats at stake here is peoples hard earned money in a nation that already has enough problems as it is. I simply ask to draw attention to the issue as none has been. The only attention thus far, is making it all go away quietly.
  15.  
  16. When good, honest people, try to do what's right and get burned by those in 'charge', I say that's reason enough to make a stand and take action. All this man asks for is support, spreading the info and to know he is NOT ALONE. He has stated to me that he is not concerned with prison, but rather the security of his countries citizens. I think to call that fair is an understatement. Will you help?
  17. Legacy
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement