Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] http://www.chase.com/ vulnerability |
|---|---|
| Date: | Sat, 29 May 2004 11:22:11 -0400 |
"James Patterson Wicks" <pwicks@oxygen.com> writes:
The Chase home page has been like this for over a year. I was a bit worried after the change, so I just bypassed it. If you feel more secure logging in on an SSL page, just do the following:
You can also just go to https://chaseonline.chase.com/ -- that's not the point. The point is that at the very least, they're training their users to follow a very dangerous behavior -- entering passwords into forms downloaded via untrusted paths. They're even telling their users this is absolutely riskless by putting a lock icon right on the front page and having a FAQ that explains that your password is totally protected so you have nothing to worry about -- which is, of course, untrue since there is no guarantee that their front page has not been tampered with.
Since Chase changed this page over a year ago, I'm sure we would have heard something if the Chase site was being exploited.
First, I doubt we would have heard anything. Chase might not even know, for one thing -- I doubt they investigate cases of password theft very deeply. Second of all, even if it hasn't been exploited yet, it is inviting trouble. For years people scoffed when I'd say "the idea of .exe archive/installer files is terrifying. Microsoft is training its users to run programs sent in email, and some day they're going to reap the whirlwind." Well, eventually, someone decided to exploit that stupidity. Some day, some gang is going to start ripping of customers of Chase, American Express, Wells Fargo, and other companies that are perpetuating this foolishness, and then everyone is going to be absolutely shocked that it is happening. Of course, the trivial thing to do would be to simply follow the example of other banks, like Citibank, that force you to enter your password in only on an https: protected page. -- Perry E. Metzger perry@piermont.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] Re: rsynd-too-open.c posted on fd is backdoored. Don't run it!!!, Cory Donnelly |
|---|---|
| Next by Date: | Re: [Full-Disclosure] Pentesting an IDP-System, evilninja |
| Previous by Thread: | RE: [Full-Disclosure] http://www.chase.com/ vulnerability, James Patterson Wicks |
| Next by Thread: | Re: [Full-Disclosure] http://www.chase.com/ vulnerability, http-equiv@excite.com |
| Indexes: | [Date] [Thread] [Top] [All Lists] |