SlideShare a Scribd company logo
1 of 35
Download to read offline
THE
21 ST CENTURY
     BANK JOB
           @GEOVEDI
EVER THOUGHT ABOUT
   ROBBING A BANK?
JOHN DILLINGER   KUSNI KASDUT



OLD SCHOOL
HACKING A BANK
        IS EASY


     ..OR MAYBE NOT!!
CASE STUDIES
MODERN BANK JOBS
CREDIT CARD FRAUD
ATM SKIMMING
SOCIAL ENGINEERING
WHY TARGETING THE USERS?


         &
IT’S EASIER   THEY ARE CLUELESS
                [MOST OF THE TIME]
HOW ABOUT HACKING?
Swordfish (2001)
INSIDE
THE BANK’S
 IT SYSTEM
TRADE FINANCE                     TREASURY
DATA WAREHOUSING

    REMITTANCE            ANTI MONEY LAUNDRING
                                         CRM
                     CORE        ATM SWITCH
 COLLECTION SYSTEM

 INTERNET BANKING             MOBILE BANKING

        ISLAMIC BANKING      CARD MANAGEMENT
EMPLOYEES


                              MANAGEMENT



VENDORS

           NETWORK OF TRUST




  GOVERNMENT
                         CUSTOMERS
STORYTELLING SESSION
  HOW WE COMPROMISED BANKS
       ON SOME PENTEST ENGAGEMENT
COMMON PROBLEMS



PEOPLE PROBLEMS       SYSTEM PROBLEMS
   WEAK PASSWORDS          OUTDATED SYSTEMS
  LACK OF AWARENESS    INSECURE CONFIGURATIONS
    LACK OF SKILLS        INSECURE PROTOCOLS
MANAGEMENT PROBLEMS
MERCHANTS
ATM COMPROMISE
WTFKTHXBYE
WHO’S RESPONSIBLE?
SECURITY RESPONSIBILITY
 BANK                SIBLE
                             BANK            SIBLE
            RE   SPON                  RESPON




                                             SIBLE
                                       RESPON
 CUSTOMER                    CUSTOMER
According to Customer        According to Bank
BANKS’ EFFORTS TO INCREASE THE SECURITY LEVEL
ENCRYPTION
TWO-FACTOR AUTHENTICATIONS
TWO-FACTOR AUTHENTICATIONS
REGULATION COMPLIANCE
REGULAR SECURITY ASSESSMENT
WHAT’S NEXT?
WHAT’S NEXT?
THANKS!
CREDITS:
 Photos:
 •   [Page 01] http://www.flickr.com/photos/reddogfever/4580710899/
 •   [Page 02] http://www.flickr.com/photos/lanuiop/226760877/
 •   [Page 04] http://www.flickr.com/photos/deepblue66/132439533/
 •   [Page 05] http://www.flickr.com/photos/marcelnicolai/4600107436/
 •   [Page 09] http://www.flickr.com/photos/paulwatson/411792788/
 •   [Page 10] http://www.flickr.com/photos/jliba/3696592874/
 •   [Page 11] Swordfish Hack — http://www.youtube.com/watch?v=zfy5dFhw3ik
 •   [Page 12] http://www.flickr.com/photos/skreuzer/354316778/
 •   [Page 13] http://www.flickr.com/photos/tim_d/184018928/
 •   [Page 14] http://www.flickr.com/photos/eskimoblood/2111672366/
 •   [Page 15] http://www.flickr.com/photos/beneathourfeet/2502755729/
 •   [Page 16] http://www.flickr.com/photos/formalfallacy/2057169454/
 •   [Page 16] http://www.flickr.com/photos/dolor_ipsum/3262262008/
 •   [Page 17] http://www.flickr.com/photos/24443965@N08/3460357646/
 •   [Page 23] http://www.flickr.com/photos/kk/4191131924/
 •   [Page 25] http://www.flickr.com/photos/ari/2347593532/
 •   [Page 27] http://www.infosurhoy.com/cocoon/saii/images/2010/03/01/photo4.jpg
 •   [Page 28] http://en.wikipedia.org/wiki/File:CryptoCard_two_factor.jpg
 •   [Page 29] http://blogs.ft.com/gapperblog/files/2008/03/bank-regulation.jpg
 •   [Page 30] http://www.flickr.com/photos/dfarrell07/5013882149/
 •   [Page 31] http://www.flickr.com/photos/joshmt/2526552173/
@GEOVEDI



          CHECKOUT:
http://slideshare.net/geovedi

More Related Content

Viewers also liked

Hacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT ConnectionHacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT Connection
Jim Geovedi
 
Wireless Hotspot: The Hackers Playground
Wireless Hotspot: The Hackers PlaygroundWireless Hotspot: The Hackers Playground
Wireless Hotspot: The Hackers Playground
Jim Geovedi
 
Hacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to DiscoverHacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to Discover
Jim Geovedi
 
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust RelationshipHacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Jim Geovedi
 
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Jim Geovedi
 
Wireless Hotspot Security
Wireless Hotspot SecurityWireless Hotspot Security
Wireless Hotspot Security
Jim Geovedi
 
Warezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite HackingWarezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite Hacking
Jim Geovedi
 
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Jim Geovedi
 

Viewers also liked (14)

Hacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT ConnectionHacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT Connection
 
Wireless Hotspot: The Hackers Playground
Wireless Hotspot: The Hackers PlaygroundWireless Hotspot: The Hackers Playground
Wireless Hotspot: The Hackers Playground
 
Internet Worms
Internet WormsInternet Worms
Internet Worms
 
Hacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to DiscoverHacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to Discover
 
Is Cyber-offence the New Cyber-defence?
Is Cyber-offence the New Cyber-defence?Is Cyber-offence the New Cyber-defence?
Is Cyber-offence the New Cyber-defence?
 
Professional Hackers
Professional HackersProfessional Hackers
Professional Hackers
 
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust RelationshipHacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
 
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
 
Wireless Hotspot Security
Wireless Hotspot SecurityWireless Hotspot Security
Wireless Hotspot Security
 
Satellite Telephony Security
Satellite Telephony SecuritySatellite Telephony Security
Satellite Telephony Security
 
Warezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite HackingWarezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite Hacking
 
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
 
Cloud Security - Security Aspects of Cloud Computing
Cloud Security - Security Aspects of Cloud ComputingCloud Security - Security Aspects of Cloud Computing
Cloud Security - Security Aspects of Cloud Computing
 
HITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
HITB Labs: Practical Attacks Against 3G/4G Telecommunication NetworksHITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
HITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
 

Similar to The 21st Century Bank Job

Online Banking
Online BankingOnline Banking
Online Banking
Allen Thi
 
Online Banking
Online BankingOnline Banking
Online Banking
Allen Thi
 
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
spirecorporate
 
Курсовая по теме:Использование интернет ресурсов в коммерческих целях
Курсовая по теме:Использование интернет ресурсов в коммерческих целяхКурсовая по теме:Использование интернет ресурсов в коммерческих целях
Курсовая по теме:Использование интернет ресурсов в коммерческих целях
rewaza
 

Similar to The 21st Century Bank Job (20)

The21stcenturybankjob 101014152255-phpapp02
The21stcenturybankjob 101014152255-phpapp02The21stcenturybankjob 101014152255-phpapp02
The21stcenturybankjob 101014152255-phpapp02
 
Digitalisation des Parcours Clients
Digitalisation des Parcours ClientsDigitalisation des Parcours Clients
Digitalisation des Parcours Clients
 
From Online To Digital
From Online To DigitalFrom Online To Digital
From Online To Digital
 
Data Leakage Prevention - K. K. Mookhey
Data Leakage Prevention - K. K. MookheyData Leakage Prevention - K. K. Mookhey
Data Leakage Prevention - K. K. Mookhey
 
Impulse statement: Insights in the FinTech evolution
Impulse statement: Insights in the FinTech evolutionImpulse statement: Insights in the FinTech evolution
Impulse statement: Insights in the FinTech evolution
 
Online Banking
Online BankingOnline Banking
Online Banking
 
Online Banking
Online BankingOnline Banking
Online Banking
 
Redefining Convenience with Mobile Banking
Redefining Convenience with Mobile BankingRedefining Convenience with Mobile Banking
Redefining Convenience with Mobile Banking
 
Credit card fraud detection pptx (1) (1)
Credit card fraud detection pptx (1) (1)Credit card fraud detection pptx (1) (1)
Credit card fraud detection pptx (1) (1)
 
Stu w25 a
Stu w25 aStu w25 a
Stu w25 a
 
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
121010_Mobile Banking & Payments for Emerging Asia Summit 2012_A Risk-Based A...
 
Курсовая по теме:Использование интернет ресурсов в коммерческих целях
Курсовая по теме:Использование интернет ресурсов в коммерческих целяхКурсовая по теме:Использование интернет ресурсов в коммерческих целях
Курсовая по теме:Использование интернет ресурсов в коммерческих целях
 
Online banking serices
Online banking sericesOnline banking serices
Online banking serices
 
Tech developments in banking sector
Tech developments in banking sectorTech developments in banking sector
Tech developments in banking sector
 
Webcast - how can banks defend against fraud?
Webcast - how can banks defend against fraud?Webcast - how can banks defend against fraud?
Webcast - how can banks defend against fraud?
 
Virtual banking
Virtual bankingVirtual banking
Virtual banking
 
The New Banking has to be S.U.P.E.R.
The New Banking has to be S.U.P.E.R.The New Banking has to be S.U.P.E.R.
The New Banking has to be S.U.P.E.R.
 
The Technical Debt Trap - Michael "Doc" Norton
The Technical Debt Trap - Michael "Doc" NortonThe Technical Debt Trap - Michael "Doc" Norton
The Technical Debt Trap - Michael "Doc" Norton
 
Securing the Virtual Branch
Securing the Virtual BranchSecuring the Virtual Branch
Securing the Virtual Branch
 
Tecnologías emergentes y la evolución continua de los pagos electrónicos en l...
Tecnologías emergentes y la evolución continua de los pagos electrónicos en l...Tecnologías emergentes y la evolución continua de los pagos electrónicos en l...
Tecnologías emergentes y la evolución continua de los pagos electrónicos en l...
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 

The 21st Century Bank Job