Penetration Testing mailing list archives

Re: [PEN-TEST] Home-Banking PEN-TESTING


From: Erik Tayler <nine () 14X NET>
Date: Tue, 22 Aug 2000 19:21:35 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I do not believe the bank even has the right to have you test
personal computers that are housed in a residence. Ask a lawyer to be
certain, but that seems like a large invasion of privacy. I have
previously used home-banking, and I would be furious if my bank hired
people to break into my home network. I think one could consent to
such a service, I am not saying it is un-performable, but it sounds
like a pain to get such permission from everyone subscribing to the
home-banking system. Sniffing someone while they are transferring
sensitive information is just as effective as breaking into their
network/pc. None of what I just said is of any relevance if you are
not referring to the consumers that actually access the bank via
modem or web-interface to view their financial data.

Erik Tayler
14x Network Security
http://www.14x.net

- ----- Original Message -----
From: "Rafael Coninck Teigao" <rafael () SAFECORE NET>
To: <PEN-TEST () SECURITYFOCUS COM>
Sent: Monday, August 21, 2000 5:31 PM
Subject: Home-Banking PEN-TESTING


Hi, ppl.
    I'm pen-testing a home-banking system. My client has a doubt
and we basically disagree in some level: is the client's machine of
the
responsibility of the bank? I mean, if I can break the client's
machine and steal useful information from it (passwords, account's
data, etc.), is the bank responsible, having in mind that it's
programmers can fix the problem (they just don't do it 'couz it is
costly)?
    Let me hear what you think.

    []'s,
    RCT.

--
--------------------------------------------------------------------
----------- And the Raven, never flitting, still is sitting, still
is sitting
On the pallid bust of Pallas just above my chamber door;
And his eyes have all the seeming of a demon's that is dreaming,
And the lamp - light o'er him streaming throws his shadow on the
floor; And my soul from out that shadow that lies floating on the
floor
Shall be lifted - nevermore!
        E. A. Poe --> The Raven (c1845)
--------------------------------------------------------------------
-----------

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBOaMZDU0pQlPl0B0AEQJ+FACgrkKN2IDyA4bPvKWMniFXu8ufyGMAoIKx
nQOlb94j7xRHlDW1S8WvVzaz
=2uxF
-----END PGP SIGNATURE-----


Current thread: