Top Banner
35

Common security pitfalls of banking and financial applications

Apr 21, 2017

Download

Internet

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Common security pitfalls of banking and financial applications
Page 2: Common security pitfalls of banking and financial applications

Page 3: Common security pitfalls of banking and financial applications
Page 4: Common security pitfalls of banking and financial applications

Page 5: Common security pitfalls of banking and financial applications
Page 6: Common security pitfalls of banking and financial applications

References:

http://www.sfchronicle.com/business/article/Friendly-hackers-ignored-when-pointing-out-bugs-6647673.php

https://www.sec-consult.com/fxdata/seccons/prod/downloads/sec_consult_capgemini_study_application_security_for_cbs_201210_v101.pdf

Page 7: Common security pitfalls of banking and financial applications
Page 8: Common security pitfalls of banking and financial applications

References:

http://hackingdistributed.com/2014/04/06/another-one-bites-the-dust-flexcoin/

https://www.reddit.com/r/Bitcoin/comments/1wtbiu/how_i_stole_roughly_100_btc_from_an_exchange_and/

http://sakurity.com/blog/2015/05/21/starbucks.html

https://bitcointalk.org/index.php?topic=499580

https://defuse.ca/race-conditions-in-web-applications.htm

Page 9: Common security pitfalls of banking and financial applications
Page 10: Common security pitfalls of banking and financial applications

Page 12: Common security pitfalls of banking and financial applications

Polish Zloty Euro Rounded Resulting

conversion

rate PLN-

EUR

4.38 1 1 0.22831

(official)

0.01 0.0022 0.00 WE LOSE

0.02 0.0045 0.00 WE LOSE

0.03 0.0068 0.01 0.33333

0.04 0.0091 0.01 0.2500

… … … …

0.08 0.0182 0.02 0.28571

0.09 0.0205 0.02 0.28571

Page 13: Common security pitfalls of banking and financial applications

Page 14: Common security pitfalls of banking and financial applications

Page 15: Common security pitfalls of banking and financial applications

References:

http://www.exploringbinary.com/php-hangs-on-numeric-value-2-2250738585072011e-308/

http://www.exploringbinary.com/java-hangs-when-converting-2-2250738585072012e-308/

Page 16: Common security pitfalls of banking and financial applications
Page 17: Common security pitfalls of banking and financial applications

Page 18: Common security pitfalls of banking and financial applications

Page 19: Common security pitfalls of banking and financial applications
Page 20: Common security pitfalls of banking and financial applications

Page 21: Common security pitfalls of banking and financial applications

• ツ

Page 22: Common security pitfalls of banking and financial applications

Page 23: Common security pitfalls of banking and financial applications

Page 24: Common security pitfalls of banking and financial applications
Page 25: Common security pitfalls of banking and financial applications

Page 26: Common security pitfalls of banking and financial applications

Page 27: Common security pitfalls of banking and financial applications

Page 28: Common security pitfalls of banking and financial applications

Page 30: Common security pitfalls of banking and financial applications

Page 31: Common security pitfalls of banking and financial applications

Page 32: Common security pitfalls of banking and financial applications

Page 33: Common security pitfalls of banking and financial applications
Page 34: Common security pitfalls of banking and financial applications

Page 35: Common security pitfalls of banking and financial applications