Wednesday, May 23, 2012 | 10:37:04 PM
Home | About Us | Privacy Policy | Editorial | Contact Us | Feedback | Anonymous Tip | Advertise | In The Press | RSS
Nose for news? Techgoss pays Rs. 1000 for 250-word news items, photos. Anonymity Guaranteed. Email Editor.     
Just GossComment | 

ICICI email to blog
By Bala Shah

What happens when a well meaning security expert finds a flaw in the computing system of one of India’s most successful banks - ICICI?  CTO Yash, like all responsible security experts, had taken steps to ensure that the code to hack this weakness was not available to the wrong people.

The Bank, instead of thanking him and fixing the problem, sent Yash an email asking him to remove his findings from his blog.

Yash, on his blog, gives an overview of how the virus works on ICICI Online Banking

“ 
Disclaimer:  Author takes no responsibility for any actions with provided information

I have developed a proof-of-concept virus to attack the ICICI Online banking using the Man-in-Middle / Man-in-Browser attack method. I am releasing a video (of only 8 minutes) to show what an attack can do to an online banking customer who uses ICICI online banking facility and how it can result in financial loss. I am not releasing the source code or the binaries of the virus to prevent any kind of misuse from black hat hackers.

This video shows how virus can control your Internet explorer and manipulate ICICI Bank transactions in real time. The user is unaware that a virus is running, he logs into ICICI Online bank and performs an online transaction, the virus modifies the destination payee information in real-time and redirects the fund to an attacker account without the knowledge of the user.  The same virus can be extended to any browser.

Cyber law expert Na.Vijayashankar, also known as Naavi in Cyberspace, is one of the most respected names in the Indian tech and online world.  As Chairman of the Digital Society Foundation and as a Director of Cyber Law College, one of Naavi’s life mottos is “Let’s build a responsible Cyber society”.  His views are highly regarded and he is regularly quoted by Indian media.

Naavi has revealed that ICICI sent this security expert Yash an email requesting removal of the content failing which legal action was threatened.


(12/23/2011)
Comments
ICICI Bank Care at 12/23/2011 10:07:08 PM
Hi, The false and misleading 'proof of concept' mentions the exploit by a Trojan (man in the middle/man in the browser) which attacks a user’s computer. It is evident that the author has no understanding of the Bank's security controls and processes on the internet banking portal. The Bank has identified and adequately dealt with such a risk & provided for mitigating controls (which have also been checked through independent sources) and takes this opportunity to reassure its internet banking customers of the safety and security of the Bank's internet banking portal. Hence, this 'proof of concept' is totally baseless and misleading, and done with some ulterior motives. The author is a software developer & has published similar content for other banks as well and appears to be seeking attention for own gains.” Regards, ICICI Bank Team
PrintE-MailDiscussDiggFacebookSaveWrite to Editor
Techgoss Team

Editor: DJ Varma
Email | MSN Messenger

Reporters:
Bala Shah,Nitin Paul,Yasmin Ahmed

Anonymous Tip: Email

Feedback Letters: Email


 
 
Copyright 2010 Techgoss.com
Our Technology Partner: 
Best Viewed in resolution 1024 x 768 pixels