Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Security Australia Crime The Almighty Buck

Memory Gaffe Leaves Aussie Bank Accounts Open To Theft 69

mask.of.sanity writes "A researcher has found flaws in the way major Australian banks handle customer login credentials which could allow the details to be siphoned off by malware. He built proof of concept malware to pull unencrypted passwords, account numbers and access credentials from volatile memory of popular web browsers every two hours."
This discussion has been archived. No new comments can be posted.

Memory Gaffe Leaves Aussie Bank Accounts Open To Theft

Comments Filter:
  • by jonwil ( 467024 ) on Saturday June 01, 2013 @01:29AM (#43881089)

    My bank uses POST in the login form which means that sniffing memory for URLs (which is what this malware seems to do) wont get you a login.
    Plus, in order to actually transfer money to someone you haven't transferred money to before you have to input a second password.

    The biggest failing of the bank in question is that it has a 10 char maximum on passwords for some stupid reason.

There are two ways to write error-free programs; only the third one works.

Working...