Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 4th, 2013, 15:46 GMT · By

BLOG

Experts Hack Audio Tokens Used by African Banks

SHARE:

Adjust text size:


Experts find way to predict audio tokens used by African banks Enlarge picture - Experts find way to predict audio tokens used by African banks
Researchers Shingirayi Padya and Graeme Neilson of Aura Information Security have found a way to hack the audio one-time passwords used by many African banks to protect their customers against fraudsters.

While most financial institutions rely on applications or SMSs to send their customers one-time passwords when performing online transactions, African banks rely on audio tokens because SMS technology is not active and smartphones are not available for everyone.

The experts have managed to bypass the security mechanisms after they determined that the audio tokens could be predicted and played back to the online banking system to confirm a transaction, SC Magazine reports.

Furthermore, they have even demonstrated how cybercriminals could exploit the vulnerabilities they have uncovered for mass attacks.

For this purpose, they hacked into the victims’ voice mail and replaced the greeting messages with the audio token. When the verification call is made, the token is played back to the bank.

Then, all the attacker needs to do is to keep the line busy or set up a diversion to ensure that the bank goes to voicemail.

The slideshow presented by the experts at Kiwicon 6 is available here.

TELL US WHAT YOU THINK:

1,165 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Symantec on The New York Times Attacks: Antivirus Software Alone Is Not Enough

Incident Response Is Only the First Step in Proactive Threat Mitigation, Experts Say

Cisco to Acquire Prague-Based Cognitive Security

McAfee: 631 Botnet Command and Control Servers Currently Active in the US

New DDOS Tools: Server-Based Botnets and Encrypted Layer Attacks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM