Уровень 0 · материалов: 5
В кластер включаются документы о конкретных технических уязвимостях в банковских интерфейсах и API, приведших к утечке данных, и исключаются любые общие обсуждения кибербезопасности без привязки к эксплойтам в финансовых системах.
Общие признаки: критические ошибки безопасности, несанкционированный доступ к данным клиентов, уязвимости API, проблемы контроля доступа, программы Bug Bounty
Группа выше: Уязвимости финансовых и мобильных приложений
Смысл: The main idea is that a significant security flaw (Insecure Direct Object Reference) was found in Alfa-Bank's mobile app, allowing unauthorized access to other clients' statements, highlighting the need for better access control and a formal bug bounty program.
A security researcher discovered a vulnerability in Alfa-Bank's mobile app that allowed viewing any customer's statements by simply changing an ID number.
Смысл: The main idea is the exposure of critical security flaws in Rocketbank's system that allowed for data theft and phishing, as well as the bank's inconsistency regarding its public commitment to a Bug Bounty program.
A security researcher uncovered XSS and data leakage vulnerabilities in Rocketbank, which the bank quickly patched but initially refused to reward despite their public Bug Bounty policy.
Смысл: The main idea is to expose a critical security vulnerability where Tinkoff Bank allowed unauthorized access to private client account statements via unauthenticated direct links, potentially violating banking secrecy laws.
Tinkoff Bank exposed private client account statements by providing direct, unauthenticated download links in emails, creating a major security breach.
Смысл: The text highlights a critical API vulnerability where insufficient validation allowed unauthorized users to deduce card balances, emphasizing the importance of secure API design and the effectiveness of public disclosure in prompting corporate action.
A security researcher discovered a flaw in Tinkoff Bank's card transfer service that allowed anyone with a card number to find the card's balance, leading the bank to fix the bug and start a bug bounty program.
Смысл: The text illustrates how a lack of authentication on a seemingly 'public' API endpoint can lead to large-scale data scraping and privacy violations, challenging the notion that data visible in a UI is inherently non-sensitive.
A security researcher discovered an unauthenticated API in the Citymobil app that allows for the real-time tracking of all active drivers in a city.