메뉴 건너뛰기

XEDITION

Board

Using nothing more than guesswork, hackers can figure out all of the details on your credit card in just six seconds.

This includes the card number, expiration date, and the security code for any Visa credit or debit card.

Hackers can automatically generate variations of the security data and try them on multiple websites until they get a 'hit,' and experts warn such an attack is 'frighteningly easy' to carry out.

Using nothing more than guesswork, hackers can figure out all of the details on your credit card in just six seconds.

bestccshop-200103065944-thumbnail-3.jpgThis includes the card number, expiration date, and the security code for any Visa credit or debit card. Stock image 

HOW TO MINIMIZE IMPACT OF A CREDIT CARD HACK

According to the researchers, there's no 'magic bullet' against these types of attacks.

Instead, customers should take steps to minimize the impacts of such an attack in case they become a target.

Dr Martin Emms, of Newcastle University, recommends using just one card for online payments, and keeping the spending limit as low as possible.

For a bank card, the expert says you should keep the available funds at a minimum, and transfer money over when necessary.

 

On top of this, the researcher says card holders should be 'vigilant' with their statements and balance to look out for any unusual activity. 

Advertisement


In a new study, published to the journal IEEE Security & Privacy, researchers investigated an attack known as the Distributed Guessing Attack, which is thought to be responsible for the recent Tesco cyberattack, used to defraud customers of millions of dollars last month.

This can get past all of the security features that are set up in order to block online fraud, and according to the team from Newcastle University, it is 'frighteningly easy if you have a laptop and an internet connection.'

In a Distributed Guessing Attack, hackers make many attempts using automatically and systematically generated variations of security data across multiple websites.

Once they get a 'hit,' which can happen within seconds, they can then verify the data.

According to the team, the study revealed a major flaw within the Visa payment system: neither the network nor the banks were able to detect the attackers, despite multiple invalid attempts.

And with the holiday shopping season underway, they say the risk is at its highest.

'This sort of attack exploits two weaknesses that on their own are not too severe but when used together, present a serious risk to the whole payment system,' says lead author Mohammed Ali, a PhD student in Newcastle University's School of Computing Science.

As the current payment system does not detect the attempts from the different websites, the hackers are able to carry out unlimited guesses for each data field, the Ali explains.

Each site allows a given number of attempts, typically 10 or 20, and hackers can use these up until they get the right combination.

Along with this, different websites ask for different variations on the data fields to validate online purchases, meaning 'it's quite easy to build up the information and piece it together like a jigsaw,' Ali explained.

HOW A DISTRIBUTED GUESSING ATTACK WORKS

The study revealed a major flaw within the Visa payment system: neither the network nor the banks were able to detect the attackers, despite multiple invalid attempts.

MasterCard's centralized network, on the other hand, was able to detect the guessing attack after less than 10 attempts, even when distributed across multiple networks, Ali explains. 

But, these attacks are able to obtain information one field at a time, as different online merchants ask for different information.  

'Most hackers will have got hold of valid card numbers as a starting point, but even without that it's relatively easy to generate variations of card numbers and automatically send them out across numerous websites to validate them,' Ali says.

'The next step is the expiry date.

Banks typically issue cards that are valid for 60 months so guessing the date takes at most 60 attempts.

'The CVV is your last barrier and theoretically only the card holder has that piece of information - it isn't stored anywhere else.

'But guessing this three-digit number takes fewer than 1,000 attempts.

Spread this out over 1,000 websites and one will come back verified within a couple of seconds. And there you have it - all the data you need to hack the account.'

Advertisement


'The unlimited guesses, when combined with the variations in the payment data fields make it frighteningly easy for attackers to generate all the card details one field at a time,' the researcher says.

'Each generated card field can be used in succession to generate the next field and so on. 

'If the hits are spread across enough websites then a positive response to each question can be received within two seconds - just like any online payment.

'So even starting with no details at all other than the first six digits - which tell you the bank and card type and so are the same for every card from a single provider - a hacker can obtain the three essential pieces of information to make an online purchases within as little as six seconds.'

While online payments require the customer to provide that only the cardholder would know, the researchers say it is simple to carry out ‘jigsaw' identification unless all merchants ask for the same information.

Hackers can automatically generate variations of the security data and try them on multiple websites until they get a 'hit,' and experts warn such an attack is 'frighteningly easy' to carry out.

In the event you beloved this informative article and you would want to acquire more information relating to Dumps Free 2021 generously stop by the web site. A stock image is pictured 

And, there's no sure way to prevent these types of attacks.

‘Sadly there's no magic bullet,' says Dr Martin Emms, co-author on the paper.

‘But we can all take simple steps to minimize the impact if we do find ourselves of a hack.

For example, use just one card for online payments and keep the spending limit on that account as low as possible.

‘If it's a bank card then keep ready funds to a minimum and transfer over money as you need it.

‘And be vigilant, check your statements and balance regularly and watch out for odd payments.

‘However the only sure way of not being hacked is to keep your money in the mattress and that's not something I'd recommend.' 

번호 제목 글쓴이 날짜 조회 수
10981 China Jersey Shop Chicago Bears Aim To Sell Brandon Marshall RyderCartledge25115 2021.10.11 4
10980 Comment Rencontrer Des Femmes Célibataires Et Sortir Du Célibat ? EnnerickMarturier8 2021.10.11 4
10979 Agen Judi Slot Online Terpercaya - Restoslot4d ZandraFitzmaurice7 2021.10.11 2
10978 Cheap NFL Jerseys From China Chief Protection Guard -Thornhill Is Usually Expected To Take Part In The Training Camp RogerHolbrook40 2021.10.11 2
10977 Buying An Excellent Weight Loss Nutrition Plan EQWIsidro275244225243 2021.10.11 4
10976 Web-site Judi Slots Online Paling Dipercaya Mendatangkan Bermacam Ragam Games Slots Terkomplet Dan Paling Banyak Di Indonesia ChristiePineda9 2021.10.11 1
10975 6 Methods To Receive The Most Effective Out Of Your New Portable Translator SeanHarriman943565 2021.10.11 3
10974 Nfl Jersey For Sale How To Learn To Cheap Jerseys In 1 Hour FinlayMartinsen22621 2021.10.11 3
10973 Atlanta Falcons Jerseys For Sale Simian Confirms The Absence Associated With The Mustangs In Order To End The Game, Lynch Will Begin MarylinBarbee8882122 2021.10.11 2
10972 Effective Weight Loss Perks That Transcend Slimming JohannaKennion47 2021.10.11 3
10971 Le Viagra Facilite Le Processus D’érection Lamri90146658981389 2021.10.11 2
10970 Metode Menggapai Jekpot Pada Permainan Slots Online Clarice7434000151015 2021.10.11 1
10969 The Secret Life Of Air Max 270 MaximoMurillo4659 2021.10.11 1
10968 Mengecek Informasi Game Slot On The Web Sebelum Dimainkan BroderickPuglisi28 2021.10.11 1
10967 Convey More Enjoyable Actively Playing Games By Using These Tips SybilMcgrew0659 2021.10.11 3
10966 Диплом Вуза SwenLongwell3706433 2021.10.11 2
10965 The Smart Trick Of Dofollow Backlinks That No One Is Discussing MaryjoPicot08716 2021.10.11 6
10964 Cheap Jerseys Free Shipping At The End Of The Period, The Jet May Well Part Ways With The Island King OttoGagai42651455301 2021.10.11 4
10963 10 Pemain Akademi Manchester United Yang Ikut Pramusim Jamey16Y20343362 2021.10.11 3
10962 Nike Nfl Jerseys Adrian Peterson Still Hopes To Hit Emmet-His Mies Record AgustinAlder640399193 2021.10.11 1
위로