4 ms·
The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parame
by bdonlan 9y ago
The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.
- idbehold 9y agoMaybe the bank should've used this method to prevent the problem in the first place by just checking that the referer request header was from their domain.
- brianwawok 9y agoIs it proven anywhere that it wasn't?
- lightbyte 9y agoThe article mentions that unauthorized transactions were indistinguishable from legit ones: >Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitemate transactions.
- lallysingh 9y agoThey may have not been logging referrers.
- palunon 9y agoYou can spoof referrers, you just need some browser extension (or, if using python and requests, doing requests.get(url, headers={'referer': my_referer}) )
- lightbyte 9y agoThe article covers this: >Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitemate transactions.
- MichaelGG 9y agoThat doesn't really matter that much. The customer would have to show they were harmed. So if you were playing around with certain stocks, decided you didn't like the outcome and are now going to sue, you'll need to provide some proof that you didn't make that transaction. If you kept buying and selling on that account, including with the supposedly-hacked-purchased shares, you'd need to explain why you didn't bring it up until now.