25 ms·
Also, if there is any sort of timing difference on valid/invalid card numbers. Boom... timing attack / CC oracle :)
by bitexploder 6y ago
Also, if there is any sort of timing difference on valid/invalid card numbers. Boom... timing attack / CC oracle :)
- ev1 6y agoThere's already Luhn and a list of valid starting digits...
- kelnos 6y agoI think the parent meant "card number that actually is in use and works" when saying "valid", not "follows the rules of card numbers".
- sgjohnson 6y agoYes, which aids the spamming. The first 6 digits of a card number is called the BIN code. That leaves just 9 digits that have to be spammed. The fact that BIN lists are publicly available is reducing the space significantly.
- Nextgrid 6y agoI'd expect any submissions to this are just appended to a database without any actual validation beyond the trivial Luhn checksum and then there's a batch process once a day (maybe the same one that actually generates whatever marketing "insights" they claim to provide) that reads from there and ignores any card numbers from the opt-out DB.
- bitexploder 6y agoYou would hope that. I’ve been in infosec doing application security as a consultant a long time. Developers have often destroyed my hopes :)
- vageli 6y ago> You would hope that. I’ve been in infosec doing application security as a consultant a long time. Developers have often destroyed my hopes :) I used to work at a big bank in the US and the parent's description sounds exactly like how it would work.
- earthboundkid 6y agoGovernment and banks have been continuously using computers since the 60s, so as a result there’s a lot of “fancy web API to collect data… that gets batch processed by an ETL on a mainframe overnight.” Much more of it than I realized as a young dev at least.
- bitexploder 6y agoYou could be right but I have found almost this exact bug in production systems (credit card oracle sitting on the public Internet of a big card processor with no rate limiting and a really obvious timing delta). Both scenarios (batch or live processing) are pretty likely IMO. Just depends on what mess of APIs you happen to end up on.
- netsharc 6y agoHuh... create script to fill DB with all possible Visa numbers, tomorrow's "marketing insight" will suddenly be an empty file because everything will be excluded. Bonus, if they can't separate which exclusions were from legitimate requests and which came from this script, they can't just delete those entries from the database. Of course, no one should do this...
- overscore 6y ago> Bonus, if they can't separate which exclusions were from legitimate requests and which came from this script, they can't just delete those entries from the database. I think they would probably just declare them all invalid, and roll back to yesterday.
- chris_wot 6y agoI think that millions of requests from a particular IP address might give the game away.
- jmpman 6y agoPerfect use case for Splunk.
- morpheuskafka 6y agoChecked and the Mastercard one someone posted below doesn't seem to be vulnerable to this. My real card number and a dummy mastercard number with valid prefix and check digit both returned a 200 OK in around 1.01s. A random 16digit number without valid check digit returned 400 Bad Request in about 800ms. Decided to check that one since they have a completely useless machine-readable catchpa. For Visa it was 835ms for valid, 762ms for dummy, prefix and check digit appears to be checked client side.
- bitexploder 6y ago100ms is /massive/ for a timing delta but you really need a lot of samples. I have exploited timing deltas that were not much more than a handful of machine code instructions in terms of execution time. But you really do need a lot of samples to confirm small deltas. It starts getting impractical for many APIs (someone will notice, hopefully).
- texasbigdata 6y agoThis comment is why I love hackernews
- bitexploder 6y agoSee: https://rdist.root.org/2010/07/19/exploiting-remote-timing-attacks/ https://rdist.root.org/2010/07/19/exploiting-remote-timing-a... and Crosby 2007. I got into infosec around 06 and tptacek, Nate Lawson and some others were my heroes. Now I run my own consulting firm with a bunch of cool people :) Also in infosec: what is old is new. We still find shitty comparison routines (timing attacks) and SQL injection... some day :)
- dmix 6y ago> someone will notice, hopefully Or more likely "someone will notice, eventually"
- animex 6y agoI just found a use-case for the sleep( rand(1000) ) function :-)
- TylerE 6y agoCard number alone doesn't get you anywhere. An expiration date will get you a bit farther, but you really need the CVV also.
- notretarded 6y agoWhich would give you worthless information
- dzikimarian 6y agoComing from the industry - MC & Visa typically don't know if exact card is valid or not. They admit range of numbers to an issuer (bank, revolut-type, whatever), and issuers system is queried for each transaction - card can be created at any time without notifying card schemes. There's some exceptions (tokens etc.), but not relevant to this use case.