发新话题
打印

[转载]The Unbearable Lightness of PIN Cracking

[转载]The Unbearable Lightness of PIN Cracking

原始链接:http://www.arx.com/documents/The ... of_PIN_Cracking.pdf

We describe new attacks on the financial PIN processing API. The attacks apply to switches as well as to verification facilities. The attacks are extremely severe allowing an attacker to expose customer PINs by executing only one or two API calls per exposed PIN. One of the attacks uses only the translate function which is a required function in every switch. The other attacks abuse functions that are used to allow customers to select their PINs online. Some of the attacks can be applied on a switch even though the attacked functions require issuers keys which do not exist on a switch. This is particularly disturbing as it was widely believed that functions requiring issuers keys cannot do any harm if the respective keys are unavailable.

附件

The_Unbearable_Lightness_of_PIN_Cracking.rar (161 KB)

2006-11-21 23:05, 下载次数: 98

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题