Sampath Vishwa allows brute Forces

Jack_Sparrow

Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    I forgot my Sampath Vishwa password then i did for tried 6 times, finally website indicates that my user id is blocked... They have manual tedious procedure to reset accounts which has to be done by filling forms and submitting :baffled::oo:

    However i was curious then i tried an user name such as "dsfgsdfds" and then it prompts you have 5 more attempts. then i again tried it it keeps prompting 5 attempts (i doubt that this happens when particular user is not existing)

    cool thing is every time i try new username it gives me five attempts.. It does not block my IP at all...

    So how about if someone tried a Brute force attack on every possibility of usernames (more than 6 characters) and starts freezing Sampath customers Vishwa accounts :P (Simple freezer like GroundZero's Facebook Freezer could do it, thing is in fb you can reset pasword easily with email)

    Any comments or arguments weather its not possible with this site :rolleyes:
    If anyone works at sampath please inform your IT ;)
     

    radiax

    Well-known member
  • Dec 9, 2007
    8,679
    985
    113
    සුන්දර හදවතක..-NRJ-
    i have sampath vishwa too. mahan i think its for safety reasons. i never experienced this as i always remember my pass :P
    clearly it doesnt block IP but the user ID. no use of blocking IP attacker could use another IP.
    only down side is i can block your account if i know your user ID. :rofl:
    they should introduce quick and hassle free way to reset password.
    but this method is way secure :D
     

    moonrock

    Member
    Sep 1, 2013
    3,024
    202
    0
    you are an idiot for posting something like this in a public forum. you should have informed them(sampath bank) instead of exposing a critical issue like this in their system and let hackers to mess up with accounts of innocents users. users can do nothing so why did you reveal such a crucial information in here? what is the point?
     

    Jack_Sparrow

    Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    i have sampath vishwa too. mahan i think its for safety reasons. i never experienced this as i always remember my pass :P
    clearly it doesnt block IP but the user ID. no use of blocking IP attacker could use another IP.
    only down side is i can block your account if i know your user ID. :rofl:
    they should introduce quick and hassle free way to reset password.
    but this method is way secure :D

    so attacker can grab two or three user names repeat this and get block these users thats the point is ;) so sampath should have way to easily reset this with a mobile or email :) thats how big giants like FB , google fo :)

    you are an idiot for posting something like this in a public forum. you should have informed them(sampath bank) instead of exposing a critical issue like this in their system and let hackers to mess up with accounts of innocents users. users can do nothing so why did you reveal such a crucial information in here? what is the point?

    If i inform them will they give me an award or hire me for their software engineering team :shocked: hell no they will say ok we will consider and their IT team will not accept their fault, but they will secretly fix it :P
     

    moonrock

    Member
    Sep 1, 2013
    3,024
    202
    0
    so attacker can grab two or three user names repeat this and get block these users thats the point is ;) so sampath should have way to easily reset this with a mobile or email :) thats how big giants like FB , google fo :)



    If i inform them will they give me an award or hire me for their software engineering team :shocked: hell no they will say ok we will consider and their IT team will not accept their fault, but they will secretly fix it :P

    yeah they will surely fix it and that's the point of my comment and that's what should be happened.
     

    kosandpol

    Well-known member
  • Jun 10, 2008
    45,329
    1,492
    113
    haha exactly cripple the service for valuable customers and they all have to fill forms :rofl: I don't know why they don't allow recover options from emails :baffled:
    because this method is hacker proof. Only the account owner can reset pw or request access change to his account.
     

    kosandpol

    Well-known member
  • Jun 10, 2008
    45,329
    1,492
    113
    I'm a sampathvishwa user. My user name is JesonRulez. Now I'm done! :( :(
    effin' LOLZ!!

    should've thought about that before becoming a Statham fanatic :P

    Though in all seriousness, what you said just proves another security concern. Do NOT use the same username everywhere. Especially ones that are used in public sites.
     

    Jack_Sparrow

    Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    yeah they will surely fix it and that's the point of my comment and that's what should be happened.

    as a software engineer we are also developing applications and we also have loopholes and errors, but we need to accept our mistakes. For a security engineer (not a software engineer) these are very primitive things he should detected at first place.

    because this method is hacker proof. Only the account owner can reset pw or request access change to his account.

    yeah you are correct its hacker proof online, how about mobile subscription get a SMS?
     

    Jack_Sparrow

    Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    LOL ... මම 2003 ඉඳන් sampath vishwa use කරනව ... දැන් අවුරුදු 10ක් තිස්සෙ ඔය අවුල repeat වෙනව :rofl:

    sirawata from 2003 machan did you report them? :baffled:
    doubt that they still use old SSL already broken channels and encryption algorithms :oo:
     

    kosandpol

    Well-known member
  • Jun 10, 2008
    45,329
    1,492
    113
    as a software engineer we are also developing applications and we also have loopholes and errors, but we need to accept our mistakes. For a security engineer (not a software engineer) these are very primitive things he should detected at first place.



    yeah you are correct its hacker proof online, how about mobile subscription get a SMS?
    this method is still safer. if the phone gets stolen, someone can still access the account. This way, unless the hacker changes his face and get a counterfeit ID card, is impossible to fool.
     

    mldarshana

    Well-known member
  • Apr 2, 2007
    34,059
    1,404
    113
    ආශ්චර්ය අභියස :nerd:
    sirawata from 2003 machan did you report them? :baffled:
    doubt that they still use old SSL already broken channels and encryption algorithms :oo:

    ඔව් බන් මම Manager කෙනෙක්ටත් කිව්ව ඒ කාලෙම ... තව ඕකෙ IT devision එකේ වැඩ කරන යාළුවෙක්ට කිව්වම ඌ කියපි ...

    "ඔව් බන් ඕක known bug එකක් ... ළඟම තියෙන branch එකකට ගිහිල්ල reset කරගනින්කො" කියල :lol:

    තව ඌ කියනව ඒක security feature එකක්ලු :rofl: ... උන්ගෙ IT ගැන හිතාගනින්කො :dull: