generating the responses

21
eBanking: Genera,ng The Responses by k1m0ch1’s Denpasar, 16 Oktober 2010

Upload: idsecconf

Post on 27-Jun-2015

770 views

Category:

Technology


0 download

DESCRIPTION

k1m0ch1 - Ebanking: Generating The Responses

TRANSCRIPT

Page 1: Generating the responses

eBanking:    Genera,ng  The  Responses  

by    k1m0ch1’s  

                               Denpasar,  16  Oktober  2010  

Page 2: Generating the responses

Who  are  us  ?  

•  k1mOch1  (    [email protected]  )  •  Anton  hilman  (  [email protected]  )  

10/15/10

Page 3: Generating the responses
Page 4: Generating the responses

  Sesuai Peraturan Bank Indonesia No. 9/15/PBI/2007 tentang penerapan manajemen resiko dalam penggunaan teknologi informasi oleh bank umum, maka diperlukan audit terhadap aplikasi perbankan untuk menjamin keamanan nasabah dalam melakukan kegiatan perbankan.

  “Security Token” sebagai pengaman tambahan bagi aplikasi perbankan, terutama bagi aplikasi transaksi finansial.

Page 5: Generating the responses

Menurut  wikipedia,  bentuk  dari  Security  Token  diantaranya  adalah  :    

Page 6: Generating the responses
Page 7: Generating the responses
Page 8: Generating the responses
Page 9: Generating the responses

Prinsip  dari  Mobile  Token  

Page 10: Generating the responses

“Two  Factor  Authentification  Security  Device”  

Page 11: Generating the responses

“Something  You  Know…    Something  You  Have…    Something  You  Are…”  

Page 12: Generating the responses

“Challengen  and  Response”    (C/R)  Mode  for  Authentification  

Page 13: Generating the responses

   Weak  Algorithm     Response  tidak  OTP     Easly  decompile  

Page 14: Generating the responses

Decompile  

Page 15: Generating the responses

Alternatif  Solusi  Pengamanan  

Page 16: Generating the responses

Obfuscated  Code  

Page 17: Generating the responses

Encrypted  Jar  or  Class  

  Use  a  tools  to  encrypt  jar  file    Easier    than  obfuscated       

Page 18: Generating the responses

Parameter  Setting  pada  Server  

Page 19: Generating the responses
Page 20: Generating the responses
Page 21: Generating the responses