hindsight is 20/20 - but I'm awefully surprised that this would not be detected by the backend/backoffice systems processing cards.
Matercard supposedly has a single back end but VISA does not, according to the article. Given the distributed nature of the attack I imagine only the card processors could detect it; if you pick sufficiently broad set of web site to test with the chances of them sharing a server that could detect something is probably low.
Criminals can guess Visa number and security code in six seconds, experts find
11–20 of 166 posts
Re: Criminals can guess Visa number and security code in six seconds, experts find
#12Merchants doing everything they can need better protection from this crap.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#13hindsight is 20/20 - but I'm awefully surprised that this would not be detected by the backend/backoffice systems processing cards.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#14There are well-specified rules for coming up with valid credit card account numbers, and at most, say, 60 valid expiration dates (12 months × 5 years into the future). Once an attacker has a valid credit card number and expiration date, there are only 10⁴ = 10,000 four-digit security codes possible, which the attacker tries with parallel requests to hundreds of websites. Each website gives the attacker at least a few…
The data you'd gain from this is practically useless to anyone looking to commit fraud... so laugh at the article I guess? Maybe you could abuse this to create a lot of netflix accounts, but you aren't really going to be able to buy anything with just the PAN/cvv/expiry.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#15There are well-specified rules for coming up with valid credit card account numbers, and at most, say, 60 valid expiration dates (12 months × 5 years into the future). Once an attacker has a valid credit card number and expiration date, there are only 10⁴ = 10,000 four-digit security codes possible, which the attacker tries with parallel requests to hundreds of websites. Each website gives the attacker at least a few…
In the UK they are 3 digits on the back, 3000 is a worse case.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#16hindsight is 20/20 - but I'm awefully surprised that this would not be detected by the backend/backoffice systems processing cards.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#17The power of distributed attacks. Of course they can only guess a random correct credit card + exp + code not yours. Given the relative limited number of codes for each bank, I wonder what the odds are for them to wind up with yours.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#18There are well-specified rules for coming up with valid credit card account numbers, and at most, say, 60 valid expiration dates (12 months × 5 years into the future). Once an attacker has a valid credit card number and expiration date, there are only 10⁴ = 10,000 four-digit security codes possible, which the attacker tries with parallel requests to hundreds of websites. Each website gives the attacker at least a few…
The data you'd gain from this is practically useless to anyone looking to commit fraud... so laugh at the article I guess? Maybe you could abuse this to create a lot of netflix accounts, but you aren't really going to be able to buy anything with just the PAN/cvv/expiry.
Re: Criminals can guess Visa number and security code in six seconds, experts find
#19Earlier quoted context omitted.
In the UK they are 3 digits on the back, 3000 is a worse case.
Isn't that (almost) 1000? All numbers between 001 and 999?
http://m.wolframalpha.com/input/?i=count+of+permutations+of+...
Re: Criminals can guess Visa number and security code in six seconds, experts find
#20The things that needed to match also involved the customers street address, zip and name. If I recall these were scored and if the match wasn't good (zip was entered wrong) the transaction was rejected. Maybe different payment processors have different thresholds for rejecting a transaction?