mrx - adt: it's not about faking the approval

21
Asian Digital Thief : It’s not about faking the approval Asian Digital Thief : It’s not about faking the approval MrX @ IDSECCONF2009 MrX @ IDSECCONF2009

Upload: idsecconf

Post on 06-Jul-2015

365 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: MrX - ADT: It's not about Faking the Approval

Asian Digital Thief : It’s not about faking the approvalAsian Digital Thief : It’s not about faking the approvalMrX @ IDSECCONF2009MrX @ IDSECCONF2009

Page 2: MrX - ADT: It's not about Faking the Approval

AgendaAgenda

• Intro• Who are they?• Prevention Methods• Case Studies• Conclusions• Q&A

Page 3: MrX - ADT: It's not about Faking the Approval

Intro

Page 4: MrX - ADT: It's not about Faking the Approval

IntroIntro

• Hi Tech = Lazy• Cyber Crime Increased• Internet Fraud Still Exist

Page 5: MrX - ADT: It's not about Faking the Approval

Who are they?

Page 6: MrX - ADT: It's not about Faking the Approval

Who are they?Who are they?

• Credit Card Fraudster• Suppliers (crackers/phisers/scammers)• Proxy Providers• Drop Point / Reshippers

Page 7: MrX - ADT: It's not about Faking the Approval

Prevention Methods

Page 8: MrX - ADT: It's not about Faking the Approval

Prevention MethodsPrevention Methods

• SSL• AVS• 3D Secure• Automate Fraud Detection• Blocking Transaction from High Risk Country• System Hardening

Page 9: MrX - ADT: It's not about Faking the Approval

SSLSSL

• SSL is good, but it’s not everything.

Page 10: MrX - ADT: It's not about Faking the Approval

AVSAVS

• Definition• Advantage• Facts

– Not globally supported– Still can bypassed– System Abuse

• Solution

Page 11: MrX - ADT: It's not about Faking the Approval

3D Secure3D Secure

• Definition• Advantage• Facts

– Weak Password– Expensive– Still can bypassed– Miss configuration– User vulnerable to phising attack

• Solution

Page 12: MrX - ADT: It's not about Faking the Approval

Automate Fraud DetectionAutomate Fraud Detection

• Definition• Advantage• Facts

– Still can bypassed with proxies– Easier for Fraudster

• Solution

Page 13: MrX - ADT: It's not about Faking the Approval

Blocking Transaction from High Risk Country Blocking Transaction from High Risk Country

• Definition• Advantage• Facts

– No Manual Check– Drop Point– Jump Shipment

• Solution

Page 14: MrX - ADT: It's not about Faking the Approval

System HardeningSystem Hardening

• Definition• Advantage• Facts

– OS & Network Hardening– Backdooring Source Code– “Cracked” Web Application

• Solution

Page 15: MrX - ADT: It's not about Faking the Approval

Case Studies

Page 16: MrX - ADT: It's not about Faking the Approval

Case StudiesCase Studies

• SSL is not everything• 3D Secure• Security Conference?

Page 17: MrX - ADT: It's not about Faking the Approval

Conclusions

Page 18: MrX - ADT: It's not about Faking the Approval

ConclusionsConclusions

• 100% Secure System?• Manual Check still needed• Internet Fraud = Never Ending Crime

Page 19: MrX - ADT: It's not about Faking the Approval

Q&A

Page 20: MrX - ADT: It's not about Faking the Approval

• UAI• Depkominfo• Maxindo Mitra Solusi• Nimhost

Page 21: MrX - ADT: It's not about Faking the Approval

kthxbai!!