• Home
  • Exams
    • Exams
    • Punjab Text Book Board
    • Oxford University Press
    • The Educators
    • Allied School System
  • E News
    • Educational News
    • Technology News
    • Other News
    • تعلیمی خبریں
    • ٹیکنالوجی خبریں
    • دیگر خبریں
  • STUDENTS
    • Message for students
    • Online Resources
    • Share an event
    • Become a Volunteer
    • Students Magazine
    • Student Ambasadors
    • Scholarships
  • PARENTS
    • Message For Parents
    • Online Resources
    • Submit articles
    • Scholarships
  • TEACHERS
    • Message for Teachers
    • Online Resources
    • Submit your articles
    • Scholarships
  • INSTITUTIONS
    • Message for Institutions
    • Directory of Educational Institutes
    • Academic Disciplines
  • ABOUT
    • Our Mission
    • Frequently Asked Questions
    • Feedback & Suggestions
    • Login
    • Help
  • Sign Up for Zahanat
Login Help
Sign Up for Zahanat

Money-making machine cashes in on currency trades

November 19, 2013

Pass reader

A money-making machine that exploits rounding errors in currency exchanges in favour of bank customers has been built by a security researcher.

If left to run at its top speed, the device could generate almost 70 euros (£58) a day by carrying out thousands of small transactions.

The device was built to test the security of online banking systems.

However, said experts, banks’ anti-fraud systems would probably prevent the machine cashing in.

Tiny trades

The device was created by Romanian security researcher Dr Adrian Furtuna, who noticed what happened when certain amounts of Romanian leu were exchanged for euros.

These transactions were rounded up in a customer’s favour so they ended up with cash worth slightly more than they started with.

“The trick is that users can choose the amounts that they want to exchange such that the rounding will be always done in their favour,” Dr Furtuna told the BBC.

The amounts involved are so small, 0.005 of a euro, that thousands of transactions are needed to generate a significant amount of money.

Dr Furtuna, who works for KPMG Romania as a penetration tester, set out to see if banks’ online currency trading systems were vulnerable to large scale exploitation of this rounding error.Euros

The machine was needed because many banks use authentication gadgets to secure online transactions.

These devices typically generate a short sequence of numbers that must be entered alongside other credentials when moving or exchanging money online.

He automated the sequence by building a machine that could press buttons on the security device and read the code it generated as part of the authentication process.

The response rate of the device limited the number of transactions that could be carried out, Dr Furtuna told the BBC. At most, he said, it could carry out 14,400 transactions per day. This means, at most, it could generate about 68 euros per day if left to run unchallenged.

So far the device has been only proven to work in the lab, as the bank that asked Dr Furtuna to test its security did not give him permission to try it against its live online banking system.

Separate research had shown that the online systems of at least five banks in Romania might be vulnerable to the money-machine attack, he said. Other banks in other nations might also be susceptible, he added.

“Banks believe that nobody can do a high number of transactions in a feasible time since each transaction requires to be signed using the [authentication] device,” he said. “By building this machine I proved that this assumption is wrong and transactions can be automated with or without an [authenticator].”

Tod Beardsley, a security engineer at Rapid7, said such “salami slicing” attacks were well known, having been depicted in films such as Superman III, Hackers and Office Space.

“Salami slicing attacks are usually illegal, since they usually add up to some kind of bank or tax fraud, or run afoul of anti-money laundering laws,” he added.

Many banks avoided falling victim to such attacks by imposing a minimum transaction size that removed the fractional error, said Mr Beardsley.

Penetration tester Charlie Svensson, from security firm Sentor, said banks’ anti-fraud mechanisms would probably spot and stop anyone trying to carry out thousands of tiny trades all day, every day.

“I have the feeling that he would not be the first to do this, but banks tend to take notice when money goes missing,” he said. “If there’s one thing that banks worry about, it’s money.”

Source:www.bbc.com

Main sidebar

  • High-tech military goggles combine night vision, thermal imaging
    May 14, 2015
  • Google Play now lets you preregister for upcoming apps and games
    May 14, 2015
  • Apple’s Next Big Thing: Your DNA?
    May 11, 2015
  • Microsoft to stop producing Windows versions
    May 11, 2015
  • Mini launches prototype of glasses that give ‘X-ray vision’
    May 11, 2015

Follow Zahanat

Like us on Facebook Zahanat.Official



Our Channel at VimeoZahanat



Our Channel at dailymotionZahanat




Zahanat.com

Zahanat.com is a self sustained project; a free online resource for Pakistan’s academic communities. It covers widely used curricula in Pakistan from class I to XII. We also provide career guidance, exam preparation, health & social well being tips to students. We do not receive any grants from any one nor do we follow any third party agenda. We value what is good for our students and country more than any gain or profit.

Get Involved

Zahanat.com provides a platform to socialize and engage in healthy extracurricular activities for students, parents and teachers
Students: Click to learn more
Parents: Click to learn more
Teachers: Click to learn more
Our aim is to engage individuals from all academic background and field of life.
Visit our FAQ Section to learn more about how can can participate.

Legal Policies

Terms and Conditions
Privacy Policy
Copyright Policy
Anti-Spam Policy
Linking Policy
Legal Disclaimer
These policies and disclaimers apply only to the Zahanat.com. Therefore, once you link to another site, you are subject to the policies of the new site.
Beta Disclaimer
This is the Beta launch, you may experience few shortcomings or technical issues. Team Zahanat!

Parents Account

Zahanat.com offers a 21st century parenting guide for better parenting by sharing knowledge of experts with you, parents can also create a free account at zahanat.com and can become part of progressive parents community.
Visit our Frequently Asked Questions Section to learn more about how to create parent account and related benefits.

Teachers Account

Zahanat.com has created a platform for the Teachers, where they can find various useful academic articles and online resources to polish their teaching skills. Teachers can create free account and opt to be part of National Teachers Directory.
Visit our FAQ Section to learn more about how to create account and related benefits.

SMS Verification

To ensure the safe and approved online interactivity of student at zahanat.com, we have developed & implemented the SMS Verification System, under this system, students are asked to Enter their parents / guardian Mobile Number, our system sends the account approval & verification code to the provided number to get authorization for account creation.
copyright 2015 Zahanat.com