Kasus Situs KlikBCA Palsu

Slides:



Advertisements
Similar presentations
InterScan AppletTrap Zhang Hong Trend Micro, AppletTrap Team (Nanjing)
Advertisements

Andrew Newbigging Vice President, Integrations Development
ISA 662 SSL Prof. Ravi Sandhu. 2 © Ravi Sandhu SECURE SOCKETS LAYER (SSL) layered on top of TCP SSL versions 1.0, 2.0, 3.0, 3.1 Netscape protocol later.
AI3 Contact Server Takeshi Usui
Information Gathering. Before an attack What information do we need? WHOIS details OS & web server details (NetCraft, whois.webhosting.info) DNS information,
© Tally Solutions Pvt. Ltd. All Rights Reserved Shoper 9 License Management December 09.
Staying in Sync with Cloud 2 Device Messaging. About Me Chris Risner Twitter: chrisrisner.
SSL/TLS Protocol Network Security Gene Itkis. Basic paradigmatic application: on-line purchase Client contacts Server (possibly for the first time) Spontaneity.
An Introduction to Distributed Security Concepts and Public Key Infrastructure (PKI) Mary Thompson.
How to INSTALL THE CERTIFICATE
Hasil Scan Situs Internet Bank Onno W. Purbo
Cryptography and Network Security Chapter 16
Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations Chad Brubaker1 Suman Jana1 Baishakhi Ray2.
VoIP Merdeka - Architecture Onno W. Purbo
Web security: SSL and TLS
The Dog’s Biggest Bite. Overview History Start Communication Protocol Weakness POODLE Issues.
Overview The TCP/IP Stack. The Link Layer (L2). The Network Layer (L3). The Transport Layer (L4). Port scanning & OS/App detection techniques. Evasion.
CP3397 ECommerce.
SSL Implementation Guide Onno W. Purbo
Payment Gateway Onno W. Purbo Issu Utama Payment Method Security Certificate Authority Cyberlaw.
1 Lecture 17: SSL/TLS history, architecture basic handshake session initiation/resumption key computation negotiating cipher suites application: SET.
CS470, A.SelcukSSL/TLS & SET1 CS 470 Introduction to Applied Cryptography Instructor: Ali Aydin Selcuk.
Secure Socket Layer.
An Introduction to Secure Sockets Layer (SSL). Overview Types of encryption SSL History Design Goals Protocol Problems Competing Technologies.
SSL : An Overview Bruhadeshwar Bezawada International Institute of Information Technology, Hyderabad.
BASIC CRYPTOGRAPHY CONCEPT. Secure Socket Layer (SSL)  SSL was first used by Netscape.  To ensure security of data sent through HTTP, LDAP or POP3.
Mar 19, 2002Mårten Trolin1 This lecture On the assignment Certificates and key management SSL/TLS –Introduction –Phases –Commands.
Apr 2, 2002Mårten Trolin1 Previous lecture On the assignment Certificates and key management –Obtaining a certificate –Verifying a certificate –Certificate.
Department of Computer Science Southern Illinois University Carbondale Wireless and Network Security Lecture 9: IEEE
SSL (Secure Socket Layer) and Secure Web Pages Rob Sodders, University of Florida CIS4930 “Advanced Web Design” Spring 2004
Apache Security with SSL Using FreeBSD SANOG VI IP Services Workshop July 18, 2005 Hervey Allen Network Startup Resource Center.
Secure Sockets Layer (SSL) Fred Schank Kevin Wetter.
Secure Sockets Layer 1 / 99  SSL is perhaps the widest used security protocol on the Internet today.  Together with DC enables secure communication.
CSCI 6962: Server-side Design and Programming
IT:Network:Applications.  Single Key (Symmetric) encryption ◦ One “key” or passphrase used to encrypt and decrypt ◦ FAST – good for large amounts of.
8: Network Security8-1 Security in the layers. 8: Network Security8-2 Secure sockets layer (SSL) r Transport layer security to any TCP- based app using.
SYSTEM ADMINISTRATION Chapter 13 Security Protocols.
OpenVPN OpenVPN: an open source, cross platform client/server, PKI based VPN.
SSL and https for Secure Web Communication CSCI 5857: Encoding and Encryption.
Secure Socket Layer (SSL)
SSL / TLS in ITDS Arun Vishwanathan 23 rd Dec 2003.
Port Scanning 0x470~0x480 Presenter SangDuk Seo 1.
Onno W. Purbo openssl Onno W. Purbo
Private Key Algorithms RSA SSL
Introduction to Secure Sockets Layer (SSL) Protocol Based on:
Secure Sockets Layer (SSL) Presented by: Piyush Saggi Baylor University Dec 6, 2002.
ECE Prof. John A. Copeland fax Office: Klaus 3362.
Web Security : Secure Socket Layer Secure Electronic Transaction.
1 SSL - Secure Sockets Layer The Internet Engineering Task Force (IETF) standard called Transport Layer Security (TLS) is based on SSL.
1 Security Protocols in the Internet Source: Chapter 31 Data Communications & Networking Forouzan Third Edition.
Integrating and Troubleshooting Citrix Access Gateway.
X.509 Topics PGP S/MIME Kerberos. Directory Authentication Framework X.509 is part of the ISO X.500 directory standard. used by S/MIME, SSL, IPSec, and.
,294,967,296 Q. What are private IP addresses? A. The Internet Assigned Numbers Authority (IANA) has reserved the following three blocks of the.
 authenticated transmission  secure tunnel over insecure public channel  host to host transmission is typical  service independent WHAT IS NEEDED?
SSH/SSL Attacks not on tests, just for fun. SSH/SSL Should Be Secure Cryptographic operations are secure SSL uses certificates to authenticate servers.
Secure Socket Layer SSL and TLS. SSL Protocol Peer negotiation for algorithm support Public key encryptionPublic key encryption -based key exchange and.
SSL on TELIT modules.
Cryptography CSS 329 Lecture 13:SSL.
Virtual Private Network (VPN)
Secure Sockets Layer (SSL)
UNIT.4 IP Security.
Hasil Scan Situs Internet Bank
SSL Implementation Guide
Originally by Yu Yang and Lilly Wang Modified by T. A. Yang
Cryptography and Network Security
A Programmer’s Guide to Secure Connections
Domain Name System Refs: Chapter 9 RFC 1034 RFC 1035.
Presentation transcript:

Kasus Situs KlikBCA Palsu Onno W. Purbo Onno@indo.net.id

Situs KlikBCA Palsu http://wwwklikbca.com http://www.kilkbca.com http://www.clikbca.com http://www.klickbca.com http://www.klikbac.com

http://www.klikbca.com

www.klikbca.com [root@yc1dav onno]# nmap -vv -sS -O www.klikbca.com Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ ) Host (202.158.15.51) appears to be down, skipping it. Note: Host seems down. If it is really up, but blocking our ping probes, try -P0 Nmap run completed -- 1 IP address (0 hosts up) scanned in 60 seconds

https://ibank.klikbca.com

https://ibank.

ibank.klikbca.com [root@yc1dav onno]# nmap -vv -sS -O ibank.klikbca.com Starting nmap V. 2.53 by fyodor@insecure.org ( www.insecure.org/nmap/ ) Host (202.158.15.52) appears to be down, skipping it. Note: Host seems down. If it is really up, but blocking our ping probes, try -P0 Nmap run completed -- 1 IP address (0 hosts up) scanned in 43 seconds

Keamanan https://ibank. ..

Keamanan https://ibank. .. $ openssl s_client -host ibank.klikbca.com -port 443 CONNECTED(00000003) depth=1 /O=VeriSign Trust Network /OU=VeriSign, Inc. /OU=VeriSign International Server CA - Class 3 /OU=www.verisign.com /CPS Incorp.by Ref. LIABILITY LTD.©97 VeriSign verify error:num=20:unable to get local issuer certificate verify return:0 ---

Keamanan https://ibank. .. Certificate chain 0 s:/C=ID/ST=Jakarta/L=Jakarta /O=PT. Bank Central Asia /OU=Divisi Sistem Informasi /OU=Terms of use at www.verisign.com/rpa ©00 /CN=ibank.klikbca.com i:/O=VeriSign Trust Network/OU=VeriSign, Inc. /OU=VeriSign International Server CA – Class 3 /OU=www.verisign.com /CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign 1 s:/O=VeriSign Trust Network/OU=VeriSign, Inc. /OU=VeriSign International Server CA - Class 3 i:/C=US/O=VeriSign, Inc. /OU=Class 3 Public Primary Certification Authority ---

Keamanan https://ibank. .. Server certificate -----BEGIN CERTIFICATE----- MIIFiTCCBPKgAwIBAgIQNJxhVugbaLL091k1nDHipzANBgkqhkiG9w0BAQQFAD ujEfMB0GA1UEChMWVmVyaVNpZ24gVHJ1c3QgTmV0d29yazEXMBUGA1UECxMOVm aVNpZ24sIEluYy4xMzAxBgNVBAsTKlZlcmlTaWduIEludGVybmF0aW9uYWwgU2 8m/rIsc6SA19ranlBFx0zT9AURZDDcVy12ZM9T0ZvWY5xF2frWRibYnw3zyQVC a6cK5U0JK0T/ddqrgRggeqH8ushwef68etrEqgw= -----END CERTIFICATE----- subject=/C=ID/ST=Jakarta/L=Jakarta/O=PT. Bank Central Asia /OU=Divisi Sistem Informasi /OU=Terms of use at www.verisign.com/rpa ©00 /CN=ibank.klikbca.com issuer=/O=VeriSign Trust Network/OU=VeriSign, Inc. /OU=VeriSign International Server CA - Class 3 /OU=www.verisign.com /CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign ---

Keamanan https://ibank. .. No client certificate CA names sent --- SSL handshake has read 2637 bytes and written 312 bytes New, TLSv1/SSLv3, Cipher is RC4-MD5 Server public key is 1024 bit SSL-Session: Protocol : TLSv1 Cipher : RC4-MD5 Session-ID: 850000001702595756FADE4AFEE7F652BC790CC606376 Session-ID-ctx: Master-Key: 3CD841954D698035E5C82941F608D200929A3636CA07D Key-Arg : None Start Time: 991984495 Timeout : 300 (sec) Verify return code: 0 (ok) QUIT DONE $