Nullcon Goa 2023 | How I Hacked Your Bank Account: A Detailed Look At UPI Security by Nemo

  Рет қаралды 3,044

nullcon

nullcon

Күн бұрын

Abstract:
--------------
UPI needs no introduction, it is the fastest-growing payment method in the world, with billions of transactions flowing through it every month. This talk presents independent security research on UPI, including major vulnerabilities (disclosed and fixed with NPCI’s cooperation), as well as a threat model of how secure UPI really is.
The talk is based on independent research that the author did while at Razorpay, reversing and debugging multiple UPI applications to better understand the underlying security parameters. The first half of the talk goes over UPI’s payment flows, looking deeply into various security properties of the system, and how they differ between various apps. Peppered with a few demos to showcase the reversing process, the rest of the talk will walk the audience through a major vulnerability disclosure - which allowed mass hacking of bank accounts in India.
#hackingUPI #upipayments #Infosec #Nullcon #NullconGoa2023
---------------------------------------------------------------------------------------------------------------------
Follow nullcon on Facebook: / nullcon
Twitter: / nullcon
LinkedIn: / nullcon
Website: nullcon.net

Пікірлер: 5
@VacuumFluctuation
@VacuumFluctuation 11 ай бұрын
Superb eye - opener for all in the infosec community. More infosec people should work on UPI security due to its impact & scale but early that's not the reality... That's surprising. 😮
@anonymouspheonix5198
@anonymouspheonix5198 11 ай бұрын
Awesome Video
@kumud-ranjan
@kumud-ranjan 11 ай бұрын
bhai koi easy way m samjha sakta h? to samjha do....
@surajraika7821
@surajraika7821 11 ай бұрын
there is no easy way
@bhumiputra6108
@bhumiputra6108 11 ай бұрын
Dude reverse engineered a less secure payment application using Frida. Then exploited the Business Logic Flaw(lack of SMS validation) basically bad implementation of Zero Trust on the UPI Backend. This helped him in performing Impersonation attack(Logging in as You) by spoofing the mobile number that was being sent to UPI backend.
Spongebob ate Michael Jackson 😱 #meme #spongebob #gmod
00:14
Mr. LoLo
Рет қаралды 11 МЛН
Running With Bigger And Bigger Lunchlys
00:18
MrBeast
Рет қаралды 124 МЛН
pumpkins #shorts
00:39
Mr DegrEE
Рет қаралды 68 МЛН
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 116 М.
Completely Get Rid of Null Using This Technique
25:28
Milan Jovanović
Рет қаралды 10 М.
basic 1 tin and 1 bottle
3:13
bon sebastian
Рет қаралды 3,2 М.
Nullcon Berlin 2024 | Hacking Trains By Jaden Furtado
38:10
Free Hacking API courses (And how to use AI to help you hack)
53:46
David Bombal
Рет қаралды 110 М.
oAuth for Beginners - How oauth authentication🔒 works ?
10:43
Spongebob ate Michael Jackson 😱 #meme #spongebob #gmod
00:14
Mr. LoLo
Рет қаралды 11 МЛН