Two Android Phones Work in Relay to Reactivate Expired Bank Cards, Successfully Facilitating a $500 Payment
2 day ago / Read about 0 minute
Author:小编   

At the USENIX Security Symposium, researchers from the University of Massachusetts Amherst showcased a 'zombie card' attack. Leveraging two NFC-enabled Android phones to establish a man-in-the-middle relay, they manipulated the 'Application Expiration Date' field of an expired Visa contactless bank card. This enabled them to bypass local terminal verification and successfully process payments of up to $500. The vulnerability stems from Visa's use of Kernel 3, which excludes the expiration date field from the signed dynamic application data. Furthermore, it sends a terminal verification result field filled with zeros to the issuer, preventing the bank from detecting any tampering. Testing uncovered that the five major U.S. banks exhibit inconsistent handling practices for bank cards nearing expiration, with some banks approving transactions while others reject them.

  • C114 Communication Network
  • Communication Home
7 X 24 Track global technological trends
Hot Topic