what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Wells Fargo Poor Password Configurations

Wells Fargo Poor Password Configurations
Posted Apr 21, 2017
Authored by anonymous

WellsFargo.com password and security management has been identified as being in a weak state of configuration and violation of PCI DSS 3.2 Subsection 8.2.3, 8.2.4. Multiple vulnerabilities result in poor credential management and configuration, as well as flaws in triggering fraud detection. Some vulnerabilities can be paired with each other to increase the risk associated.

tags | advisory, vulnerability
SHA-256 | 9897ca9c7c3fef37c751ef96b01826fa4151765a9919ef86e72d4e6962195fa6

Wells Fargo Poor Password Configurations

Change Mirror Download
# Title: Wells Fargo Poor Password Configurations
# Author: Anonymous
# Date: 04.21.2017
# Impacted Site: https://www.wellsfargo.com

WellsFargo.com password and security management has been identified as being in a weak state of configuration and violation of PCI DSS 3.2 Subsection 8.2.3, 8.2.4. Multiple vulnerabilities result in poor credential management and configuration, as well as flaws in triggering fraud detection. Some vulnerabilities can be paired with each other to increase the risk associated.

Poor Credential Management Findings
1. Passwords must contain 1 letter and 1 number
a. Industry standards indicate that sensitive passwords follow complexity which would include a special character or case sensitivity.
2. Passwords are limited to 6-14 characters
a. 6 characters is much too short and violates PCI DSS 3.2 Section 8.2.3
i. Compensating controls for strength are allowed such as special characters, however special characters are not enforced.
ii. Wells Fargo appears to be implementing additional controls such as repeating characters, however with the increase in computer processing hardware and GPU enable password cracking, length and complexity is more important than blocking patterns of characters.
b. 14 character passwords may not be long enough for users who choose to use passphrases, which can result in poor password selection.
3. Discovered passwords are case insensitive
a. Credit:/u/redditsmart0
b. Passwords allow uppercase or lowercase permutations of the same password
i. Coupling this along with 6 character passwords greatly increases the likelihood of password compromise.
4. Passwords are not required to be changed every 90 days
a. Violation of PCI DSS 3.2 Section 8.2.4

Fraud Detection
1. A test of logging into Wells Fargo from a new computer from a foreign country did not indicate any sort of additional security checks when logging in or transferring money. Almost all of Wells Fargo competitors, as well as other financial management entities require 2 factor passcodes when logging in with a new computer or from a foreign location.
Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    6 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close