what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Wells Fargo Poor Password Configurations

Wells Fargo Poor Password Configurations
Posted Apr 21, 2017
Authored by anonymous

WellsFargo.com password and security management has been identified as being in a weak state of configuration and violation of PCI DSS 3.2 Subsection 8.2.3, 8.2.4. Multiple vulnerabilities result in poor credential management and configuration, as well as flaws in triggering fraud detection. Some vulnerabilities can be paired with each other to increase the risk associated.

tags | advisory, vulnerability
SHA-256 | 9897ca9c7c3fef37c751ef96b01826fa4151765a9919ef86e72d4e6962195fa6

Wells Fargo Poor Password Configurations

Change Mirror Download
# Title: Wells Fargo Poor Password Configurations
# Author: Anonymous
# Date: 04.21.2017
# Impacted Site: https://www.wellsfargo.com

WellsFargo.com password and security management has been identified as being in a weak state of configuration and violation of PCI DSS 3.2 Subsection 8.2.3, 8.2.4. Multiple vulnerabilities result in poor credential management and configuration, as well as flaws in triggering fraud detection. Some vulnerabilities can be paired with each other to increase the risk associated.

Poor Credential Management Findings
1. Passwords must contain 1 letter and 1 number
a. Industry standards indicate that sensitive passwords follow complexity which would include a special character or case sensitivity.
2. Passwords are limited to 6-14 characters
a. 6 characters is much too short and violates PCI DSS 3.2 Section 8.2.3
i. Compensating controls for strength are allowed such as special characters, however special characters are not enforced.
ii. Wells Fargo appears to be implementing additional controls such as repeating characters, however with the increase in computer processing hardware and GPU enable password cracking, length and complexity is more important than blocking patterns of characters.
b. 14 character passwords may not be long enough for users who choose to use passphrases, which can result in poor password selection.
3. Discovered passwords are case insensitive
a. Credit:/u/redditsmart0
b. Passwords allow uppercase or lowercase permutations of the same password
i. Coupling this along with 6 character passwords greatly increases the likelihood of password compromise.
4. Passwords are not required to be changed every 90 days
a. Violation of PCI DSS 3.2 Section 8.2.4

Fraud Detection
1. A test of logging into Wells Fargo from a new computer from a foreign country did not indicate any sort of additional security checks when logging in or transferring money. Almost all of Wells Fargo competitors, as well as other financial management entities require 2 factor passcodes when logging in with a new computer or from a foreign location.
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close