It hasn't changed one bit since I was last there almost 3 years ago dealing with them on some financial matters. The layout is still as bewildering as ever, it is completely un-disabled-friendly (for a lack of a better word) and like most places in Malaysia, the air-conditioning is set to artic circle for no good reason. The condensation on the glass walls separating the ATM's from the food path is a testimony to that.
Amongst other things through, there is a computer terminal for one to do their online banking:
Now I applaud the move by banks to have computer terminals in their branches as to allow their customers to do online banking. Most Australian bank branches have this convenience, and this helps me to do some quick money transfers when I'm out.
Generally, the terminals provided by the banks should be the most secure computers to do your online banking with the financial institution. Except this particular one.
Problem no 1:
Internet Explorer 6.
It the web browser that gives web developers sleepless nights, is buggy as hell, and it is impossible to develop websites that render correctly on it without breaking on other browsers. Unfortunately, it is the default browser for Windows XP. The web developer in me cries out "If you're going to use Internet Explorer at least use Internet Explorer 7!"
Secondly, it is a full blown web browser, with an address bar, that one can enter URL's into.
And it has full access to the internet. I could load and surf any webpage. Granted, there is a notice stuck on the keyboard saying "This computer is for use of Maybank2u only" or words to that effect, and it would be really obvious if you camped out there for extended periods of time.
I also noticed that the copy of Windows XP that was running on it had full administrator rights, and it was not patched to Windows XP Service Pack 3.
It doesn't take much imagination to figure out how to exploit this. It is easy to knock up a website using the black and yellow colors of Maybank. There was nothing stopping me setting the default home page of IE6 to some phishing website.
With full access to the internet, I could also have downloaded any of the many keyloggers avaliable and installed on the machine because I had full administrator rights. Torpig anyone?
But I need not have had access to the internet. A quick glance down showed that the USB ports were for all to see:
with a floppy drive and a Aztech 605E ADSL modem.
Remember that it was not patched with Service Pack 3? I could have used any flash drive as a infection vector. A simple Autorun.inf file, a keylogger, connected to the control bot. It would take me less than 30 seconds to infect the machine and have access to anyone who accessed their bank account using that machine. Plugging in any (infected) flash drive would almost be undetectable.
Think using Maybank's TAC would keep you safe? Think again. Like most Two-factor authentication mechanisms, it is vulnerable to a replay attack. It takes me less than 15 seconds to empty a bank account by using your TAC that you used for another transaction. Not to mention in Bolehland, intercepting SMS'es is not that hard.
There was also no sign for any anti-malware protection on the terminal, a worrying sign considering that anyone had full administrative rights using the machine. I don't know about you, but personally that machine would be the last machine that I'd use to log on to any kind of internet banking.
The "fix" for this "problem" is glaringly simple. It doesn't cost much either. Blocking unused ports is easy. Patching Windows XP to SP3 and disabling autorun.inf is not that hard. The latter is one line of registry code.
Do we need to close the door after the horse has bolted?


















