3 weeks ago
3 weeks ago
3 weeks ago
Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.
We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

A new method has been discovered by a team of security researchers at Newcastle University the United Kingdom, to hack VISA Credit and Debit cards in just six seconds. The name of the attack is Distributed Guessing Attack. It works same as brute force attack and dictionary attack. This attack is nothing more than a successful guess. Security researchers showed that attackers can submit fake card details on online payment websites and they can analyze its reply to the transaction to check that whether the data is correct or not. The most shocking fact about this attack is, it can bypass all the security methods very easily, which have been used by online payment systems to protect card details from hackers.
The security flaw exists in VISA payment systems. A Ph.D. student of Newcastle University Mohammed Ali (Lead Security researcher of this project) wrote about two major security flaws which are allowing this attack:
"In simple words, hackers can generate new card details by bypassing security features of VISA payment systems. All the different variations generated by the hackers could allow them to make unauthorized purchases on all that e-commerce websites, which are accepting VISA cards."
Mohammed Ali said that only VISA payment systems are vulnerable to this attacks. The payment systems of MasterCard are detecting invalid attempts and they are blocking IP address after 10 invalid attempts.
Security researchers believe that in the recent Tesco Bank Cyber Attack incident, hackers had used this Distributed Guessing Attack. More than £2.5m had been stolen by the hackers from Tesco Bank. No special equipment and hardware devices are required to perform this attack. A laptop and an internet connection are enough to perform Distributed Guessing Attack.
Sorry to say but this attack does not require legit card details. Hackers are generating new card details which are working on the VISA payment systems. There is not any magic key which could protect your money. But you could use some security methods to reduce the risk of money loss:
Such type of attack is more dangerous in this Christmas season when everyone is busy in doing shopping and nobody cares about his credit card or bank statements.