Working out the card number, expiry date and security code of any Visa credit or debit card can take as little as 6 seconds and uses nothing more than guesswork. New research reveals the ease with which criminals can hack an account without any of the card details.
Research published in the academic journal IEEE Security & Privacy, shows how the so-called Distributed Guessing Attack is able to circumvent all the security features put in place to protect online payments from fraud.
To obtain card details, the attack uses online payment websites to guess the data and the reply to the transaction will confirm whether or not the guess was right.
Different websites ask for different variations in the card data fields and these can be divided into three categories: Card Number + Expiry date (the absolute minimum); Card Number + Expiry date + CVV (Card security code); Card Number + Expiry date + CVV.
Because the current online system does not detect multiple invalid payment requests on the same card from different websites, unlimited guesses can be made by distributing the guesses over many websites.

However, the team found it was only the VISA network that was vulnerable...
Lire la suite de l'article : http://www.ncl.ac.uk/press/news/2016/12/cyberattack/
http://eprint.ncl.ac.uk/file_store/prod ... 6E1FDB.pdf
https://www.theguardian.com/technology/ ... udy-claims