Dear SF, I am writing this to inform the public that bank of America's two step authentication is fundamentally flawed. The user at there website will enter a user name then tell there systems which state it originates from but the next step is flawed. The server connects you to a secret challenge where it gives a question like "Whats your mothers maiden name?" but if you were to answer "Joni" it lets you in. On step 1 of this authentication you answer "Jon i" or "Jni " it lets you in, I found a couple times the server did not mind a letter missing as long as the beginning is kept the same; Also moving the word or letters with spaces allows entrance. This is a common vulnerability in fact the Point Of Sale at the company I work for allows 3 letters of your password to be entered and it usually authenticates because it isn't strict on how precise you enter the password as long as it appears to be the original password.
Superuser of Socal gr33ts to 23.org, Uber Tron Da Hacker _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/