Re: internet banking security

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 10/17/05

  • Next message: Micheal Espinola Jr: "Re: Host placement and DMZ internal/external questions."
    To: Muhammad Aslam <aslam.popal@gmail.com>
    Date: Mon, 17 Oct 2005 20:27:31 +0100
    
    
    

    On Mon, 2005-10-17 at 14:45 +0430, Muhammad Aslam wrote:

    > I agree with you but we want some preliminary information about
    > ebanking security systems and different steps in making it secure and
    > reliable.
    >

    So what specifically are you asking ? A banking system can be put
    together in a variety of different ways and until you have specifics we
    could talk about building secure Windows systems or writing secure code.
    It's very wide, what are your actual worries - give us questions to
    answer, otherwise we could just talk for pages on random security
    topics.

    > Exactly we are outsourcing this project but prior doing so , we want
    > to get enough information so that we will be in the loop whatever
    > happening and what the security company will suggest us in going
    > online.

    What do you need information on ? "Ebanking security" is very wide, do
    you want to know about development environments, security policies, OS
    hardening, OS choices ?

    >
    > >
    > > It seems like you are ready to just grab the software and security
    > > advice we give here and dive into building the system, very bad idea.
    > >
    > Which we are also not going to do as we are aware of the magnitude of
    > responsibility is invovled and as i mentioned we are going to
    > outsource the project.

    Do you want us to just tell you everything there is to know about
    security or do you have _specific_ queries ?

    Like I said in my first email your question can be answered in hundreds
    of different ways, can you please give us more specific questions.

    "What are the security implications of creating an ebanking system as a
    3 tier web app based on PHP/IIS/MySQL?"

    "What sort of policy documents should we prepare for an ebanking system
    (for internal and customer use) ?"

    These are very different questions and we could discuss either of them
    in response to your original query and they may not even come close to
    what it is you need. Can you _please_ explain exactly what your issues
    are so we can offer help.

    -- 
    With Regards..
    Barrie Dempster (zeedo) - Fortiter et Strenue
    "He who hingeth aboot, geteth hee-haw" Victor - Still Game
    blog:  http://reboot-robot.net
    sites: http://www.bsrf.org.uk - http://www.security-forums.com
    ca:    https://www.cacert.org/index.php?id=3
    
    


    • application/x-pkcs7-signature attachment: smime.p7s

  • Next message: Micheal Espinola Jr: "Re: Host placement and DMZ internal/external questions."

    Relevant Pages

    • Re: Is MSIE dead as a browser - if Microsoft does not patch it then it is as far as I am concerned!
      ... it has to do only with ultimate responsibility. ... might not know better when it comes to doing timely security updates, ... Most malware uses some sort of buffer overflow exploit. ... How many patches will it take to make my XP OX as secure as my ...
      (microsoft.public.security.virus)
    • RE: How hackers cause damage...
      ... "Security Companies" that do not lock down systems or give ... Having enough people to completely secure all ... responsibility for negligence - systems are not always secured. ... be helpful to prosecute the person that *exploited* a vulnerability ...
      (Security-Basics)
    • Re: Ten least secure programs
      ... it's probably better you leave the topic alone ... I said I do not have security issues with the programs I code. ... I didn't realize you were a Linux user, ... > the most widely used and secure UNIX flavors? ...
      (Security-Basics)
    • "An Asp.Net accident waiting to happen" - Draft article
      ... In a time where Security ... in shared hosting environments. ... technologies that allow the creation and deployment of secure ... IIS 6 web server and windows 2003 also provide some tools to deploy ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • RE: Why Easy To Use Software Is Putting You At Risk
      ... I do agree that the additions and changes to Solarius will make it more secure and that this is good. ... Why Easy To Use Software Is Putting You At Risk ... instead I would say that the view that security is ... Four Construction Workers Died after Crane Collapse in Toledo, ...
      (Security-Basics)