Security Problem in an Indian Bank website
Just visited SBI(State Bank of India) bank’s online section. It is one of the Biggest Government Bank in India. Its customers can do online banking via its website www.onlinesbi.com …
Select “Personal Banking” in the Login box.
You will be redirected to https://www.onlinesbi.com/login.html by an Applet.
I entered a username and password generally.
Lets say Username: kumar Password:asdfasdf
I got “Invalid Username or Password” error. Yes it may be wrong.
Again i entered the same logins.. Again and again.. After 4th or 5th attempt. I got “You have been locked out for the day because of three invalid attempts during the day.”
Someone’s account got blocked for today!
I think i am not 100% perfect.. I think my ip may be blocked.. So i asked my friend to login with “same Username” and some other password. He got the “Locked out” message in his veryfirst try…
So no one can login with the username “kumar” for today…
Sorry Kumar!!!
But the shame information is… That website got a certificate from “VeriSign”
They can block my IP due to invalid login attempts or they may send an email to account holder about the login attempts.. They do nothing… they simply blocked the account access…
























You must be logged in to post a comment.