• Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Home Research/How to do it

Hackers Can Guess Your Visa Card Details In About Six Seconds

Paul Balo by Paul Balo
December 6, 2016
in Research/How to do it, Security
Share on FacebookShare on Twitter

We’ve reported on some really scary security lapses that are being exploited by hackers but this one appears to be a serious one too. Hackers can now guess your Visa card details in less than six seconds.

Security researchers from the University of Newcastle in a paper titled “Does The Online Card Payment Landscape Unwittingly Facilitate Fraud?” said there is a security hole in your bank card that makes it easy for hackers to guess sensitive  information such as  your PIN. In the video attached, you’ll see that using a special tool, it actually takes about six seconds to get aa card’s secure code and it’s easy for them because if guesses for your card’s CVC number (the three digits behind) are spread out across different websites, there’s no security alert sent to you about this. So exploiting this loophole across different websites, they are able to come up with the CVC number for that card as well other basic data like your postal address. The good (maybe not good) news is that this doesn’t affect all cards according to the research carried out. It only affects Visa cards.

The attackers are able to get this information because different websites demand different authentication data from you to process transactions. , websites that only require card number and expiry can be used to glean the expiry date in no more than 60 guesses (because cards are only valid for a maximum of 60 months) and then this card number/expiry pair to can be used to guess the three-digit CVV in no more than 999 guesses.

Seeing as card numbers are region based (you can know this from the first six digits of the card), it becomes easy to hackers to narrow down once they have other data attached to the card. So one difficult one is the address attached to the card, but with the ability to narrow down cards to regions, this can be guessed over time too.

According to tech website BoingBoing, “Mastercards are not vulnerable to this attack because “MasterCard’s centralised network detects the guessing attack after fewer than 10 attempts (even when those attempts were distributed across multiple websites),” but Visa cards are, because “Visa’s payment ecosystem does not prevent the attack.”

To deal with this threat though, the researchers propose a uniform standard required by different websites so that the accuracy of guessing is cut down. Other proposed solutions include use of IP address instead of Captcha and other Visa induced authentication requirements.

To prevent the attack, either standardisation or centralisation can be pursued (some card payment networks already provide this). Standardisation would imply that all merchants need to offer the same payment interface, that is, the same number of fields. Then the attack does not scale anymore. Centralisation can be achieved by payment gateways or card payment networks possessing a full view over all payment attempts associated with its network. Neither standardisation nor centralisation naturally fit the flexibility and freedom of choice one associates with the Internet or successful commercial activity, but they will provide the required protection. It is up to the various stakeholders to determine the case for and timing of such solutions.

Last month, researchers in Lancaster University developed an algorithm that can guess passwords of even more security conscious internet users. Called TarGuess, it is able to guess passwords with a 73 percent accuracy.

MasterCard on the other hand is now attempting to replace passwords with selfie and finger print authentications to make it harder for such guesses to happen.

Related Posts:

  • contactless-payment-marquee-800×450
    The Significance of Visa Tap-to-Pay Technology For…
  • End-to-End Payments
    Everything You Need to Know About End-to-End Payments
  • pci security
    How To Begin With PCI Data Security Compliance
  • router-595x335_0
    US And UK Warn Of Custom Malware Vulnerability On…
  • DOJ-says-it-will-no-longer-prosecute-good-faith-hackers-under-CFAA
    US Department Of Justice Will No Longer Prosecute…
  • kcb-bank-1024×683
    The KCB & Visa Partnership Deal Innovates NFC…
  • carbon
    Carbon and Verve Partner to Issue Debit Cards
  • 32gb-sandisk-memory-card
    Review: Here's The Best 32 GB Card Of 2022

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: hackersmastercardmobile paymentnew castleresearcherssecurityunited kingdomuniveristyvisa
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Select Category

    Receive top tech news directly in your inbox

    subscription from
    Loading

    Freshly Squeezed

    • Top 10 Fee-Free Fintech Apps Nigerians Are Turning To After CBN’s New Charges May 8, 2025
    • Airtel Launches Mobile Money in 2026 to Rival M-Pesa & MoMo May 8, 2025
    • Nigeria Hits 172M Mobile Subscriptions; MTN Tops 90M Barrier May 8, 2025
    • WhatsApp Developing AI Chat Wallpapers & Message Summaries May 8, 2025
    • Bill Gates to Wind Down Foundation by 2045, Slams Elon Musk Over USAID Cuts May 8, 2025
    • Central Bank of Nigeria Approves Open Banking Launch This August. Here’s what to Know May 8, 2025

    Browse Archives

    May 2025
    MTWTFSS
     1234
    567891011
    12131415161718
    19202122232425
    262728293031 
    « Apr    

    Popular Tags

    africa (135) AI (497) android (367) app (717) Apple (576) artificial intelligence (419) business (482) china (132) cryptocurrency (209) ecommerce (122) enterprise (287) facebook (507) fintech (244) funding (121) gadget (558) gaming (201) google (709) government (469) instagram (173) internet (466) ios (291) iphone (246) meta (116) microsoft (369) mobile (352) new feature (384) nigeria (440) privacy (158) research (140) samsung (185) security (421) smartphone (277) social media (835) software (509) startup (419) streaming (174) telecom (242) tips (372) twitter (289) united states (216) users (158) videos (127) website (173) whatsapp (201) youtube (138)

    Quick Links

    • About TechBooky
    • Advertise Here
    • Contact us
    • Submit Article
    • Privacy Policy

    About Us

    TechBooky

    TechBooky is a social Tech blog with a special focus on the budding African Technology sector. TechBooky is currently based in Abuja, Nigeria.

    Recent News

    Top 10 Fee-Free Fintech Apps Nigerians Are Turning To After CBN’s New Charges

    Top 10 Fee-Free Fintech Apps Nigerians Are Turning To After CBN’s New Charges

    May 8, 2025
    Airtel Launches Mobile Money in 2026 to Rival M-Pesa & MoMo

    Airtel Launches Mobile Money in 2026 to Rival M-Pesa & MoMo

    May 8, 2025
    MTN Recovers ₦32 Billion in USSD Fees

    Nigeria Hits 172M Mobile Subscriptions; MTN Tops 90M Barrier

    May 8, 2025
    WhatsApp Developing AI Chat Wallpapers & Message Summaries

    WhatsApp Developing AI Chat Wallpapers & Message Summaries

    May 8, 2025
    Bill Gates to Wind Down Foundation by 2045, Slams Elon Musk Over USAID Cuts

    Bill Gates to Wind Down Foundation by 2045, Slams Elon Musk Over USAID Cuts

    May 8, 2025
    Central Bank of Nigeria Approves Open Banking Launch This August. Here’s what to Know

    Central Bank of Nigeria Approves Open Banking Launch This August. Here’s what to Know

    May 8, 2025
    • Login

    © 2021 Design By Tech Booky Elite

    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
    • African
    • Artificial Intelligence
    • Gadgets
    • Metaverse
    • Tips
    • About TechBooky
    • Advertise Here
    • Submit Article
    • Contact us

    © 2021 Design By Tech Booky Elite

    Discover more from TechBooky

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Ok