Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Trading > IOActive Discloses More Vulnerabilities in Popular Stock Trading Applications at Black Hat USA 2018
    Trading

    IOActive Discloses More Vulnerabilities in Popular Stock Trading Applications at Black Hat USA 2018

    IOActive Discloses More Vulnerabilities in Popular Stock Trading Applications at Black Hat USA 2018

    Published by Gbaf News

    Posted on August 9, 2018

    Featured image for article about Trading
    Tags:emote Denial of ServiceIOActivestock tradingStock Trading Applications

    Security researcher Alejandro Hernandez expands his 2017 research on vulnerabilities found in popular mobile trading, desktop and web stock trading applications

    IOActive, Inc., the worldwide leader in research-driven security services, today announced new vulnerabilities the research team has discovered in mobile, desktop and web stock trading applications.

    IOActive Senior Security Consultant, Alejandro Hernandez, will be presenting his vulnerability findings at Black Hat Las Vegas on Thursday, August 9th at 11am PT in his talk, “Are You Trading Stocks Securely? Exposing Security Flaws in Trading Technologies.”

    His research expands upon his original 2017 research on mobile trading applications. At Black Hat, Hernandez will discuss how he tested several stock trading and cryptocurrency trading technologies including 16 desktop applications, 30 websites, and 34 mobile applications and discovered major vulnerabilities that can allow malicious actors to gain access to a user’s personal banking information through desktop and web applications, steal money and gain insights into net worth and investment strategies.

    Hernandez commented, “I published my original research nearly a year ago, and it’s deeply concerning that some of the same vulnerabilities have still not been fixed.”

    Similar to his research last year, Hernandez found that the usernames and passwords can easily be stolen from stock trading networks. This year, he found many vulnerabilities including unencrypted authentication, communications, passwords and trading data, and remote Denial of Service (DoS) that can leave applications useless. In addition, he found issues with weak password policies, hardcoded secrets and poor session management.

    “Imagine a stock trader in a coffee shop, using public Wi-Fi. An attacker would be able to easily perform a man-in-the-middle attack and identify or modify the network traffic that is unencrypted,” says Hernandez. “For example, the attacker could see the username and password of the trader’s account and later login through a web browser, link his or her bank account, sell the stocks at market price to liquidate the investments, transfer the money, remove the added bank account and log out.”

    “Alejandro’s continued research and discovery of major flaws in stock trading technologies will hopefully be a wakeup call to the financial industry,” said Jennifer Steffens, CEO of IOActive. “They need to implement the strong security controls they already have in place for banking applications and follow industry best practices to properly develop mobile, desktop and web applications, and continuously scan them for vulnerabilities.”

    All of the vendors impacted by these stock trading vulnerabilities have been notified. IOActive cannot confirm whether or not they are fixed at this point in time.

    Security researcher Alejandro Hernandez expands his 2017 research on vulnerabilities found in popular mobile trading, desktop and web stock trading applications

    IOActive, Inc., the worldwide leader in research-driven security services, today announced new vulnerabilities the research team has discovered in mobile, desktop and web stock trading applications.

    IOActive Senior Security Consultant, Alejandro Hernandez, will be presenting his vulnerability findings at Black Hat Las Vegas on Thursday, August 9th at 11am PT in his talk, “Are You Trading Stocks Securely? Exposing Security Flaws in Trading Technologies.”

    His research expands upon his original 2017 research on mobile trading applications. At Black Hat, Hernandez will discuss how he tested several stock trading and cryptocurrency trading technologies including 16 desktop applications, 30 websites, and 34 mobile applications and discovered major vulnerabilities that can allow malicious actors to gain access to a user’s personal banking information through desktop and web applications, steal money and gain insights into net worth and investment strategies.

    Hernandez commented, “I published my original research nearly a year ago, and it’s deeply concerning that some of the same vulnerabilities have still not been fixed.”

    Similar to his research last year, Hernandez found that the usernames and passwords can easily be stolen from stock trading networks. This year, he found many vulnerabilities including unencrypted authentication, communications, passwords and trading data, and remote Denial of Service (DoS) that can leave applications useless. In addition, he found issues with weak password policies, hardcoded secrets and poor session management.

    “Imagine a stock trader in a coffee shop, using public Wi-Fi. An attacker would be able to easily perform a man-in-the-middle attack and identify or modify the network traffic that is unencrypted,” says Hernandez. “For example, the attacker could see the username and password of the trader’s account and later login through a web browser, link his or her bank account, sell the stocks at market price to liquidate the investments, transfer the money, remove the added bank account and log out.”

    “Alejandro’s continued research and discovery of major flaws in stock trading technologies will hopefully be a wakeup call to the financial industry,” said Jennifer Steffens, CEO of IOActive. “They need to implement the strong security controls they already have in place for banking applications and follow industry best practices to properly develop mobile, desktop and web applications, and continuously scan them for vulnerabilities.”

    All of the vendors impacted by these stock trading vulnerabilities have been notified. IOActive cannot confirm whether or not they are fixed at this point in time.

    Related Posts
    What Is a Liquidity Provider – And Why Modern Brokers Can’t Function Without One
    What Is a Liquidity Provider – And Why Modern Brokers Can’t Function Without One
    OneFunded: Prop Firm Overview and Program Structure
    OneFunded: Prop Firm Overview and Program Structure
    What if You Can Actually Chat with Your Crypto Wallet?
    What if You Can Actually Chat with Your Crypto Wallet?
    The Growing Importance of Choosing the Right Crypto Broker in 2025
    The Growing Importance of Choosing the Right Crypto Broker in 2025
    The Rise of Algorithmic Trading Among Retail Investors in the UK
    The Rise of Algorithmic Trading Among Retail Investors in the UK
    Forex Trading for the 9-to-5er: A Realistic Path to a Second Income
    Forex Trading for the 9-to-5er: A Realistic Path to a Second Income
    Quality Matters: ZiNRai’s Focus on Empowering Traders with Precision and Purpose
    Quality Matters: ZiNRai’s Focus on Empowering Traders with Precision and Purpose
    MiCA Regulations and the Legal Requirements for Crypto Presales and Token Offerings in the European Union
    MiCA Regulations and the Legal Requirements for Crypto Presales and Token Offerings in the European Union
    Top Ways Forex Traders Benefit From Peer-to-Peer Learning
    Top Ways Forex Traders Benefit From Peer-to-Peer Learning
    Why High Leverage Remains Attractive to Forex Traders Worldwide
    Why High Leverage Remains Attractive to Forex Traders Worldwide
    XDC Network’s ETP Listing Signals the Maturing Convergence of Blockchain and Trade Finance
    XDC Network’s ETP Listing Signals the Maturing Convergence of Blockchain and Trade Finance
    Inside the Perp DEX Landscape: How Platforms Like Grvt and Hyperliquid Are Shaping Their Long-Term Vision
    Inside the Perp DEX Landscape: How Platforms Like Grvt and Hyperliquid Are Shaping Their Long-Term Vision

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Trading PostCSDR: how penalties and mandatory buy-ins will hit banks
    Next Trading PostA Pragmatic View of Predictive Analytics

    More from Trading

    Explore more articles in the Trading category

    Blending Theory and Practice: Building Stronger Forex Strategies

    Blending Theory and Practice: Building Stronger Forex Strategies

    Strategies for Professional CFD Traders: Tools and Company Support

    Strategies for Professional CFD Traders: Tools and Company Support

    Trust as the Cornerstone of Capital Markets

    Trust as the Cornerstone of Capital Markets

    UK Investors Reassess Trading Venues as Liquidity Shifts

    UK Investors Reassess Trading Venues as Liquidity Shifts

    Bitcoin Price Live: What Factors Influence Its Value?

    Bitcoin Price Live: What Factors Influence Its Value?

    Offshore Forex Brokers vs. U.S.-Regulated Brokers: A Risk Assessment

    Offshore Forex Brokers vs. U.S.-Regulated Brokers: A Risk Assessment

    The Broker Expo, Its Role in the Small Business World, and Everest Business Funding’s Role as Sponsor

    The Broker Expo, Its Role in the Small Business World, and Everest Business Funding’s Role as Sponsor

    Finding Your Edge with a Crypto-First Prop Firm

    Finding Your Edge with a Crypto-First Prop Firm

    Evaluating the Most Reliable Tools for Tracking Real-Time Cryptocurrency Prices

    Evaluating the Most Reliable Tools for Tracking Real-Time Cryptocurrency Prices

    MT5 vs MT4: Why More Brokers Are Moving to MetaTrader 5

    MT5 vs MT4: Why More Brokers Are Moving to MetaTrader 5

    From Central Banks to Retail Traders: Who Drives the Forex Market?

    From Central Banks to Retail Traders: Who Drives the Forex Market?

    Building a Winning Forex Portfolio: Tools and Resources You Can’t Ignore

    Building a Winning Forex Portfolio: Tools and Resources You Can’t Ignore

    View All Trading Posts