We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
NATWEST online banking - rapport safety software not so safe
Comments
-
I just cannot believe this. I use rapport everyday and this is really frightening. Knowing this has put me on guard now.
Thanks chris-wales:T£100 into £10000 challenge. Getting there 1150/10000!!!!!:j0 -
If the OP had continued and then had his account(s) emptied, would Nat West have stood the loss?0
-
Just twigged Chris... so it could have been down to you that the NWOLB site was running like treacle quite recently :rotfl:
[sorry, serious face back on now]
I don't log in at the main Natwest site, but through a saved shortcut (not Favorites) straight to NWOLB. Don't know if it has any relevance either way though, better or worse.~cottager0 -
That wouldn't work, even if Rapport was just performing a rudimentary check on the SSL certificate. An attack like this would require the browser to set up a genuine TLS connection with nwolb.com in the first instance.
ah that's where you're wrong, we're not talking to the real nwolb server in my hypothesis.
Since there is a client side virus it could easily install a new root certificate into the computer's certificate store, then you simply produce an SSL certificate signed with your root cert and serve that up to the infected client, as far as IE or Firefox will know it's a valid SSL certificate.
Alternatively you could skip SSL completely and show the phishing page over standard HTTP, either method will work just fine since the client is talking to your server and not NatWest's.0 -
ah that's where you're wrong, we're not talking to the real nwolb server in my hypothesis.
Since there is a client side virus it could easily install a new root certificate into the computer's certificate store, then you simply produce an SSL certificate signed with your root cert and serve that up to the infected client, as far as IE or Firefox will know it's a valid SSL certificate.
Alternatively you could skip SSL completely and show the phishing page over standard HTTP, either method will work just fine since the client is talking to your server and not NatWest's.
http://www.trusteer.com/support/faqTo protect you against pharming attacks Rapport verifies the IP address and the SSL certificate of the website each time you connect to a protected website. If the verification fails, Rapport terminates the connection and establishes a new connection to the real website.
Edit: Just to clarify, I am asserting that it is not possible to fake the IP address in a TCP connection and it is not feasible to engineer a fake SSL certificate with a specified hash (I know there is an issue with MD5, but Natwest are using SHA1). One of those two is required to fool Rapport (assuming Trusteer's security people are not totally incompetent).
0 -
Which is why I use norton 360. However, I am dead cert on the correct webpage for online banking so I never ever really trust my anti-virus software.
Just added protection at best.Hi, we’ve had to remove your signature. If you’re not sure why please read the forum rules or email the forum team if you’re still unsure - MSE ForumTeam0 -
Hi,
thank you for the heads- up... i'm guessing this is also relevant to RBS online bank users as they use this rapport software as well? Cheers anyhow! :T
:mad: Hindsight is a wonderful thing...
:j One of Mike's Mob! yea!!!
Finally settled full balance of RBS personal loan ahead of schedule on 10th August 2010 :money:
DEBT FREE AT LAST... BUT FOR HOW LONG?! :eek:0 -
possible but unlikely, it's much simpler to modify the computer's hosts file to make the DNS address resolve to a different IP, frankly it's pathetic that Trusteer don't have a hard-coded list of IPs that the nwolb.com DNS address should resolve to
It would need more than that - Trusteer/Rapport works with a whole lot of other banks and other organisations - it's not hard wired to natwest0 -
Your hypothesis is wrong.
Edit: for those interested, I got the following report from the Rapport console:-The following IP addresses were tagged as suspicious. When you access a protected website, Rapport checks the IP address against a list of known good addresses for this website. If the address is not found in the list, Rapport replaces it with a known good address for the website. There is no action you need to take.- Mar 21 2010 20:18 IP address 216.239.61.104 doesn't match NatWest
I also found the following in the configuration options:-When you are browsing to a protected website Rapport checks the website’s SSL certificate. If the certificate is outdated, incorrect, or signed by unknown issuer Rapport triggers an alert that requires your action. Rapport’s SSL validation is stronger than the browser’s mechanism and should be used for Partner websites even if your browser warns about invalid certificates. SSL certificate validation prevents access to fraudulent websites.0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.7K Banking & Borrowing
- 253.4K Reduce Debt & Boost Income
- 454K Spending & Discounts
- 244.7K Work, Benefits & Business
- 600.1K Mortgages, Homes & Bills
- 177.3K Life & Family
- 258.4K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards