TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Revolut's botched BIC update

1 pointsby bendlasover 7 years ago

1 comment

bendlasover 7 years ago
or: The blog post, Revolut doesn&#x27;t want you to read ;o)<p>or: How Revolut self-owned by ways of XSS<p>That page was presented to me as an in-app communication, that I noticed after not getting through a transfer to my debit card and I wanted to to get the url, to send to my bank. After failing to google it, I noticed a tag below the article, saying `unlisted`.<p>Not being easily frustrated by such a feeble attempt, I cranked out android-studio and apktool, but stopped after tracking a build error (in my attempt at recompiling for debug), back to a ticket in something called apk-backdoor ...<p>It seems, like Revolut at least has their basic security measures right. At that point, I also want to applaud Revolut for communicating openly with their customers, even if not posting this publicly seems ridiculous to me.<p>So how did I actually get at the url? Logcat? Binary disassembly? MITMing myself? Nope. I just pushed the floating `open in app` button, which triggered a 404 page with a broken Medium in-app link. &lt;lol.gif&gt;<p><a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;eRaTZ" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;eRaTZ</a>