Developers: | Lime Systems |
Branches: | Financial services, investments and audit |
Technology: | Systems of remote banking |
The Ukrainian developer of the bank software, Lime Systems company, in the light of steadily growing popularity of Internet banking, held independent testing for penetration of the product iTiny at the end of 2012.
The information security audit was executed by specialists of QATestLab company. Under the agreement with the auditor the methodology of OWASP Top 10 2010 was selected, and the most critical points from methodology of OWASP Top 10 2007 were also taken into account. The methodology of OWASP is the standard de facto for holding procedures of security for web applications.
Based on the carried-out security tests it was established that the security level and resistance to unauthorized invasion conforms to requirements of OWASP Top 10 2010 and OWASP Top 10 2007. The web application Internet banking of iTiny showed high degree of security from invasions on a server part of the application. Also the vulnerabilities allowing to compromise the operating system of a hosting of the web application are not revealed.
It should be noted that according to different independent experts on information security — similar vulnerabilities — not a rarity, and meet including in bank Internet solutions. Therefore, it is very important that the developer company safeguarded both bank, and his clients.