SECURITY AND CONFIGURATION

       I.SECURITY

A. What kind of security is used on eSGBL ?

1. 128-bit SSL communication protocol

SGBL uses SSL (Secure Sockets Layer) with 128-bits encryption (such technology provides the best protection level available on the internet currently). SSL technology uses Secure Servers, Digital Certificates and Encryption to ensure security and integrity of all eSGBL transactions. To access eSGBL, you will need a 128 bits encryption enabled browser.

You can easily verify whether you are on a secured site, since an “s” should always appear in the address bar of your browser window after “http”. Thus, after accessing your accounts the URL address should start by :
« https://www.esgbl.com/fr/... » such as the sign in page which is « https://www.esgbl.com/fr/idehom.html »

If your browser does not support SSL 128-bit, the message "We page cannot be displayed ..." will appear on the page.

Back to table of content 

2.  The security of your access thanks to your ID number (numéro d’abonné) and your password

You should memorize your ID number (numéro d'abonné) and your password and never disclose them to anybody. You must be the only one who knows your password;  you can modify it as many times as you want and we advise you to change it regularly. Any change will take effect immediately.

All the password entry errors are registered. After three failed attempts, access is blocked. To unblock your access, you will need to contact your branch. Your customer representative can unblock it immediately during working hours from Monday till Friday from 8:00 AM till 5:00 PM (Beirut time) and on Saturday from 8:00 AM till 1:00 PM.

Some recommendations on the use of your password :

  • Do not disclose your password to anyone either face to face, by telephone or in writing, even to anyone who is purportedly an SGBL representative.

  • Do not enter your password anywhere else except in the secured area of the website.

  • Change it regularly regularly, at least twice a year.  

  • Do not use number sequences or dates of birth in passwords; a mixture of letters and numbers is the most secure type of password.

Do not forget to deactivate the auto-complete option of your browser since it saves some of your personal information, the procedure is different according to the browser you use. Do not hesitate to ask for our technical assistance of check the FAQ section of the site.

Back to table of content

3.  Disconnection of the site

You are automatically disconnected if you stop using the service for 5 minutes. If you wish to reconnect, you should reenter your ID number and password.
No eSGBL page will be kept in the memory of your browser (in the cash).
SGBL recommends you to click on "end session" (in the menu on the left of the screen) when your are done using eSGBL.
If you are checking on your accounts at a public place with shared computers (Internet café, .....), we highly recommand you to use the "end session" button to quit the online service.

Back to table of content 

4.  Your browser's messages

When your are surfing from a secured page (https) to a non secured page (http), your browser will display a message such as the one here below:

This standard message is not related to eSGBL and indicates that you are about to leave a secured page to enter a non secured page. You can click on "Yes
".

Back to table of content

 

B. What are the common risks of fraud on the banking sites ? 

1.  Spoof emails : spoofing and phishing

a. What you need to know

Phishing is the practice whereby fraudsters send emails in the name of an institution or bank and invite users to visit a look-alike site which is made to resemble a legitimate website. This bogus website is generally used to obtain confidential information from users, such as their account passwords.

b. How to protect ?

First, check the mail's transmitter identity : often, it can present small differences with the one of the official site :for example www.esbgl.com instead of www.esgbl.com
As a precaution, you should always type the URL of your site in the address bar of your browser or select the site from your Favourites list (to store the homepage in your favourites list, click “Add to Favourites” in the “Favourites” menu of your browser). Avoid using a link to your transactional site.

Back to table of content
 

When you consult a secure site (whose address starts from http s://), you should verify the certificate of the site.
For instance, when you are consulting your accounts on our site: On the login page, enter the menu "File" of your browser, and select the option "Properties":



The following screen will appear. Verify that the “Connection” area shows:
- SSL v3.0 or TLS v1.0
- RC4 or AES
- 128-bit (or higher) encryption

Back to table of content 



 

Click on the button Certificates
Verify that the General tab shows:
  • Delivered to: www.uabbank.com
  • Delivered by: Thawte Server CA
     

Back to table of content

Verify that the Access tab shows :
Thawte Server CA
This certification is OK

Back to table of content

2. Viruses and Trojan horses

a. What you need to know

Viruses are malicious programs that destroy essential files or overload the resources of the machine. A newer type of virus has also emerged: worms. These are self-replicating programs that duplicate themselves by means of computer networks. Trojan horses are programs that, once in your computer, can consult data in files, modify files or destroy them. It can remain inoffensive, as part of a game or utility program for example, until the pre-programmed date.

b. How can I protect my computer ?

  • The only way to protect your computer from viruses, Trojans and worms is to install an anti-virus software and to update it regularly.

  • Always keep your system and softwares up to date.

  • Install a personal firewall (1) and keep it up to date.

  • More generally, do not open any email that you suspect is unsolicited (coming from someone to whom you didn’t give your email address for example) Also don’t open or download email attachments if you don’t know its content, even if you know his sender: in fact, the virus can be propagated without this person‘s knowledge.
  • If you have any queries or concerns about eSGBL or www.sgbl.com.lb, you can contact our assistance service

    • By phone at  961 3 477777 : Our customer representatives will answer you from Monday till Friday from 9:00 AM till 6:00 PM and Saturday from 9:00 AM till 1:00 PM

    • Through the following e-mail addresses: « webmaster1@sgbl.com.lb » and « webmaster2@sgbl.com.lb » 

    • By filling the hotline form on the menu on the left.

(A firewall is a software program which allows selective transmission of data flows between your PC and the internet, and blocks all intrusion attempts by unauthorized programs/users .

Back to table of content

 

       II.CONFIGURATION

« eSGBL » is compatible with "DOM" norms implemented by W3C (World Wide Web Consortium).

All navigators that comply with these norms can access eSGBL :

  • The browsers confirmed and tested by SGBL:

• For Windows users: Internet Explorer should be higher than 5.50 or Netscape higher than 4.75
• For Macintosh users: Internet Explorer should be higher than 5.50 or Netscape higher than 4.77 and English version

However, other configurations can also work but are not guaranteed by SGBL:

  • Non tested browser compatible with W3C

  • Non authorized browsers: not compatible with W3C or not in accordance with the security standards of Société Générale de Banque au Liban

To use the functionalities offered by eSGBL your browser should dispose of external modules or « Plug-ins » :

  • Macromédia Flash player

  • Java

eSGBL uses "cookies" that contain the necessary information in order to manage properly your connection. Therefore, you should accept them on your browser. They will be kept in the memory during your eSGBL session. Make sure your browser knows how to manage them and that its settings will accept them.

To verify your browser configuration, we invite you to access the FAQ section on the left sided menu on the homepage.

Back to table of content