<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on Man in the Browser </title>
	<subtitle></subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on Man in the Browser " href="http://blog.fireeye.com/research/2010/02/man-in-the-browser/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="Man in the Browser " href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2010-02-17T21:19:07Z</updated>
	<author>
		<name>FireEye</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2010/02/man-in-the-browser/comments/atom.xml/</id>
    
		<entry>
			<title>Atif Mushtaq commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="Joshua, Let me clear few things here. What I said was like this: &quot;Man in the Browser a.k.a MITB is..." href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef01311009a89d970c#comment-6a00d835018afd53ef01311009a89d970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01311009a89d970c</id>
			<published>2010-04-01T21:06:39Z</published>
			<updated>2010-04-01T21:06:39Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>Joshua, Let me clear few things here. What I said was like this: &quot;Man in the Browser a.k.a MITB is...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;Joshua,&lt;br /&gt;
Let me clear few things here. What I said was like this:&lt;/p&gt;

&lt;p&gt;&amp;quot;Man in the Browser a.k.a MITB is a new breed of attacks whose primary objective is to spy on browser sessions (mostly banking) and in that process intercept and modify the web page contents transparently in the background&amp;quot;&lt;/p&gt;

&lt;p&gt;MITB technique may be old, but modern malware actively using it, is something relatively new and this is what I was meant by saying &amp;quot;new breed of attacks&amp;quot; (not technique). Zbot recently added support for MITB attack, same is true for Torpig and Clampi. URLZone is also a very new malware, just discovered in late 2009.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Joshua Akira commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="Forgive the correction, but MITB has been around since the 90&#39;s at least. Remember the plethora of &quot;free popup blockers&quot;..." href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef013110079785970c#comment-6a00d835018afd53ef013110079785970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef013110079785970c</id>
			<published>2010-04-01T13:38:57Z</published>
			<updated>2010-04-01T13:38:57Z</updated>
			<author>
				<name>Joshua Akira</name>
                
			</author>
			<summary>Forgive the correction, but MITB has been around since the 90&#39;s at least. Remember the plethora of &quot;free popup blockers&quot;...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;Forgive the correction, but MITB has been around since the 90&amp;#39;s at least.  Remember the plethora of &amp;quot;free popup blockers&amp;quot; and other browser toolbars?&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>J Cooper commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="Instead of offering a rss link how about a potential solution?or a link to a potential solution?" href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef0120a8c88742970b#comment-6a00d835018afd53ef0120a8c88742970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a8c88742970b</id>
			<published>2010-02-23T15:25:04Z</published>
			<updated>2010-02-23T15:25:04Z</updated>
			<author>
				<name>J Cooper</name>
                
			</author>
			<summary>Instead of offering a rss link how about a potential solution?or a link to a potential solution?</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;Instead of offering a rss link how about a potential solution?or a link to a potential solution?&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>L A commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="This technique might be 2 years old, but until it becomes so well known that even the bankers themselves know..." href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef01310f2f435f970c#comment-6a00d835018afd53ef01310f2f435f970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f2f435f970c</id>
			<published>2010-02-23T15:08:17Z</published>
			<updated>2010-02-23T15:08:17Z</updated>
			<author>
				<name>L A</name>
                
			</author>
			<summary>This technique might be 2 years old, but until it becomes so well known that even the bankers themselves know...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;This technique might be 2 years old, but until it becomes so well known that even the bankers themselves know what to look for and become smarter about their browsing, then I will thank Atif Mushtaq&lt;br /&gt;
for his efforts and tell him to keep it up, as this will someday hopefully make its way to all bankers too!!!&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Tom Welsh commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="Could the bank servers not refuse to open more than one session at a time? That is, if you have..." href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef0120a8c8683f970b#comment-6a00d835018afd53ef0120a8c8683f970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a8c8683f970b</id>
			<published>2010-02-23T14:58:24Z</published>
			<updated>2010-02-23T14:58:24Z</updated>
			<author>
				<name>Tom Welsh</name>
                
			</author>
			<summary>Could the bank servers not refuse to open more than one session at a time? That is, if you have...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;Could the bank servers not refuse to open more than one session at a time? That is, if you have logged in, you should not be allowed to log in again until you have either logged out or timed out. That seems elementary, so what am I missing?&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Oasisbob commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="Here&#39;s something I&#39;ve always wondered: Why don&#39;t the trojans just steal the cookie which is set during the MFA registration..." href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef0120a8c65d42970b#comment-6a00d835018afd53ef0120a8c65d42970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a8c65d42970b</id>
			<published>2010-02-23T03:55:18Z</published>
			<updated>2010-08-14T21:52:15Z</updated>
			<author>
				<name>Oasisbob</name>
                <uri>http://profile.typepad.com/oasisbob</uri>
			</author>
			<summary>Here&#39;s something I&#39;ve always wondered: Why don&#39;t the trojans just steal the cookie which is set during the MFA registration...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;Here&amp;#39;s something I&amp;#39;ve always wondered: Why don&amp;#39;t the trojans just steal the cookie which is set during the MFA registration process, record the credentials (keystroke logger), and use the combination to login from elsewhere? &lt;/p&gt;

&lt;p&gt;I find it hard to imagine that a trojan like Zeus can&amp;#39;t find a way to get at stored cookies, even if there isn&amp;#39;t an explicit API exposed.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>old commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="it&#39;s not new; this technique is at least 2 years old" href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef01310f1f5e01970c#comment-6a00d835018afd53ef01310f1f5e01970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f1f5e01970c</id>
			<published>2010-02-19T22:59:43Z</published>
			<updated>2010-02-19T22:59:43Z</updated>
			<author>
				<name>old</name>
                
			</author>
			<summary>it&#39;s not new; this technique is at least 2 years old</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;it&amp;#39;s not new; this technique is at least 2 years old &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>IT Ninja commented on &#39;Man in the Browser &#39;</title>
			<link rel="alternate" type="text/html" title="btw, the National Security Agency was recently hacked. Yes hacked! But it was downplayed to the media for obvious shameful..." href="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html?cid=6a00d835018afd53ef0120a8b5c453970b#comment-6a00d835018afd53ef0120a8b5c453970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a8b5c453970b</id>
			<published>2010-02-19T10:17:40Z</published>
			<updated>2010-02-19T10:17:40Z</updated>
			<author>
				<name>IT Ninja</name>
                
			</author>
			<summary>btw, the National Security Agency was recently hacked. Yes hacked! But it was downplayed to the media for obvious shameful...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/man-in-the-browser.html">&lt;p&gt;btw, the National Security Agency was recently hacked. Yes hacked! But it was downplayed to the media for obvious shameful reasons. Here’s the link :&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://pinoysecurity.blogspot.com/2010/02/wwwnsagov-hacked.html&quot; rel=&quot;nofollow&quot;&gt;http://pinoysecurity.blogspot.com/2010/02/wwwnsagov-hacked.html&lt;/a&gt;&lt;/p&gt;</content>
		</entry>
	
</feed>

<!-- ph=1 -->