« Infiltrating Pushdo -- Part 1 | Main | Conference Stuff »

2010.02.18

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef0120a8adee95970b

Listed below are links to weblogs that reference Man in the Browser :

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Instead of offering a rss link how about a potential solution?or a link to a potential solution?

This technique might be 2 years old, but until it becomes so well known that even the bankers themselves know what to look for and become smarter about their browsing, then I will thank Atif Mushtaq
for his efforts and tell him to keep it up, as this will someday hopefully make its way to all bankers too!!!

Could the bank servers not refuse to open more than one session at a time? That is, if you have logged in, you should not be allowed to log in again until you have either logged out or timed out. That seems elementary, so what am I missing?

Here's something I've always wondered: Why don't the trojans just steal the cookie which is set during the MFA registration process, record the credentials (keystroke logger), and use the combination to login from elsewhere?

I find it hard to imagine that a trojan like Zeus can't find a way to get at stored cookies, even if there isn't an explicit API exposed.

it's not new; this technique is at least 2 years old

btw, the National Security Agency was recently hacked. Yes hacked! But it was downplayed to the media for obvious shameful reasons. Here’s the link :

http://pinoysecurity.blogspot.com/2010/02/wwwnsagov-hacked.html

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

Enter your email address:

Delivered by FeedBurner

Bookmark and Share

Twitter Updates

    follow me on Twitter

    In The News