<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on MITB (Man in the Browser) Protection Layers</title>
	<subtitle></subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on MITB (Man in the Browser) Protection Layers" href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="MITB (Man in the Browser) Protection Layers" href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2010-02-25T20:48:57Z</updated>
	<author>
		<name>FireEye</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2010/02/mitb_protection_layers/comments/atom.xml/</id>
    
		<entry>
			<title>Johan commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="Well, I do keep my banking application on its own virtual machine that I use for nothing else (I only..." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef01310f5383bc970c#comment-6a00d835018afd53ef01310f5383bc970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f5383bc970c</id>
			<published>2010-03-02T17:11:56Z</published>
			<updated>2010-03-02T17:11:56Z</updated>
			<author>
				<name>Johan</name>
                
			</author>
			<summary>Well, I do keep my banking application on its own virtual machine that I use for nothing else (I only...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;Well, I do keep my banking application on its own virtual machine that I use for nothing else (I only have it turned on for the time I&amp;#39;m using the banking application). I&amp;#39;m sure this is very good practice but not everybody is a sysadmin...&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="Johan ------ End of the day there will be some application running on the vulnerable system making all these transactions...." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef01310f4e6bb5970c#comment-6a00d835018afd53ef01310f4e6bb5970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f4e6bb5970c</id>
			<published>2010-03-01T19:47:54Z</published>
			<updated>2010-03-01T19:47:54Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>Johan ------ End of the day there will be some application running on the vulnerable system making all these transactions....</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;Johan&lt;br /&gt;
------&lt;br /&gt;
End of the day there will be some application running on the vulnerable system making all these transactions. You are assuming that this application would be more secure than browser. I don&amp;#39;t think so! It&amp;#39;s not very difficult in windows to change values in the memory of any external process. Attacker can hook into windows message queue and wait for the user to do some transactions, and right before these values are going to be encrypted, change the legitimate account information with one of his money mules accounts. Similarly it&amp;#39;s not difficult to launch this application in hidden mode and problematically perform the complete transaction.  &lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="Daniel ------ Paper based codes are just like &#39;Safety Pass&#39; based random code. We already know how attacker might hijack..." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef01310f4e6205970c#comment-6a00d835018afd53ef01310f4e6205970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f4e6205970c</id>
			<published>2010-03-01T19:40:19Z</published>
			<updated>2010-03-01T19:40:19Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>Daniel ------ Paper based codes are just like &#39;Safety Pass&#39; based random code. We already know how attacker might hijack...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;Daniel&lt;br /&gt;
------&lt;br /&gt;
Paper based codes are just like &amp;#39;Safety Pass&amp;#39; based random code. We already know how attacker might hijack such codes with simple social engineering. Apart from that, it can&amp;#39;t protect user against transaction manipulation MITB.   &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="Thanks guys for these suggestions. But I find slight problems with each of the above techniques..Let me explain one by..." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef0120a8e77916970b#comment-6a00d835018afd53ef0120a8e77916970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a8e77916970b</id>
			<published>2010-03-01T19:31:58Z</published>
			<updated>2010-03-01T19:31:58Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>Thanks guys for these suggestions. But I find slight problems with each of the above techniques..Let me explain one by...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;Thanks guys for these suggestions. But I find slight problems with each of the above techniques..Let me explain one by one.&lt;/p&gt;

&lt;p&gt;Ali&lt;br /&gt;
----&lt;br /&gt;
The only problem I found is that user might also end up handing this secret question to the attacker.&lt;/p&gt;

&lt;p&gt;1. User gets a fake SMS from the attacker, pretending to be bank and asking about this secret question. Just like user fooled into giving these secret questions to the attacker while MITB attack. He may hand it over again.&lt;/p&gt;

&lt;p&gt;2. User might select a secret question which is already compromised or already known to the attacker.&lt;/p&gt;

&lt;p&gt;But yes this technique would further improve things a bit but on the cost of more inconvenience to the user. If user would have to enter it again and again. He might get used to it so much that he would simply learn to enter it always.   &lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Johan commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="Am I more secure using an application that establishes its own VPN tunnel with the bank server, instead of using..." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef01310f4cec43970c#comment-6a00d835018afd53ef01310f4cec43970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f4cec43970c</id>
			<published>2010-03-01T14:28:33Z</published>
			<updated>2010-03-01T14:28:33Z</updated>
			<author>
				<name>Johan</name>
                
			</author>
			<summary>Am I more secure using an application that establishes its own VPN tunnel with the bank server, instead of using...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;Am I more secure using an application that establishes its own VPN tunnel with the bank server, instead of using a web browser? I have always felt more secure, because there is no browser involved...&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Daniel Lohin commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="I think an easier method is what some European banks do. Send a One time key paper to the user...." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef01310f4cb965970c#comment-6a00d835018afd53ef01310f4cb965970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01310f4cb965970c</id>
			<published>2010-03-01T13:37:06Z</published>
			<updated>2010-03-01T13:37:06Z</updated>
			<author>
				<name>Daniel Lohin</name>
                
			</author>
			<summary>I think an easier method is what some European banks do. Send a One time key paper to the user....</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;I think an easier method is what some European banks do.  Send a One time key paper to the user.  This paper just contains random keys like xcdse23.  A user starts at the top left and each time one of these keys is used, they cross it out and move on to the next one.  This has a few benfits, it is pretty cheap.  I think it is easier then having the user do a Ceasar Cipher.  I know that this One Time key approach is using the definition a little off, because you would need enough characters to encrypt all the data.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Ali Islam commented on &#39;MITB (Man in the Browser) Protection Layers&#39;</title>
			<link rel="alternate" type="text/html" title="Atif, Good article, you have treated the topic very well. I would like to propose another solution to technique_1. Solution..." href="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html?cid=6a00d835018afd53ef0120a8e5d8bf970b#comment-6a00d835018afd53ef0120a8e5d8bf970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a8e5d8bf970b</id>
			<published>2010-03-01T13:30:14Z</published>
			<updated>2010-03-01T13:30:14Z</updated>
			<author>
				<name>Ali Islam</name>
                <uri>http://aliislam.wordpress.com</uri>
			</author>
			<summary>Atif, Good article, you have treated the topic very well. I would like to propose another solution to technique_1. Solution...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/02/mitb_protection_layers.html">&lt;p&gt;Atif,&lt;/p&gt;

&lt;p&gt;Good article, you have treated the topic very well. I would like to propose another solution to technique_1.&lt;/p&gt;

&lt;p&gt;Solution --&amp;gt; Instead of just asking for plain acknowledgment via SMS, the bank should ask for an answer to a &amp;quot;secret question&amp;quot;. With that done, even if the attacker successfully changes the Safety Pass (using MITB) to his own mobile, he cannot answer that secret question and hence can&amp;#39;t do the illegal transaction.&lt;/p&gt;

&lt;p&gt;It may not be the perfect solution but so far I don&amp;#39;t see any problem with it.&lt;/p&gt;

&lt;p&gt;cheers,&lt;br /&gt;
Ali&lt;/p&gt;</content>
		</entry>
	
</feed>
<!-- ph=1 -->
<!-- nhm:from_kauri -->