May 2, 2006

New Tactics of SSL Evading Trojans

sw-0013ComputerWorld has a scary article about the strategies being utilized by some of the more advanced trojans to bypass SSL and even the most advanced authentication. Among the strategies they are using:

  • Stealing passwords via keystroke loggers, plus taking screen shots of secondary authentication mechanisms like on-screen keyboards.
  • Creating a man-in-the middle site on the users own computer and using that to harvest credentials, while still proxying them on to the real site.
  • And, my favorite, using the existing authenticated channel to the bank:

The Trojan then manipulates the underlying transaction, so that what the user thinks is happening is different from what’s actually transpiring on the site’s servers…When the user successfully authenticates, the Trojan opens a hidden browser window, reads the user’s account balance, and creates another hidden window that initiates a secret transfer.

I may be transferring all my money to First National Bank of the Mattress soon.

How SSL-evading Trojans Work

Share It: del.icio.us:New Tactics of SSL Evading Trojans digg:New Tactics of SSL Evading Trojans reddit:New Tactics of SSL Evading Trojans Y!:New Tactics of SSL Evading Trojans
Read More: Threats, Web, Crypto, Passwords, Phishing
Related: No related posts

3 Responses to “New Tactics of SSL Evading Trojans”

  1. Dakota Bolkestein Says:

    Thank you!

    August 27th, 2007 at 12:01 pm
  2. Cameron Wijers Says:

    You have an outstanding good and well structured site. I enjoyed browsing through it.

    August 27th, 2007 at 10:47 pm
  3. Brandon Castro Says:

    You have an outstanding good and well structured site. I enjoyed browsing through it.

    August 28th, 2007 at 5:57 am

Post a Comment...

(required)

(required)
(will not be published)

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>