Boy-in-the-Browser Gets Aggressive By Evading Anti-Malware
London (UK), 6th June 2011 -- Imperva, a provider in data security, warns Boy-in-the-Browser (BITB) attacks are gaining force as they continue to evade traditional anti-malware software.
Tomer Bitton, from the Imperva Application Defense Center, explains, "Many are familiar with Man-in-the-Browser (MitB) attacks, but most are unaware of the lesser known Boy-in-the-Browser (BitB). Not as sophisticated as MitB, BitB malware has evolved from traditional key loggers and browser session records. The recent spate of BitB trojans that targeted Chilean banks, and their customers, demonstrates that this type of attack is gaining force and continues to evade traditional anti-malware software."
Talking you through the steps of an attack, Tomer outlines how it shapes up, "It all starts with a simple, innocent-looking phishing email that encourages the user to click a link to visit a website for more details. However, rather than then asking the user to divulge personal details – which most are now wise to, it instead tells the user that they need to download the latest version of Adobe Flash Player to view the page. Most users will be duped into believing this and will click the link.
"However, rather than receiving the latest version of Flash, they’re actually downloading malware.
"Once "installed" the flash-player Trojan writes itself to the registry, then asks the user to "Run" the programme, which allows it to survive the reboot and infects the machine. To avoid detection, the Trojan creates the new hosts file as read-only file." Explaining the consequences of having infected the machine with the malware, Tomer continues, "From this point, the malware overwrites the users file mapping of hostnames (URL) to network address (IP) mechanism. The next time the user tries to connect to a banking application, or other frequently visited URL, the Trojan instead redirects the user to a fake site controlled by the criminals, which mimics the real site. Often it is so cleverly done that the user would struggle to tell the difference. However it is here that the credentials are stolen, or the user is duped into completing a bogus transaction."
About Imperva: Imperva, a Data Security company, enables a complete security lifecycle for business databases and the applications that use them. Over 4,500 of the world’s leading enterprises, government organizations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognized for its overall ease of management and deployment.
Don't have a current membership with ContactCenterWorld.com?
become a member and connect with the rest of the Contact Center Industry at ContactCenterWorld.com here
Forum Profile
Job Title:
(Display this on the Forum)
Company:
(Display this on the Forum)
Neither the Administrators of these forums, or the Moderators participating, are responsible for the privacy practices of any user. Remember that all information that is disclosed in these areas becomes public information and you should exercise caution when deciding to share any of your personal information. Any user who finds material posted by another user objectionable is encouraged to contact us via e-mail. We are authorized by you to remove or modify any data submitted by you to these forums for any reason we feel constitutes a violation of our policies, whether stated, implied or not.
This site may contain links to other web sites and files. We have no control over the content and can not ensure it will not be offensive or objectionable. We will, however, remove links to material that we feel is inappropriate as we become aware of them.
By pressing the "Agree" button, you agree that you, the user, are 13 years of age or over. You are fully responsible for any information or file supplied by this user. You also agree that you will not post any copyrighted material that is not owned by yourself or the owners of these forums. In your use of these forums, you agree that you will not post any information which is vulgar, harassing, hateful, threatening, invading of others privacy, sexually oriented, or violates any laws.
If you do agree with the rules and policies stated in this agreement, and meet the criteria stated herein, proceed to press the "Agree" button below, otherwise press "Cancel".
If you have any questions about this privacy statement or the use of these forums, you can contact the forum administrator at: rajw@contactcenterworld.com