EDITION:GLOBALNORTH AMERICACENTRAL & SOUTH AMERICAUK & IRELANDEUROPEMIDDLE EAST & AFRICAAUSTRALIA & NEW ZEALANDASIA
LANGUAGES:

Welcome
to ContactCenterWorld.com

Raj Wadhwani
President

President of Contact Center World
Wednesday, May 23, 2012
Learn the best practices in the industry from those who 'do the job' every day - click on Top Performers Conferences under conferences and events
OVER 129,000 MEMBERS

The Global Association for Contact Center Best Practices & Networking


Site Map
About this Site
Contact Us


 
 Pulse Survey

Global Benchmarking Study Promo

FEATURED SUPPLIERS
on ContactCenterWorld.com this week:

Global Benchmarking Study of Top Performers







Click on the company name for more details!


View:Folder:
Read:Page:
Order:Asc/Des:
To:CC:
Reply:Forward:
SearchP1:BCC:
Stack:
Error:
Boy-in-the-Browser Gets Aggressive By Evading Anti-Malware

London (UK), 6th June 2011 -- Imperva, a provider in data security, warns Boy-in-the-Browser (BITB) attacks are gaining force as they continue to evade traditional anti-malware software.

Tomer Bitton, from the Imperva Application Defense Center, explains, "Many are familiar with Man-in-the-Browser (MitB) attacks, but most are unaware of the lesser known Boy-in-the-Browser (BitB). Not as sophisticated as MitB, BitB malware has evolved from traditional key loggers and browser session records. The recent spate of BitB trojans that targeted Chilean banks, and their customers, demonstrates that this type of attack is gaining force and continues to evade traditional anti-malware software."

Talking you through the steps of an attack, Tomer outlines how it shapes up, "It all starts with a simple, innocent-looking phishing email that encourages the user to click a link to visit a website for more details. However, rather than then asking the user to divulge personal details – which most are now wise to, it instead tells the user that they need to download the latest version of Adobe Flash Player to view the page. Most users will be duped into believing this and will click the link.

"However, rather than receiving the latest version of Flash, they’re actually downloading malware.

"Once "installed" the flash-player Trojan writes itself to the registry, then asks the user to "Run" the programme, which allows it to survive the reboot and infects the machine. To avoid detection, the Trojan creates the new hosts file as read-only file."

Explaining the consequences of having infected the machine with the malware, Tomer continues, "From this point, the malware overwrites the users file mapping of hostnames (URL) to network address (IP) mechanism. The next time the user tries to connect to a banking application, or other frequently visited URL, the Trojan instead redirects the user to a fake site controlled by the criminals, which mimics the real site. Often it is so cleverly done that the user would struggle to tell the difference. However it is here that the credentials are stolen, or the user is duped into completing a bogus transaction."


Related Groups
Computer Hardware / Software
Performance
Security
Technology

Related News
Imperva Enhances Dynamic Profiling For Its Web Application Firewall
Stolen Government Certificate Signed Malware is an Upcoming Trend
Imperva Introduces Data Security for Microsoft SharePoint
Imperva Expands File Protection with Broad Data Loss Prevention Integrations
Imperva Introduces Cloud-based Web Application Firewall Service
Royal Wedding Presents Commercial Opportunity as Hackers Abuse Forthcoming Nuptials

About Imperva:
Imperva, a Data Security company, enables a complete security lifecycle for business databases and the applications that use them. Over 4,500 of the world’s leading enterprises, government organizations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognized for its overall ease of management and deployment.

More Editorial from Imperva
Imperva Enhances Dynamic Profiling For Its Web Application Firewall
Imperva Deconstructs Local and Remote File Inclusion Attack Vectors
Imperva Analyzes High-Profile ‘Anonymous’ Attack
Imperva Finds Business Logic Attacks Attractive To Hackers
Stolen Government Certificate Signed Malware is an Upcoming Trend
Imperva Introduces Data Security for Microsoft SharePoint

Date Published: Monday, June 06, 2011
Printer Friendly Version Printer friendly version
 Recommend to a friend
 Bookmark & Share



Post Message

Post Message






 

 

 





-Back To Top-

| Request Information from CRM & Contact Center Suppliers | About ContactCenterWorld |
| Advertise CRM & Contact Center Solutions | Link to this site |
| Submit CRM and Contact Center Content | Contact Us | Privacy Policy |
| Recommend this site to other CRM & Contact Center Professionals | Disclaimer |

©ContactCenterWorld.com 1999-2011
The Global Support Organization For Contact Center Professionals & the place for information on:
Help Desk Software, Internet Telephony (IP), IVR, Knowledge Management (KM), Metrics, Multimedia Contact Center, Offshore Outsourcing, On Hold, Outsourcing, Predictive Dialers, Quality Monitoring, Recruitment, Self Service, Speech Recognition, Telemarketing, Virtual Contact Center, VoIP, Web Chat