HZGN.COM
welcome to my space
X
Search:  
Welcome to:hzgn.com
NAVIGATION - HOME

From Russia With Larceny

Published by: jane 2009-01-08

Finjan, a developer of Web security products, has found what has to be the nastiest of malware yet because it inserts itself into a legitimate online banking transaction that's supposed to be protected by SSL encryption.

The company is calling this new form of thievery "crimeware," as if we needed another term to keep straight, but it's nasty stuff. In just the month of July, Finjan identified 58 criminals using the MPack toolkit to infect over 500,000 unique users.

MPack may be the most dangerous malware development kit seen yet. It is a PHP-based kit produced by Russian hackers for building mostly keylogging software. It's actually sold and supported by the Russians, complete with a service contract for new versions, and is upgraded every two to four weeks. It's not the first time a service contract has been offered for software that supports the spread of malware.

What makes MPack so nasty is that people using it hide it not on porn sites or sites with cracks and serial numbers for software, but on legitimate news and information sites that people just don't think will be infected. Earlier this year, the Web site for Dolphin Stadium, site of the Super Bowl, was compromised.

Restoration in Russia: Much Needed and Inevitable - Politics::
Restoration in Russia: Much Needed and Inevitable plus articles and information Ted Sihpol on 29 of 33 counts over the charges of grand larceny and fraud.
http://www.advancingwomen.com/politics/15718.php
HOME
The goal of these Trojans is theft of intellectual property, as well as your bank account. "We've seen Trojans that were looking for AutoCAD files," Yuval Ben-Itzhak, CTO for Finjan, told Internetnews.com.

"What info could you want there? Likely product designs. We're not always sure what is the exact interest in collecting this data, but if someone wrote this software, tested it and deployed it, they probably have a good reason to send it out," he added.

But the worst that Finjan has seen as yet involves an MPack-based Trojan that inserts itself into the online banking page of a popular bank – Finjan was asked not to disclose which banks – and asks for additional information than just the login and password.

According to Finjan, the crimeware it's seen on user's computers can recognize which bank Web site they were on and would intercept communication between the client and server to insert data entry boxes onto the Web page. The false data entry boxes mimicked the exact style of the bank so they looked totally legitimate, except they asked for things like credit card numbers with the CVV, social security numbers and ATM PINs.

If the user was not so eagle-eyed and entered the information, they would never know they were robbed, as the legitimate logon information was sent to the bank, so the transaction continued as normal, while the extra, stolen information was sent elsewhere.

All of this worked while the user has established a secure connection to the bank via SSL (define). In fact, the SSL connection was also used to send the stolen information, which Finjan traced to a server in Panama.

"In all of my years in computer security I've never seen anything like it, it was so well-done," said an astonished Ben-Itzhak. He said the MPack-based crimeware can even remove itself from your computer so you never knew it was there.

What Ben-Itzhak found troublesome was the lack of detection for MPack. In July 1, Finjan queried VirusTotal, a Website that tracks more than 30 antivirus programs and determines which are able to detect a piece of malicious code and which don't see it. Only six of the 32 recognized it.

When he checked again on July 29, it was still only vendors that saw it. Fortunately, two of the six were Panda Software and Symantec, which are widely used in the enterprise.

Other security vendors need to get on the stick, because MPack is "getting huge visibility in the market. It's being used everywhere," said Ben-Itzhak.


Red Hat's Rough Recovery From CFO Exit
Windows Live Finds a New, Pre-installed Home

PRINT Add to favorites
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about From Russia With Larceny , Please add it free.
  • did anyone hear the story about the guy posting his suicide on you tube
  • why is it that so many boys hate the jonas brothers
  • did you record sky the channel 4 dispatches documentary rich kid poor kid i will pay for a copy
  • does anyone know how to get vip passes backstage to the hannah montana concert at the jobing com arena
  • where can i get jonas brothers
  • new hairstyles
  • why does disneyland
  • ac dc black ice tour merchandise
  • does my employer have to honor a verbal job offer
  • why do people say jim jones was crazy
  • jonas brothers coming to ohio
  • what are the correct songs words for 103 9 cisn 92 5 joe in edmonton for thursday november 27th
  • what is a good gift to give the jonas brothers
  •  
  • am i actually in love
  • all jonas brothers fans please read d
  • good cheap japanese food in downtown toronto
  • pirates taking over ships a question about it
  • im 18 and want a job please help me think of some places to apply as many as u can think of please
  • online radio were i can choose genre
  • i want to watch the movie 3000 miles with bam margera online but i cant find a website to
  • how do i get to know the jonas brothers
  • what is the name of the hospital in hawaii in which obama was born
  • are poverty drug abuse and welfare on obama 039 s list for change
  • where you listening to rush limbaugh today nov 25
  • who else think hillary clinton is very hot in this pic wonder why bill cheated on her she 039 s gorgeous
  • jonas brothers back stage
  • is the introduction of id cards a waste of taxpayers money
  • About us |Contact us |Advertisement |Site map |Exchange links
    Copyright© 2008hzgn.com All Rights Reserved