Beyond Phishing - Cronto Shows the Growing Threat of Internet Banking FraudBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/7 8:22:57
2009/11/7 8:22:57
2009/11/7 0:09:48
2009/11/6 20:09:28
Our Partners
Downloads
Identity Theft - Phishing : Beyond Phishing - Cronto Shows the Growing Threat of Internet Banking Fraud
Posted by Max on 2008/4/29 17:29:51 (1106 reads)
Identity Theft - Phishing

Banking security specialists Cronto have published a guide to help demystify the latest threats to web banking services. Much publicity has been given to ‘phishing’ but the threat has now moved up to a much more sophisticated and worrying level.

Until recently, ‘phishing’ attacks simply used stolen access credentials (i.e. passwords and PINs etc) to fraudulently remove money from customers accounts. Banks strengthened their access security to defend against this type of attack.

Criminals have now developed this attack by tampering with the customer’s connection to the bank. There is no need to ‘phish’ for the banks account details as they can steal the customer’s money while he is legitimately connected to the bank. The customer will never know the attack has occurred – until their money has been removed.

These new types of attack are known as ‘Man in the Middle’ and ‘Man in the Browser’. They are highly sophisticated frauds and can be used to systematically attack thousands of customers. Kits to perform these types of attack are being manufactured by the criminal community.

With a ‘Man in the Middle’ attack the criminal creates a copy of a banks web site which he then tricks the customer to visit. The criminal passes through all information to the bank’s real web site so the customer is unaware of the attack, but the criminal has the opportunity to modify the conversation and remove funds from the customers account. If the customer is vigilant he might spot the fake address of the attacking site but this type of fraud has already proved dangerously effective.

‘Man in the Browser’ is even more destructive than ‘Man in the Middle’. In this case the criminal downloads a Trojan into the customer’s browser. A Trojan is a sophisticated piece of software that can control the customer’s PC, including the browser.

This attack works in the same way as ‘Man in the Middle’ with the Trojan modifying the customer’s conversation with their bank during a legitimate session. Neither the customer nor the bank will be aware of this type of attack.

A recent ‘Man in the Browser’ Trojan was programmed to attack over 400 banks and once in the customer’s computer could even be automatically updated by the criminal to add new banks’ details. This Trojan was designed to be downloaded into hundreds of thousands of PCs and attack every customer’s bank account.

Sophisticated systematic attacks like these are far more threatening to the security of web banking services than simple ‘phishing’. Banks are now developing new defences against this type of attack.

The only way to completely defend against ‘Man in the Middle’ and ‘Man in the Browser’ attacks is to authenticate every important instruction the customer sends to the bank. The security effectively moves down from protecting the ‘front door’ at login to protecting each individual instruction.

The problem has always been in finding an effective means of doing this without making the system unusable for the customer. Fiddly hand held authenticators, already introduced by some banks, are not the right solution.

Cronto had developed a unique solution based on its innovative visual cryptogram which secures transactions without requiring codes to be entered into fiddly authenticators. The customer, for example, can use the camera in his mobile phone to authenticate important instructions to his bank.

What is clear is that the criminal world has turned its attention to web banking and banks cannot delay any longer the introduction of transaction authentication of individual instructions.

Cronto’s guide ‘Beyond Phishing – De-mystifying the growing threat of Internet banking fraud’ can be downloaded free of charge from the Cronto website http://www.cronto.com

About Cronto Limited:
Cronto Limited is a leading provider of secure visual transaction authentication solutions for online banking based upon visual signing technology born out of leading edge engineering research undertaken at the University of Cambridge.

Cronto's mission is to facilitate the deployment of secure solutions that both meet the approval of the customers that use them, and can be deployed cost-effectively and in confidence by any banking organisation.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.

Poster Thread
salma529
Posted: 2009/2/6 7:18  Updated: 2009/2/6 7:18
Just popping in
Joined: 2009/2/5
From:
Posts: 6
 Re: Beyond Phishing - Cronto Shows the Growing Threat of ...
Hello. Visite mi sitio con chicas: espanacams en vivo