• Home
  • Advertise
  • Contact Us
  • Free eBooks
  • Infographics
  • About Us


  • Technology
    • Programming
      • Java
      • PHP
      • HTML
      • CSS
      • Javascript
      • XML
      • AJAX
      • JQuery
      • Perl
      • IDE
    • CMS
      • Opencart
      • WordPress
      • Prestashop
      • Magento
    • Database
  • Security
    • Cyber Laws
    • Digital Signature
    • Passwords
    • Reverse Engineering
    • Steganography
    • Forensics
    • Networking
  • E-Commerce
  • Digital Media
    • SEO
    • Social Media
      • Facebook
  • Gadgets
    • Laptops
    • Tablets
    • Just CellPhones
    • Social CellPhones
  • OS
    • Linux
    • Mac
    • Windows
    • iOS
    • Android
  • Courses
    • Development in Android
  • General

Breaking

The supercomputer "Tianhe-2" Takes No. 1 Ranking on 41st TOP500 List

Export tweets in different formats

OWASP - Top 10 Vulnerabilities

New Windows-backdoor deletes MBR

The world's first CPU of 5GHz

Critical vulnerability in 60 + models of CCTV and IP-cameras

Hack a Samsung TV with SmartTV function

The man who "almost broke the Internet"

The search continues for the sixth member of LulzSec

Statistics on the botnet Carna


Hacker published code to steal advanced banking data

0 Comment
 19 Dec 2011   Posted by synt4x

1 Star2 Stars3 Stars4 Stars5 Stars
Loading ... Loading ...


flattr this!

Hacker posted code for a powerful attack XSS, which, as stated, goes beyond the usual cookie theft or sale of phishing to steal personal information.

Cross-site scripting vulnerability (XSS) allows hackers to control the content of the vulnerable, but still a trusted site, passing critical information to cybercriminals. In addition to creating tools for popup windows that are controlled by hackers on websites, XSS can also lead to theft of cookies.

Nicklas Femerstrand – a hacker who in October 2011 found that the mechanism of debugging American Express site was vulnerable to this kind of vulnerability . He developed the so-called “XSS on steroids” script by examining a similar vulnerability to the site of one of the Swedish banks.

“There are common myths about XSS, which can be used for phishing and cookie collection,” – he said.”My code destroys these myths and converts non-permanent XSS in something sustainable.”

“I have created code that defines its own existence and locally infects the payload, all references to the web site visitor. In this case, becomes a permanent non-permanent XSS for him. It also monitors the behavior of the user and sends an attacker interesting information (logins, passwords, credit card information), “- he added.

Femerstrand published his code on this site last week.

Rick Ferguson, director of security research and communications at Trend Micro, has confirmed that the script is designed Ferestrandom is a bigger threat than expected, but there are questions about whether the idea of a hacker innovative. Ferguson said that this technique had already existed for some time and was introduced in beefproject.com .

In response to this statement Femerstrand said: “I heard about BeEF, but only in passing. I did not know that they use a similar technique, and I did not come across in my eyes any documents on this topic. I saw them a keylogger can not distinguish between an input line from one another, and instead of entering what has been published, introduces anything that is on the page. I have never used BeEF, but personally I think the project is too bloated. ”

He noted that the publication of the code was logical, since it has identified inadequate security gaps in banking institutions.

“The original code was written as a proof of how easy it is to rob a bank now,” – he wrote. ”I see that banks are mocking people. Banks are serious enough to safety. But when a man sees a sign standard PCI DSS, he thinks that the bank does its job well, but in fact, anything that makes such standards – Issue logo “We confirmed the same,” and check the 4-digit PIN codes there. ”

“Modern banks know that in case of bankruptcy, the government will provide them with financial support. I am convinced that the publication of the code – the right decision, because it highlights the practical importance of financial security,” – added Femerstrand.

Spread The Word:

  • Facebook
  • Twitter
  • Pinterest
  • StumbleUpon
  • Google +1
  • Digg
  • Reddit
  • Email
  • LinkedIn
  • Tumblr
    Share This


Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • Find Us On Facebook

  • Airtel Hello Tunes

  • Ads.

  • Ads.

  • Shrugs Online


  • More...

    • Advertise
    • Crawl Fashion | Fashion Directory
    • Information Technology Act 2000 Compliance [Sec 43A and Sec 72A]
    • Java Tutorial
    • Netbeans Tutorial
    • Photography Blogs
    • Street Shopping
    • Virus Protection And Internet Security
  • Recent Posts

    • OWASP - Top 10 Vulnerabilities
    • New Windows-backdoor deletes MBR
    • Critical vulnerability in 60 + models of CCTV and IP-cameras
    • Hack a Samsung TV with SmartTV function
    • The man who "almost broke the Internet"
    • The search continues for the sixth member of LulzSec
  • Enter your email address to subscribe to "Bytes" Mag & receive THE latest updates on Tech!


Copyright © LetsByteCode Inc.
DMCA.com
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.