Finjan Web Security Trends Report – Q3/2007

Finjan has released it’s Web Security Trends Report – Q3/2007 (PDF) and I found it quite interesting to read.
One of the innovative research presented in the report is the security model and risk posed by the various widgets which seem to be the hottest trend in GUI design.Either built for WWW, Windows Vista or Macintosh OSX Dashboard,the widgets are everywhere and Finjan found vulnerabilities in widgets and gadgets that enable attackers to gain control of user machines.
This report also presents a detailed analysis of a very special malware : the financial data trojan which gets activated whenever an user does internet banking or logs in a financial institution website . "Financially-focused crimeware – what happens when a trojan goes phishing" shows step by step all the Crimeware Trojan Workflow :
- Detect login page to a financial service
- Send the login credentials to the financial service as well as the crimeware server
- Crimeware server response contains custom designed page to get more sensitive information (designed for the service provider)
- Crimeware on infected PC injects the custom page into the browser (which is already connected via SSL to the financial provider)
- Victim enters sensitive data into customized form
- Crimeware sends customized form data to crimeware server
- Crimeware gets the financial service response to the original login credentials and shows them on the browser.
Get a copy of this report here .
Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.
Print This Post
Post Info
This entry was posted on Tuesday, September 18th, 2007 . Tagged with:You can follow any responses to this entry through the Comments Feed. You can Leave A Comment, or A Trackback.
Previous Post: 2007 Best of Open Source in Security Awards »
Next Post: Kerberos Consortium Targets Universal Authentication Platform »
Read More
Related Reading:- My Twitter Notes on 2010-07-25
- New NetWitness Visualize : Welcome To The Future!
- My Twitter Notes on 2010-07-18
- My Twitter Notes on 2010-07-11
- My Twitter Notes on 2010-06-27
- Qualys and Imperva Integration: Natural Evolution
- My Twitter Notes on 2010-06-20
- Pro CERT – First Romanian Commercial CERT
- GFI EventsManager 2010 Review
- My Twitter Notes on 2010-06-13



