Finjan Web Security Trends Report - Q3/2007

Finjan has released it’s Web Security Trends Report - Q3/2007 (PDF) and I found it quite interesting to read.
One of the innovative research presented in the report is the security model and risk posed by the various widgets which seem to be the hottest trend in GUI design.Either built for WWW, Windows Vista or Macintosh OSX Dashboard,the widgets are everywhere and Finjan found vulnerabilities in widgets and gadgets that enable attackers to gain control of user machines.
This report also presents a detailed analysis of a very special malware : the financial data trojan which gets activated whenever an user does internet banking or logs in a financial institution website . "Financially-focused crimeware – what happens when a trojan goes phishing" shows step by step all the Crimeware Trojan Workflow :
- Detect login page to a financial service
- Send the login credentials to the financial service as well as the crimeware server
- Crimeware server response contains custom designed page to get more sensitive information (designed for the service provider)
- Crimeware on infected PC injects the custom page into the browser (which is already connected via SSL to the financial provider)
- Victim enters sensitive data into customized form
- Crimeware sends customized form data to crimeware server
- Crimeware gets the financial service response to the original login credentials and shows them on the browser.
Get a copy of this report here .
If you enjoyed this post, make sure you subscribe to my RSS feed!
Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.
Post Info
This entry was posted on Tuesday, September 18th, 2007 and is filed under Web Applications, Articles.You can follow any responses to this entry through the Comments Feed. You can Leave A Comment, or A Trackback.
Previous Post: 2007 Best of Open Source in Security Awards »
Next Post: Kerberos Consortium Targets Universal Authentication Platform »
Read More
Related Reading:- Free alternative to ArcSight ESM ? Hardly..
- Privacy Dilemma: How to Protect Yourself Online
- Solera Networks Deep-Packet Capture Review
- WordPress Exploit Scanner
- Phishing Exposed, Brands Secured
- Scanners: New Nessus Release; New eEye Web Scanner
- Good News from ArcSight and Imperva
- CCTV Security Camera and Surveillance Equipment
- OpenDNS Offers Free Web Content Filtering
- Can I Evade ScanSafe Anywhere+ ?

