欢迎来到天天文库
浏览记录
ID:33838112
大小:5.48 MB
页数:56页
时间:2019-03-01
《us-15-Park-Winning-The-Online-Banking-War.pdf》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、TrendMicroWorkedforoneofbig4banksinAustraliafor6yearsasmalwaresecurityconsultant.DevelopedbankingmalwaredetectionsystemServedatSophos,Symantec,FireEyeandKasperskyCurrentlywithTrendMicroIdentifythecruxoftheonlinebankingwarSetthestrategicdefenseframeworkPoCdesign&implementation:MIPSSpa
2、mServerC&CSiteInfectionURLMalwareCampaignDropperDropSiteGotatokenforyourcorporateaccount?Doyoustillfeelsafe?NowyouarelockedoutwhiletheybuyenoughtimetotransfermoneyThereisnosuchathingas‘PleaseWait’intheonlinebankingpage.What’shappeningwhileyouarewaiting…Evenwhenthereisnovisualsignofinfe
3、ction,itcanhappensilently.C&CcommunicationduringTxpagesWhatisthemalwarereceiving?InjectandMuleMule’sAccountTransferAmountInformation$("#submit").on("click",function(){varid=$("#signin-id").val();varpw=$("#signin-password").val();console.log(">>DOMInject:"+id+“:"+pw);});WebOnlineBrowserBa
4、nkingPOST/mipsMIPSMIPS_INTELInjectBlacklistMalwareIntelligenceMalwareinjectremovesitself,butitstillremainsinthememoryExploitmemoryleakpatternsDanglingreferencesCircularreferencesClosuresDOMbodybuttonscriptonclickscriptvarme=document.currentScript;me.parentNode.removeChild(me);DOMbodyRe
5、fToDomRefToSCriptscriptvarrefToDom=document.body;document.body["refToScript"]=refToDom;DOMbodybuttononclickscriptfunctionAttachEvent(element){element.attachEvent("onclick",MyClickHandler);functionMyClickHandler(){/*Thisclosurereferenceselement*/}}Identifyentrypoints(unload,click,timer)Enu
6、merateeventhandlerselement.onclick=handlerScan:element.onclickelement.addEventListenerScan:getEventListeners(element,“click”)$(element).on(“click”,handler)Scan:$._data(element,"events")$(element).observe(“click”,handler)Scan:element.getStorage().get('prototype_event_registry').get('click')F
7、or$(‘#submit’),‘click‘,Eventhandler’snamespacepropertyismissingNormalDOMStealthbutton01button01button01button01button01button01‘’DOMUser-definedFunctionsWhitelistFunctionFunctionFunctionFunctionFunction?Enumerateuser-definedfunctionsObject.keys(window)
此文档下载收益归作者所有
点击更多查看相关文章~~