Cybercriminals: Always one step ahead

commentary In June 2003, the financial sector was jolted by a worm called Bugbear.b, which preyed on more than 1,300 banks around the world. Australia's big four -- ANZ, Commonwealth, National and Westpac -- were part of the hit list.

Bugbear.b was a multi-faceted mass-mailing worm. It could log keystrokes, plant backdoors and had the ability to disable anti-virus programs. The worm exploited a year-old flaw in Microsoft's Internet Explorer browser.

One year later, nothing much has changed. Malicious code writers continue to prey on Internet Explorer's lingering vulnerabilities to create weapons of mass deceit ... so news of a Trojan that steals personal banking data came as no surprise.

The malicious software targeted leading financial institutions worldwide and the discovery was made by Tom Liston of the Internet Storm Center, a site that monitors network threats.

By exploiting flaws in Internet Explorer, the malicious program is downloaded unbeknownst to the user. It then installs itself as a browser helper object (BHO) and becomes part of Internet Explorer, Liston said.

A BHO is a dynamic link library (DLL) that allows software developers to customise Internet Explorer. "When IE 4.x and higher starts, it reads the registry to locate installed BHO's and then loads them into the memory space for IE. Created BHO's then have access to all the events and properties of that browsing session," he added.

This particular BHO watches for HTTPS access to domain names containing 50 financial-related strings including Australia's Citibank, St George Bank, Bendigo Bank, HSBC, Suncorp Metway, as well as the four banks on Bugbear's radar.

When a user logs onto any one of those Web sites, the BHO captures the user identification and password. The data is then encrypted to bypass intrusion detection software and is sent to the alleged crackers before it gets encrypted by the browser. Did I mention this problem was unique to Internet Explorer?

To tell if a system has been compromised, Liston recommends Definitive Solutions' BHODemon -- a free scanning tool that detects all BHOs installed on a Windows machine.

Since the security threat was made public, more than 65,000 copies of BHODemon have been downloaded, company spokesperson Larry Leonard told ZDNet Australia.

BHODemon is a useful product but it plays a small part in the overall security landscape. Liston said the new Trojan represents a huge threat to the online financial industry. "As the proliferation of ad/spyware shows, installing executable software on user's machines is far too easy.

"The approach of using a BHO makes this method of stealing identity information all the more insidious," he said.

Today, more than 60 percent of Australian Internet users access online financial services regularly. This far outweighs transactions conducted at bank branches.

The affected banks and other commercial concerns must immediately assess the root cause of these security problems before it further erodes consumer confidence in online banking. Historical evidence points to one recurring problem ... perhaps it's time to explore other options?

Advertisement

Talkback 4 comments

  1. I've used IE since going online a few years ago, but it's gotten to the stage where it's become obvious that I need to switch to another browser just because IE is targeted so much. Why didn't I do it before? Because a few of the useful BHOs I use will Anonymous -- 07/07/04

    I've used IE since going online a few years ago, but it's gotten to the stage where it's become obvious that I need to switch to another browser just because IE is targeted so much. Why didn't I do it before? Because a few of the useful BHOs I use will not run anything other than IE. When it's got to this stage though where I can no longer trust that anything between me and the bank I use will stay that way, then I'll just have to live without that convenience.

  2. For years I used IE (in fact, to be honest, I am using it this second), as it was lightyears ahead of the competition. I was sick of Netscape 4 not rendering pages correctly, and it looked dated too. When Netscape 6 came out, I installed it, but it was th Anonymous -- 07/07/04

    For years I used IE (in fact, to be honest, I am using it this second), as it was lightyears ahead of the competition. I was sick of Netscape 4 not rendering pages correctly, and it looked dated too. When Netscape 6 came out, I installed it, but it was the slowest dog of a browser I wasted my time ever installing. Netscape 7 was a major improvement speedwise and it almost renders as well as IE for most things.

    Opera has always been a good browser, though recently I have been using Mozilla and have been very impressed with it. In fact, I use it for my banking etc.

    But IE is needed to run ActiveX plugins. I really hope they actually fix the thing rather than change a configuration every time a new threat is discovered.

  3. Apple's Safari is impervious to such pathetic security holes Anonymous -- 08/07/04

    Apple's Safari is impervious to such pathetic security holes

  4. I've switched to Safari, the browser Apple created... IE crashed on my Mac so many times due to cache problems... a buggy software indeed ... Anonymous -- 08/07/04

    I've switched to Safari, the browser Apple created... IE crashed on my Mac so many times due to cache problems... a buggy software indeed ...

Add your opinion


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured