Cybercriminals: Always one step ahead

commentary In June 2003, the financial sector was jolted by a worm called Bugbear.b, which preyed on more than 1,300 banks around the world. Australia's big four -- ANZ, Commonwealth, National and Westpac -- were part of the hit list.

Bugbear.b was a multi-faceted mass-mailing worm. It could log keystrokes, plant backdoors and had the ability to disable anti-virus programs. The worm exploited a year-old flaw in Microsoft's Internet Explorer browser.

One year later, nothing much has changed. Malicious code writers continue to prey on Internet Explorer's lingering vulnerabilities to create weapons of mass deceit ... so news of a Trojan that steals personal banking data came as no surprise.

The malicious software targeted leading financial institutions worldwide and the discovery was made by Tom Liston of the Internet Storm Center, a site that monitors network threats.

By exploiting flaws in Internet Explorer, the malicious program is downloaded unbeknownst to the user. It then installs itself as a browser helper object (BHO) and becomes part of Internet Explorer, Liston said.

A BHO is a dynamic link library (DLL) that allows software developers to customise Internet Explorer. "When IE 4.x and higher starts, it reads the registry to locate installed BHO's and then loads them into the memory space for IE. Created BHO's then have access to all the events and properties of that browsing session," he added.

This particular BHO watches for HTTPS access to domain names containing 50 financial-related strings including Australia's Citibank, St George Bank, Bendigo Bank, HSBC, Suncorp Metway, as well as the four banks on Bugbear's radar.

When a user logs onto any one of those Web sites, the BHO captures the user identification and password. The data is then encrypted to bypass intrusion detection software and is sent to the alleged crackers before it gets encrypted by the browser. Did I mention this problem was unique to Internet Explorer?

To tell if a system has been compromised, Liston recommends Definitive Solutions' BHODemon -- a free scanning tool that detects all BHOs installed on a Windows machine.

Since the security threat was made public, more than 65,000 copies of BHODemon have been downloaded, company spokesperson Larry Leonard told ZDNet Australia.

BHODemon is a useful product but it plays a small part in the overall security landscape. Liston said the new Trojan represents a huge threat to the online financial industry. "As the proliferation of ad/spyware shows, installing executable software on user's machines is far too easy.

"The approach of using a BHO makes this method of stealing identity information all the more insidious," he said.

Today, more than 60 percent of Australian Internet users access online financial services regularly. This far outweighs transactions conducted at bank branches.

The affected banks and other commercial concerns must immediately assess the root cause of these security problems before it further erodes consumer confidence in online banking. Historical evidence points to one recurring problem ... perhaps it's time to explore other options?

Like this article? Click below to send it to your mobile for free!

Talkback 4 comments

  1. I've used IE since going online a few years ago, but it's gotten to the stage where it's become obvious that I need to switch to another browser just because IE is targeted so much. Why didn't I do it before? Because a few of the useful BHOs I use will Anonymous -- 07/07/04

    I've used IE since going online a few years ago, but it's gotten to the stage where it's become obvious that I need to switch to another browser just because IE is targeted so much. Why didn't I do it before? Because a few of the useful BHOs I use will not run anything other than IE. When it's got to this stage though where I can no longer trust that anything between me and the bank I use will stay that way, then I'll just have to live without that convenience.

  2. For years I used IE (in fact, to be honest, I am using it this second), as it was lightyears ahead of the competition. I was sick of Netscape 4 not rendering pages correctly, and it looked dated too. When Netscape 6 came out, I installed it, but it was th Anonymous -- 07/07/04

    For years I used IE (in fact, to be honest, I am using it this second), as it was lightyears ahead of the competition. I was sick of Netscape 4 not rendering pages correctly, and it looked dated too. When Netscape 6 came out, I installed it, but it was the slowest dog of a browser I wasted my time ever installing. Netscape 7 was a major improvement speedwise and it almost renders as well as IE for most things.

    Opera has always been a good browser, though recently I have been using Mozilla and have been very impressed with it. In fact, I use it for my banking etc.

    But IE is needed to run ActiveX plugins. I really hope they actually fix the thing rather than change a configuration every time a new threat is discovered.

  3. Apple's Safari is impervious to such pathetic security holes Anonymous -- 08/07/04

    Apple's Safari is impervious to such pathetic security holes

  4. I've switched to Safari, the browser Apple created... IE crashed on my Mac so many times due to cache problems... a buggy software indeed ... Anonymous -- 08/07/04

    I've switched to Safari, the browser Apple created... IE crashed on my Mac so many times due to cache problems... a buggy software indeed ...

Add your opinion


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured