View Single Post
  #3 (permalink)  
Old 08-20-2008, 10:10 AM
wige's Avatar
wige wige is offline
Moderator
WebProWorld Moderator
 
Join Date: Jun 2006
Location: United States
Posts: 2,651
wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9
Default Re: Silent Banker Trojan

I have heard a bit about the Silent Banker Trojan, but I have to admit I am somewhat confused how this phone out of band authentication would solve the problem in any way.

From my understanding, the Trojan works by waiting for the user to begin an authenticated session with the bank, then during that session alters the transaction data before sending it to be encrypted and transmitted to the bank. The phone system appears to try to correct for this by taking the authentication away from the computer. However, the actual attack occurs after the user is authenticated.
__________________
The best way to learn anything, is to question everything.
Reply With Quote