Author Topic: New Man-in-the-Middle attacks  (Read 681 times)

0 Members and 1 Guest are viewing this topic.

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
New Man-in-the-Middle attacks
« on: April 04, 2014, 07:52:07 pm »
New MitM attacks impersonate banking sites without triggering alerts

PhishLabs has observed a new wave of "Man-in-the-Middle" (MitM) attacks targeting users of online banking and social media. Customers of more than 70 different financial institutions are being targeted.

In these attacks, hackers use spam to deliver malware that changes DNS settings and installs a rogue Certificate Authority (CA).  The DNS changes point to the hacker's clandestine DNS name server so that users are directed to proxy servers instead of legitimate sites. Based on the CA, the user's PC trusts the attacker’s proxy servers and provides no indication that an attack is taking place. The browser displays the proper website name and displays the familiar security icon to indicate a trusted, secure connection.

http://blog.phishlabs.com/new-man-in-the-middle-attacks-leveraging-rogue-dns
« Last Edit: April 04, 2014, 08:08:53 pm by kenjoe41 »
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]