Log'N'Rock: New Banking Trojan Caught Breaking CAPTCHA - Log'N'Rock

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New Banking Trojan Caught Breaking CAPTCHA

#1 User is offline   Peaches4U Icon

  • Rockin' News Angel
  • Icon
  • Group: Road Crew
  • Posts: 2,911
  • Joined: 14-September 09
  • Gender:Female
  • Location:Canada
  • Interests:computers; travel; keeping busy; fashion;

Posted 31 January 2012 - 03:41 AM



Quote

Monday, January 30, 2012

New Banking Trojan Caught Breaking CAPTCHA

A new banking Trojan variant can bypass CAPTCHA, as demonstrated by a video posted today by security firm Websense on their Security Labs blog

See Video here: https://threatpost.c...m_campaign=Home

Once downloaded to the machine, Cridex, a data-stealing Trojan, will track content from various web forms. Cridex also downloads a ‘spamming module’ to the infected machine that enables the botmaster to send malicious e-mails to boost infection rates. This module, as shown in the video, utilizes a CAPTCHA-breaking server that helps the botmaster circumvent any CAPTCHA after a few tries, allowing the attacker to create a new Yahoo e-mail account.

The CAPTCHA attempts are sourced from a series of challenge images (embedded in HTTP) that have been gathered from the e-mail registration form and uploaded to the remote CAPTCHA-breaking server.

For more on the methods used by Cridex and the exact steps of the CAPTCHA-breaking process, head to Websense.


http://community.web...rity-issue.aspx - there are more details and screenshots, etc.


0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users