Over-the-Air Cross-platform Infection for Breaking mTAN-based Online Banking Authentication
نویسندگان
چکیده
We present a novel stealthy cross-platform infection attack in WiFi networks. Our attack has high impact on two-factor authentication schemes that make use of mobile phones. In particular, we apply our attack to break mTAN authentication, one of the most used scheme for online banking worldwide (Europe, US, China). We present the design and implementation of the online banking Trojan which spreads over the WiFi network from the user's PC to her mobile phone and automatically pairs these devices. When paired, the host and the mobile malware deliver to the attacker authentication secrets which allow her to successfully authenticate against the online-banking portal and perform nancial transactions in the name of the user. Our attack is stealthy compared to the known banking Trojans ZeuS/ZitMo and SpyEye/Spitmo, as it does not rely on phishing or naïve user behavior for malware spreading and pairing. Our reference implementation targets Windows PCs and Android based smartphones, although our attack is not platform speci c. To achieve cross-platform infection, we applied and adapted attack techniques such as remote code execution, privilege escalation, GOT overwriting, DLL injection and function hooking. Our attack can be implemented by knowledgeable attackers and calls for re-thinking of security measures deployed for protection of online transactions by banks.
منابع مشابه
Biometric Authentication of Fingerprint for Banking Users, Using Stream Cipher Algorithm
Providing banking services, especially online banking and electronic payment systems, has always been associated with high concerns about security risks. In this paper, customer authentication for their transactions in electronic banking has been discussed, and a more appropriate way of using biometric fingerprint data, as well as encrypting those data in a different way, has been suggest...
متن کاملBreaking Legacy Banking Standards with Special-Purpose Hardware
In the field of eCommerce, online-banking is one of the major application requiring the usage of modern cryptography to protect the confidentiality and integrity of financial transactions between users and the banking system. In banking applications of some countries, the authorization of user transactions is performed with support of cryptographic One-Time-Password (OTP) tokens implementing AN...
متن کاملAn Enhanced Remote Authentication Scheme using Secure Key Exchange Protocol with Platform Integrity Attestation
Most remote authentication schemes use key exchange protocol to provide secure communication over an untrusted network. The protocol enables remote client and host to authenticate each other and communicate securely with prearranged shared secret key or server secret key. Many remote services environment such as online banking and electronic commerce are dependent on remote authentication schem...
متن کاملThe Problems with Secure On-line Banking
A growing awareness of the commercial benefits of online banking have contributed to a sense of urgency among banks to deploy such systems. However, while security of the communications is usually well considered, most do not sufficiently address the security of the platform on which these applications run. In this paper, we outline two existing on-line banking schemes and describe how this wea...
متن کاملDetermination of the Influencing Factors for the Acceptance of Mobile Banking Based on Social Cognitive Theory by Bank Mellat Customers in Bandar Abbas
Aims: Due to the development of the Internet, banks are rapidly moving towards providing an online banking platform for their customers. One of the most widely used aspects of such platforms is the use of mobile banking. The aim of the present study was to determine the factors affecting the acceptance of mobile banking based on Social Cognitive Theory by Bank Mellat customers in Bandar Abbas. ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2012