Re: [SC-L] Solution for man-in-the-browser

2010-09-11 Thread Wall, Kevin
On Sep 10, 2010, at 5:34 PM, smurray1 wrote: > Hello, > > I have been discussing an issue with an organization that is having > an issue with malware on it's customer's clients that is intercepting > user credentials and using them to create fraudulent transactions. > (man-in-the-browser type atta

Re: [SC-L] Solution for man-in-the-browser

2010-09-11 Thread James Manico
I do not think this will work. Once your browser is trojaned, it's game over. The Trojan has the capability to just sit in your browser and wait for the user to log in. (Trojans do not need to steal credentials to cause harm). Once the user has logged on, the Trojan can simulate any user activity s