| |||||||
| Register | FAQ | Members List | Calendar | Arcade | Search | Today's Posts | Mark Forums Read |
| Data Security Viruses, Firewalls and Safe computing |
![]() |
| | LinkBack | Thread Tools | Rate Thread |
| ||||
| New phishing Trojan found Written by Daniel Wednesday, 09 August 2006 WebsenseŽ Security Labs™ has received a sample of a new phishing Trojan that delivers stolen information back to the attacker via ICMP packets. Upon infection of a victim's computer, the Trojan will install itself as an Internet Explorer Browser Helper Object (BHO). The BHO then waits for the user to post personal information to a monitored website. As this information is entered by the user, it is captured by the BHO and sent back to the attacker. The method of network transport used by the attacker makes this Trojan unique. Typically, keyloggers of this type will send the stolen information back to the attacker via email or HTTP POST, which can appear suspicious. Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into the data section of an ICMP ping packet. Front Page
__________________ "Though all men live in ignorance before mystery, they need not live in darkness... Justice is foundation and ETERNAL." DKE "All that we do is touched by Ocean Yet we remain on the shore of what we know." Richard Wilbur ![]() Subscribers! Ask Pitch about a Custom Sig Graphic |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Rate This Thread | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Phishing Scam netted! | Daniel ~ | Data Security | 1 | 29th September, 2006 06:50 PM |
| Trojan Horses? | Strongwolf | Random Nonsense! | 1 | 29th July, 2006 12:42 PM |
| FireFox Add-on Trojan! | Daniel ~ | Data Security | 2 | 28th July, 2006 01:07 PM |
| Phishing tricks.... | Lazgoat | Data Security | 6 | 18th December, 2004 03:21 PM |
| Trojan/Downloader.checkin | Southern Man | Random Nonsense! | 6 | 17th June, 2003 10:30 AM |