Feeds

REVEALED: Cyberthug tool that BREAKS HSBC's anti-Trojan tech

Browser lockdown method also used by PayPal

Beginner's guide to SSL certificates

Cybercrooks on an underground forum have developed a technique to bypass anti-Trojan technology from Trusteer used by financial institutions worldwide – including HSBC and Paypal – to protect depositors from cybersnoopers.

Trusteer has downplayed the vulnerability and said it's in the process of rolling out beefed-up protection anyway. However, independent security researchers who first spotted the exploit warn that bank customers remain at risk.

Trusteer's Rapport browser lock-down technology is offered as a voluntary download by 50 banks worldwide, including NatWest and HSBC in the UK. US customers include ING Direct USA; eBay and PayPal also offer it to their customers as protection against banking Trojans.

An exploit on private cybercrime forums, spotted by digital forensics firm Group-IB, offers a means to bypass the browser lock-down technology. More precisely, Trusteer Rapport versions 1208.41 and below suffer from a memory modification vulnerability that turns off "Rapport's selfcheck unhooking and intercepting system" APIs.

More technical details of the flaw can be found in a post over the weekend on a full disclosure mailing list here.

"With the help of this new exploit it is possible to intercept users' credentials when Trusteer Rapport is active," explained Andrey Komarov, head of international projects at Group-IB.

Members of the cybercrime forum have started to use the trick to bypass Rapport checking, which prevents the theft of users' credentials – including login details for online banking services - through interception, according to Komarov.

In a statement Amit Klein, CTO at Trusteer. downplayed the seriousness of the flaw. Klein said the bug only affected one of the protection layers offered to customers by the software.

The patch for this vulnerability is available and is being rolled out automatically to the entire Trusteer Rapport customer base. No action is required from Rapport users. This vulnerability has no impact on Rapport's ability to block financial malware like Zeus, KINS, Carberp, Gozi, Tilon and Citadel as Rapport uses additional mechanisms, other than the mechanism impacted by this vulnerability, to block these malware strains. Furthermore, there is no financial malware to date that is trying to exploit this vulnerability.

An advisory along the same lines, a copy of which has been seen by El Reg, was sent to Trusteer's banking customers on Monday. This advisory adds the important caveat that "the combination of this vulnerability with a new (i.e. unknown, not currently seen in the wild) strain of malware, for which Rapport doesn’t apply multiple layers of protection, could result in a successful bypass of Rapport’s protection."

The bypass is still in play, according to Komarov.

"It is still unpatched, we can create a similar video on the actual [current] version of Rapport, where the bypass will be still working," he told El Reg. "Because of leakage of source codes of SpyEye and Carberp, there are already some recompiled copies which use this exploit to bypass its security."

Komarov added that Group-IB is profiling teams of hackers who have already started to use this bug. Some of these hackers had previously released Anti-Rapport modules to SpyEye and ZeuS, the two most widely used banking Trojan tools abused by cybercriminals over recent years.

Cybercrime forums have been active with discussions about possible mechanisms to bypass Trusteer since 2010, Komarov added. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.