Web Hack List

Collected research

Winning the Online Banking War

Winning The Online Banking War

Banking trojans steal money through JavaScript injected into the victim's browser rather than through the malware binary. The paper dissects how these injects hook the DOM to alter transactions and defeat two-factor authentication, catalogues evasion tricks such as obfuscation, control-flow randomisation and DOM rootkits, and proposes a DOM-integrity whitelist defence called MIPS.

Record

Document
Winning The Online Banking War
Researcher
Sean Park
Published by
blackhat.com
Date
Format
Recording
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sean Park, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .