This is a great Man In the Browser Attack webinar(15 min), hosted by CISO Platform and briefly points out the Risks and also Recommends Some Fixes. It is presented by the CTO at Iviz. MiTB being particularly important for banking and finance Industry.

What will you learn?

- Learn why MiTB attacks pose a high risk to online banking and why is it hard to detect
- How Man In The Browser' Attack Bypasses Banks' Two-Factor Authentication Systems
- How one can mitigate the risks of MiTB attacks

Watch the 15min Power Webinar:

(Read more:  My Key Learning While Implementing Database Security)

View Presentation/PPT:

(Read more:  Database Security Vendor Evaluation Guide)

Quick Glance:

Attack Scenarios-

  • Classic 'Man In The Middle' -Involves attacker between victim client & server, prevention->Encryption eg.SSL
  • Compromised host to gain full access of client system, prevention->Multi factor Authentication eg.Biometric
  • 'MiTB'- Deadly combination of above two, prevention->Above 2 measures fail here

Reasons of Danger-

  • Can Read- Identity,Bank Password & Balance,Credit & Debit card numbers, Session keys
  • Can Modify- Details of Transaction
  • Can change password- you can get locked out!
  • Bypasses all sort of multi-factor authentication like captcha

How to Protect as End-user-

  • Strong passwords- not effective
  • Basic security awareness, updated OS & browser, separate system for online banking- maybe effective
  • Updated Antivirus/Antimalware- sometimes helps
  • Hardened Browser in USB- Moderate security
  • Use online banking with banks who have countermeasure- High security 

Mitigation Strategy for Bank-

  • Provide hardened browser in USB with authentication mechanism eg. token
  • OTP Token with signature
  • Before transaction, Confirm transaction details with OTP
  • Fraud Detection on basis of client behavior or transaction type & amount( less effective )

(Read more: How effective is your SIEM Implementation?)

Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (Monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

6 City Round Table On "New Guidelines & CISO Priorities for 2025" (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    We are pleased to invite you to an exclusive roundtable series hosted by CISO Platform in partnership with FireCompass. The roundtable will focus on "New Guidelines & CISO Priorities for 2025"

    Date: December 1st - December 31st 2025

    Venue: Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata

    >> Register Here

  • Created by: Biswajit Banerjee

Fireside Chat With Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.)

  • Description:

    We’re excited to bring you an insightful fireside chat with Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.) and Erik Laird (Vice President - North America, FireCompass). 

    About Sandro:

    Sandro Bucchianeri is an award-winning global cybersecurity leader with over 25…

  • Created by: Biswajit Banerjee
  • Tags: ciso, sandro bucchianeri, nab