YOUR IT - Technology for you

No. 1 Story

Cloud alliance sides with Optus on copyright

OzHub, the Macquarie Telecom-led cloud computing alliance, has come down firmly on the side of Optus over the copyright controversy surrounding Optus TV Now, warning that any moves to change the law "risk branding Australia a global luddite state."

read more

Security company warns of new Banker Trojan

Your IT - Home IT

Security vendor Sophos has warned of a new piece of malware that takes a sneaky approach to intercepting people's Internet banking details.

All the Trojan does is add eight entries to Windows' HOSTS file. This file associates host names with specific IP addresses, without reference to the Internet's Domain Name Service. It has some legitimate uses, but the Bancos-BDF Trojan uses it to associate host names corresponding to a South American Banking institution with an IP address that has nothing to do with the bank.

"What this means for anyone infected by this particular Trojan is that any and all attempts to visit the website of the target bank, including logging in to check your balance, viewing the bank homepage and even email correspondence will be re-routed to the assailant's IP address," said Chris Mitchell of SophosLabs Australia. "This would give the attacker all the information he needs and by duplicating the banks stationary and email signatures he could wreak untold damage to unassuming victims."

While similar tricks have been played for some time - HOSTS file hijacking has been around for at least four years - Mitchell said "This is by far the most effective man in the middle attack I have evidence of to date".

One bona fide use of a modified HOSTS file is to block access to 'known bad' domains, but that job is probably better left to security software and firewalls for ease of management.

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more