Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Alert - Live Attack:Virus attack on ICICI Bank Transactions

6 views
Skip to first unread message

Yash

unread,
Dec 19, 2011, 4:45:26 AM12/19/11
to
Hi All,

I have developed a proof-of-concept virus to attack the ICICI Online
banking using Man-in-Middle / Man-in-Browser attack method. I am
releasing a video (of only 8 minutes) to show what such an attack can
do to an online banking customer, who uses ICICI online banking and
how it can result in a financial loss to the ICICI Online banking
customer.

http://www.yashks.com/2011/12/virus-attack-on-icici-bank-transactions/

We are at face book - Broken Internet. Please click on "Like" button
to join us for latest updates : https://www.facebook.com/pages/Broken-Internet/311290055569092

Regards,
Yash K.S

ICICI Bank Care

unread,
Dec 23, 2011, 11:41:20 AM12/23/11
to
Hi,

The false and misleading 'proof of concept' mentions the exploit by a
Trojan (man in the middle/man in the browser) which attacks a user’s
computer. It is evident that the author has no understanding of the
Bank's security controls and processes on the internet banking portal.
The Bank has identified and adequately dealt with such a risk &
provided for mitigating controls (which have also been checked through
independent sources) and takes this opportunity to reassure its
internet banking customers of the safety and security of the Bank's
internet banking portal. Hence, this 'proof of concept' is totally
baseless and misleading, and done with some ulterior motives. The
author is a software developer & has published similar content for
other banks as well and appears to be seeking attention for own
gains.”

Regards,
ICICI Bank Team

meagain

unread,
Dec 23, 2011, 2:27:15 PM12/23/11
to
ICICI Bank Care wrote:
> Hi,
>
> The false and misleading 'proof of concept' mentions the exploit by a
> Trojan (man in the middle/man in the browser) which attacks a user’s
> computer. It is evident that the author has no understanding of the
> Bank's security controls and processes on the internet banking portal.
> The Bank has identified and adequately dealt with such a risk&
> provided for mitigating controls (which have also been checked through
> independent sources) and takes this opportunity to reassure its
> internet banking customers of the safety and security of the Bank's
> internet banking portal. Hence, this 'proof of concept' is totally
> baseless and misleading, and done with some ulterior motives. The
> author is a software developer& has published similar content for
> other banks as well and appears to be seeking attention for own
> gains.”
>
> Regards,
> ICICI Bank Team
...

You mean he/she is a spammer! Surprize surprize!



David H. Lipman

unread,
Dec 23, 2011, 2:39:15 PM12/23/11
to
0 new messages