­
Man in the Browser Attacks on Online Transactions & Prevention Strategies - All Articles - CISO Platform

This is a great Man In the Browser Attack webinar(15 min), hosted by CISO Platform and briefly points out the Risks and also Recommends Some Fixes. It is presented by the CTO at Iviz. MiTB being particularly important for banking and finance Industry.

What will you learn?

- Learn why MiTB attacks pose a high risk to online banking and why is it hard to detect
- How Man In The Browser' Attack Bypasses Banks' Two-Factor Authentication Systems
- How one can mitigate the risks of MiTB attacks

Watch the 15min Power Webinar:

(Read more:  My Key Learning While Implementing Database Security)

View Presentation/PPT:

(Read more:  Database Security Vendor Evaluation Guide)

Quick Glance:

Attack Scenarios-

  • Classic 'Man In The Middle' -Involves attacker between victim client & server, prevention->Encryption eg.SSL
  • Compromised host to gain full access of client system, prevention->Multi factor Authentication eg.Biometric
  • 'MiTB'- Deadly combination of above two, prevention->Above 2 measures fail here

Reasons of Danger-

  • Can Read- Identity,Bank Password & Balance,Credit & Debit card numbers, Session keys
  • Can Modify- Details of Transaction
  • Can change password- you can get locked out!
  • Bypasses all sort of multi-factor authentication like captcha

How to Protect as End-user-

  • Strong passwords- not effective
  • Basic security awareness, updated OS & browser, separate system for online banking- maybe effective
  • Updated Antivirus/Antimalware- sometimes helps
  • Hardened Browser in USB- Moderate security
  • Use online banking with banks who have countermeasure- High security 

Mitigation Strategy for Bank-

  • Provide hardened browser in USB with authentication mechanism eg. token
  • OTP Token with signature
  • Before transaction, Confirm transaction details with OTP
  • Fraud Detection on basis of client behavior or transaction type & amount( less effective )

(Read more: How effective is your SIEM Implementation?)

Votes: 0
E-mail me when people leave their comments –

Community Head, CISO Platform

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

Fireside Chat With Rick Doten (VP - Information Security at Centene Corporation)

  • Description:

    We’re excited to bring you an exclusive fireside chat on "A CISO’s Guide on How to Manage a Dynamic Attack Surface" with Rick Doten (VP - Information Security, Centene Corporation) and Erik Laird (Vice President - North America, FireCompass). In this session, we’ll explore how top CISOs are tackling today’s rapidly expanding attack surface and what it takes to stay ahead of evolving threats in a cloud-first, AI-driven world.

    As…

  • Created by: Biswajit Banerjee
  • Tags: ciso, attack surface management, rick doten, ciso guide

CISO Meetup at BlackHat Las Vegas 2025

  • Description:

    We are excited to welcome you to the CISO Meetup during BlackHat USA 2025 in Las Vegas! Join us for an exclusive networking, meaningful conversations, and community building with top CISOs and cybersecurity leaders from around the globe. 

    Meetup Details:

    Location: Mandalay Bay, Las Vegas …

  • Created by: Biswajit Banerjee
  • Tags: ciso, black hat, black hat 2025, black hat usa

6 City Playbook Round Table Series (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    Join us for an exclusive 6-city roundtable series across Delhi, Mumbai, Bangalore, Pune, Chennai, and Kolkata. Curated for top cybersecurity leaders, this series will spotlight proven strategies, real-world insights, and impactful playbooks from the industry’s best.

    Network with peers, exchange ideas, and contribute to shaping the Top 100 Security Playbooks of the year.

    Date : Sept 2025 - Oct 2025

    Venue: Delhi, Mumbai, Bangalore, Pune,…

  • Created by: Biswajit Banerjee