Secure Banking - a little german Software

Discussion in 'other anti-malware software' started by testsoso, Sep 12, 2012.

Thread Status:
Not open for further replies.
  1. fredvries

    fredvries Registered Member

    Joined:
    Jun 13, 2003
    Posts:
    62
    Location:
    Harlingen - The Netherlands
    Actually, I'm a bit amazed that Secure Banking already is considered worthy of a test with these other well-known programs.

    And the independent results show that it is the best program of the lot.
     
  2. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    Wrong. There are quite a few products out there with BB and HIPS additions that warn you about code intrusion, process manipulation etc.
     
  3. SecureBanking

    SecureBanking Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    17
    Well I never saw something similar. All this HIPS are scanning all processes for malicious behavior, like you said code injection etc.
    But Secure Banking operates completely different.
    It checks the webbrowser for MitB attacks and so it can detect all kind of banking trojans.
    With this technology it can in contrast to HIPS/behaviour scanner conclude the name of the malware. HIPS/behaviour guards are not able to do that.

    For example a trojan can bypass such HIPS/behaviour guards if they are heavily obfuscated and has alot of dummy code in it, but Secure Banking detects them because in the end it performs a MitB attack.
    On the other side of course, Secure Banking cannot detect malware which is not attacking the webbrowser, but HIPS/behaviour guards can.

    So you cannot compare this tools. In my opinion both tools complete each other.
     
  4. SLE

    SLE Registered Member

    Joined:
    Jun 30, 2011
    Posts:
    361
    No, beside the name thing which sometimes may be interesting you must see how trojans can get into the browser. And good HIPS solutions warn about process changes and manipulations,no matter how much dummy code the trojan contains. So IMO your tool is a nice addition to traditional signature based solutions. And I never wanted it to compare to HIPS/BB solutions, cause they usually contain a lot more.

    btw.: How can you decline that it will detect "all kind of banking trojans"? I believe it can only detect that ones, that use the known (cause used in the pased) entry points your tool watches.

    Beside that all: There are many other ways to attack online banking than MitB attacks. Thats why the name of your tool is confusing and suggesting a wrong feeling of secureness. It's more a sort of browser protection.
     
  5. kareldjag

    kareldjag Registered Member

    Joined:
    Nov 13, 2004
    Posts:
    622
    Location:
    PARIS AND ITS SUBURBS
    just to complete SLE statements with a few examples.
    Browser protection is not new, a few years ago i have talked on my blog about some products like browser sentinel (http://www.browsersentinel.com/ ) spywall (http://www.trlokom.com/product/spywall.php ) and mostly trusdefender ( http://www1.trustdefender.com/ ).
    TrustDefender has been acquired by ThreatMetrix and is now a SaaS.
    And i do not mention Firefox IDS and other tools.

    *your product target is not new, and nothing new under the sun.

    The new generation of security suite already takes into consideration MitB based malwares.
    an example with Bullguard http://www.bullguard.com/bullguard-...rity/internet-threats/man-in-the-browser.aspx
    If there is many Security as a Service solutions designed for banks and merchants (i do not list them, as i do not want to see Secure-banking appeared as a ridiculous solution), there is a few other specialized products that try to mitigate risks during the transaction
    As examples SafeTok https://www.safetok.com/solutions/anti-phishing.html
    Antlabs Securite http://www.securitelive.com/

    *Secure-banking is not the only online banking/shopping focused security product on the market (and how it works hooking monitoring, malware fingerprint, heuristic and other protection design does not really matter).

    *I do not see what kind of advantages secure banking provides in comparison to well established HIPS like Sandboxie, Defense Wall, Online Armor and co.
    As most of them are able to prevent most rootkit/trojan infections...
    Does Secure Banking protects against XSS keylogguer, web/java script worm, keyboard sniffing, SSL MitM, cerificate spoofing....
    With no doubt NO.
    Some suite includes hardened browsers, and the user has the possibility for instance to surf with a cloud browser condom like Spoon for instance
    https://spoon.net/browsers/
    There is many ways to mitigate risks, without any secure banking solution...

    Well...checked this soft for 10 mn on the train, and i have noticed its weak implementation on the system...poor self-protection and other weaknesses.
    Anyway it needs of course to grown up, and additional routines on the table draw...

    Auf Wiedersen
     
  6. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    What does it mean if everything in Secure Banking seems to be functioning properly, but there is no balloon notification for the system tray icon when launching the browser? Is the balloon supposed to pop-up with every new use of the browser?
     
    Last edited: Sep 23, 2012
  7. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
  8. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Found the D/L link under downloads, 30 day trial

    https://www.safetok.com/download/download.html
     
  9. fredvries

    fredvries Registered Member

    Joined:
    Jun 13, 2003
    Posts:
    62
    Location:
    Harlingen - The Netherlands
    It's a 30 day trial. Afterwards you have to buy it for £ 35.94/year.

    Which means it's not free like Secure Banking is.
     
  10. guest

    guest Guest

    The new banking malware (or the malware specifically oriented to banks) always works with MitB attacks, right?
    All the famous and successful banking malware uses MitB: https://www.owasp.org/index.php/OWASP_Anti-Malware_-_Knowledge_Base

    A keylogger screen logguer could read your bank account (but most of the banks mitigate this with virtual keyboards, or entering a partial password, or with confirmation via sms) anyway this kind of malware is not oriented to banking.

    The difference btw Secure Banking and a HIPS is that Secure Baking blocks directly the banking malware and an HIPS will so you a popup that you may consider it trusted.

    As far as I read from the MRG banking malware tests, all of them make a general use (more or less) of MitB, so even if is a new baking malware some products are able to block it directly. Like happend in the MRG tests with Zemana and Trusteer rapport using a private testing tool able to reproduce a MitB attack that couldn't be in any database of any program.
     
    Last edited by a moderator: Sep 24, 2012
  11. SecureBanking

    SecureBanking Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    17
    Well, no anti-virus solution is completely perfect on its own. (Example: Bypassing Comodo Internet Security HIPS)

    I know, everything can be bypassed, also Secure Banking.

    Also I cannot see the similarity between browsersentinel and Secure Banking.

    And don't forget it is free! ;)

    Edit: As guest said, 99% of malware which is targeted on online-banking fraud are using MitB attacks. Secure Banking is focused on such trojans and is free and a lightweight.
     
    Last edited: Sep 24, 2012
  12. guest

    guest Guest

    To improve your program, I mean to avoid to kill easily Secure Banking you can use some of the tools of the matousec pack to test it. It has a lot of tools that you can use to try to kill, crash... Secure Banking.

    64bit: http://www.matousec.com/projects/security-software-testing-suite-64/
    32bit: http://www.matousec.com/projects/security-software-testing-suite/
     
  13. TaranScorp

    TaranScorp Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    57
    Location:
    USA
    Ok, will the Opera browser ever be supported?
    Don't want to get excited for nothing :)
     
  14. SecureBanking

    SecureBanking Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    17
    Well, the threats aren't very big for Opera (Source), but if I get malware in my hands, which is attacking it, I'll definitely think about it.
     
  15. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    @Secure Banking. Could you please respond to this...

    What does it mean if everything in Secure Banking seems to be functioning properly, but there is no balloon notification for the system tray icon when launching the browser? Is the balloon supposed to pop-up with every new use of the browser -- every time the browser is opened?

    I seem to only get the balloon the first time I open my browser, but then not again after that unless I restart or reboot.
     
  16. kareldjag

    kareldjag Registered Member

    Joined:
    Nov 13, 2004
    Posts:
    622
    Location:
    PARIS AND ITS SUBURBS
    Hi
    My posts on this board are only motivated by performing my english without the need of any dictionnary, and to guive an independent (no software to promote) and neutral opinion.
    If there is many security enthusiasts here, it is sometimes necessary to introduce a few "strudlle" of scepticism...
    Banking is a process, and then this process is only secure if all possible insecurity holes for each side is circumsribed with reliability and efficiency.
    This never happens in theory, but often in practise and in a statistically point of view.
    Unfortunatelly, most softs only try to keep the host side immune from threats vectors (malware, keyloggers etc).
    But various other factors need to be reliable: sockets, certificate authaurity, bank web site, data protection and authentication factors, DNS servers etc...
    That s why a subscription to a Security as a Service providers appears more interesting for the average user.
    As an example i can mention for UK users SafeCentral
    http://lifestore.aol.co.uk/category/computer-security/safecentral/?ncid=txtlnkukstor00000067
    Info here http://www.safecentral.com/banking-user.html

    Of course taking time to provide a free security soft for users is a respected attitude, and a pro, paid and enhanced version would not be scandalous at all.
    In this case some improvement are needed...especially if we consider that any script kiddy can try to bypass most popular products with the help of the underground economy (attached image).
    I have no respect for plagiarists like Matousec, as they have hiacked the FREE work and methodology that some guys have done years and years before (gkweb, kareldjag, André Kolishchak and some others)...

    Rgds
     

    Attached Files:

    • rd.jpg
      rd.jpg
      File size:
      38.3 KB
      Views:
      552
  17. TaranScorp

    TaranScorp Registered Member

    Joined:
    Jul 6, 2012
    Posts:
    57
    Location:
    USA
    SecureBanking,
    Thanks for considering Opera.
    Do you think Secure Banking would compliment Webroot's SecureAnywhere and Emsisofts Online Armor's Banking Mode?
     
  18. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    @ Dark Star 72

    In order not to hijack this thread, i've started a new one.

    @ fredvries

    Correct :thumb:
     
  19. guest

    guest Guest

    According to that link Chrome is less targeted than Opera but Secure Banking is compatible with Opera... I don't understand it.
     
  20. SecureBanking

    SecureBanking Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    17
    That sounds strange.
    How often you get this balloon tips depends on your webbrowser.
    For example Firefox just creates one process for the whole surfing-session. So you just get one balloon tip. If you close your webbrowser and start it again, you should get another balloon tip.

    In contrast to Firefox, IE and Chrome are creating new processes each time you open a new tab. So a new process means -> a new balloon tip.

    What do you exactly mean with compliment? :D

    Thats true, (lets say they're both same up) but Chrome has 10x more users as Opera. :)
     
  21. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    When can we expect the English version?
     
  22. fredvries

    fredvries Registered Member

    Joined:
    Jun 13, 2003
    Posts:
    62
    Location:
    Harlingen - The Netherlands
    @TomAZ

    The next version will be bilingual (German and English). It is not exactly known when that version will be released because the coder is very busy with his studies at university.
     
  23. newbino

    newbino Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    464
    @SecureBanking

    Firstly, welcome to Wilders and thanks for your efforts with this freeware. I look forward seeing it developed further.

    Please also consider adding Waterfox, a Firefox 64-bit specific variant, to your list of protected browsers.
     
  24. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Is SecureBanking still effective when the browser is running under Sandboxie?
     
    Last edited: Oct 1, 2012
  25. SecureBanking

    SecureBanking Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    17
    Yes, it is. ;)

    Thanks, I'll keep an eye on it.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.