Attacking mTAN-Applications like e-Banking and mobile Signatures
Peter Schartner, Stefan Bürger, Peter Schartner, Stefan Bürger · 2010
Many operating systems, including the Windows- and Android-family, are based on message processing. These messages (called events or intents respectively) are sent from the operating system to applications or vice versa or between applications. Both, Windows, and Android provide entry points (so called hooks) for additional message processing software. Since there is no check, if these additional event processing methods are malicious or not, this opens the door for well known attack scenarios like password-sniers. But even worse, the new message processor may drop system messages or insert new (forged) messages into the event queue. In this paper we will describe, how additional message processing routines can be used to attack systems secured by mTANs (mobile TANs { TANs sent to the user’s phone via the short message service { SMS) like web-banking and mobile signatures on PCs and smartphones. After describing the attack principle, we will discuss potential countermeasures and open problems.