Attacking The Java Virtual Machine To Capture Critical User Information by Arthur Wongtschowski, Wilson V. Ruggiero, Paulo S. L. M. Barreto
AUTHORS' DESCRIPTION
'In this paper, we present an attack against the Java Virtual Machine environment that could be used to capture critical user information during on-line banking transactions. The attack itself is made possible due to the lack of validation of the Virtual Machine's integrity. A malicious program can change the JRE jar files, modifying its behavior and disabling security completely. A specially crafted trojan-horse could exploit this flaw in order to capture critical information or disable security related software from the victim's computer.' Read the full article
by Arthur Wongtschowski, Wilson V. Ruggiero, Paulo S. L. M. Barreto
AUTHORS' DESCRIPTION'In this paper, we present an attack against the Java Virtual Machine environment that could be used to capture critical user information during on-line banking transactions. The attack itself is made possible due to the lack of validation of the Virtual Machine's integrity. A malicious program can change the JRE jar files, modifying its behavior and disabling security completely. A specially crafted trojan-horse could exploit this flaw in order to capture critical information or disable security related software from the victim's computer.'








