The iTAN Online-Banking Security System allows remote attackers to obtain TAN numbers via a man-in-the-middle (MITM) attack while the transaction is taking place, which facilitates a "phishing" attack.
Link | Tags |
---|---|
http://www.redteam-pentesting.de/advisories/rt-sa-2005-014.txt | exploit vendor advisory |
http://marc.info/?l=bugtraq&m=112498693231687&w=2 | mailing list |