Author Topic: Issus regarding the security of Avast Secure Browser (bank mode)  (Read 2271 times)

0 Members and 1 Guest are viewing this topic.

Offline svnupa

  • Jr. Member
  • **
  • Posts: 27
Since a few years I'm working with the Avast Antivirus Engine and the Secure Browser.
It's a very comfortable and secure way to work in the internet with extensives ways to configure (i like it  :D).

Unfortunately it works with windows board equipments inside the bank mode.
It's like you lock your house, but you let open the backdoor of the building.

If you find a way to exchange one of these files (e.g. notepad.exe or calc.exe), it' is possible to break into the sandbox.
I tried it with metasploit and a reverse tcp connection on my local pc system (combined with Virtualbox).
The result was, that I had the possibility to log the keyboard input inside the sandbox.
This is really to simple.  :o

Why Avast don't create his own tools inside the bank mode?
Another idea is to transfer the ASB bank mode to a window instead a full screen mode.
All keyboard inputs could be encrypted (my home bank work on this way).
Anyone could use all the tools they need without limitation.

It's only a report, not more.
Perhaps somebody can say more to this (e.g. level or reason of development).
Windows 10 Professional - Avast Free Antivirus - Avast Secure Browser

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Luukjr

  • Sr. Member
  • ****
  • Posts: 276
Re: Issus regarding the security of Avast Secure Browser (bank mode)
« Reply #2 on: April 11, 2020, 11:51:26 AM »
Since a few years I'm working with the Avast Antivirus Engine and the Secure Browser.
It's a very comfortable and secure way to work in the internet with extensives ways to configure (i like it  :D).

Unfortunately it works with windows board equipments inside the bank mode.
It's like you lock your house, but you let open the backdoor of the building.

If you find a way to exchange one of these files (e.g. notepad.exe or calc.exe), it' is possible to break into the sandbox.
I tried it with metasploit and a reverse tcp connection on my local pc system (combined with Virtualbox).
The result was, that I had the possibility to log the keyboard input inside the sandbox.
This is really to simple.  :o

Why Avast don't create his own tools inside the bank mode?
Another idea is to transfer the ASB bank mode to a window instead a full screen mode.
All keyboard inputs could be encrypted (my home bank work on this way).
Anyone could use all the tools they need without limitation.

It's only a report, not more.
Perhaps somebody can say more to this (e.g. level or reason of development).

Suppose you use the 2-Step Verification to log in to your bank, how likely is it that the secure browser bank modus can be abused? Just a question from an interested layman. ???
« Last Edit: April 11, 2020, 12:44:17 PM by Luukjr »
OS: Windows 10 Home
Soft: Avast Premium Security  / Avast Cleanup / Malwarebytes Premium

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48604
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Issus regarding the security of Avast Secure Browser (bank mode)
« Reply #3 on: April 11, 2020, 03:01:42 PM »
Since a few years I'm working with the Avast Antivirus Engine and the Secure Browser.
It's a very comfortable and secure way to work in the internet with extensives ways to configure (i like it  :D ).

Unfortunately it works with windows board equipments inside the bank mode.
It's like you lock your house, but you let open the backdoor of the building.

If you find a way to exchange one of these files (e.g. notepad.exe or calc.exe), it' is possible to break into the sandbox.
I tried it with metasploit and a reverse tcp connection on my local pc system (combined with Virtualbox).
The result was, that I had the possibility to log the keyboard input inside the sandbox.
This is really to simple.  :o

Why Avast don't create his own tools inside the bank mode?
Another idea is to transfer the ASB bank mode to a window instead a full screen mode.
All keyboard inputs could be encrypted (my home bank work on this way).
Anyone could use all the tools they need without limitation.

It's only a report, not more.
Perhaps somebody can say more to this (e.g. level or reason of development).

Suppose you use the 2-Step Verification to log in to your bank, how likely is it that the secure browser bank modus can be abused? Just a question from an interested layman. ???
I don't follow your 2 step question? In bank mode, you would enter your user name and p/w then you would received your
numeric or alpha numeric code via your smart device and enter it into the appropriate place. How is that bypassing anything?
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline svnupa

  • Jr. Member
  • **
  • Posts: 27
Re: Issus regarding the security of Avast Secure Browser (bank mode)
« Reply #4 on: April 12, 2020, 10:36:27 AM »
Since a few years I'm working with the Avast Antivirus Engine and the Secure Browser.
It's a very comfortable and secure way to work in the internet with extensives ways to configure (i like it  :D ).

Unfortunately it works with windows board equipments inside the bank mode.
It's like you lock your house, but you let open the backdoor of the building.

If you find a way to exchange one of these files (e.g. notepad.exe or calc.exe), it' is possible to break into the sandbox.
I tried it with metasploit and a reverse tcp connection on my local pc system (combined with Virtualbox).
The result was, that I had the possibility to log the keyboard input inside the sandbox.
This is really to simple.  :o

Why Avast don't create his own tools inside the bank mode?
Another idea is to transfer the ASB bank mode to a window instead a full screen mode.
All keyboard inputs could be encrypted (my home bank work on this way).
Anyone could use all the tools they need without limitation.

It's only a report, not more.
Perhaps somebody can say more to this (e.g. level or reason of development).

Suppose you use the 2-Step Verification to log in to your bank, how likely is it that the secure browser bank modus can be abused? Just a question from an interested layman. ???
I don't follow your 2 step question? In bank mode, you would enter your user name and p/w then you would received your
numeric or alpha numeric code via your smart device and enter it into the appropriate place. How is that bypassing anything?

I share this opion. 2FA is so safe, how it can be.
The risk is higher for services which using no 2FA function.

Besides that, you have nothing to fear, if you don't use the tools inside the sandbox.
Then nothing can be bypasst (I don't know a way).

Also I'm really sure, that somebody at Avast has already thought about that problem.
Windows 10 Professional - Avast Free Antivirus - Avast Secure Browser