Information Security Blog

Zeus – NYS Department Homeland Security Guidance

Zeus – NYS Department Homeland Security Guidance

Hopefully, this will be the last time I write about Zeus the banking Trojan.  However, when the New York State Department of Homeland Security releases a five page cyber information security advisory — its a little hard to ignore it.

It’s a very comprehensive document that provides good guidance, although I was a bit disappointed they didn’t discuss using a non-windows platform and/or running off a live bootable cd or usb.

That being said, I really liked their idea of using the on screen keyboard (osk.exe invokes it) for entering in your password.  It’s a tiny bit awkward … but it virtually eliminates your password from being stolen via Zeus or similar malware.



About the Author:

John W. Verry, CISA/27001 Lead Auditor/CCSE/CRISC - "Security Sherpa" - Information Security Auditor

Add a Comment