Главная
Study mode:
on
1
Intro
2
Typical Formjacking Sequence
3
Formjacking Demo ... let's go shopping
4
Formjacking Incidents
5
Formjacking Detections and Infections
6
Get the Script onto the Server Own vulnerable infrastructure
7
Many Ways to Inject the Script • Directly in the HTML/PHP with a tag . Link to a remote server, e.g.
8
Script Activation Script is only activated if keyword is found, e checkout and if there is a web form Method Description
9
Gathering the Data
10
Exfiltrating Data
11
Easy to Use» Formjacking Toolkits
12
Not Always Easy to Help
13
Mitigation Tips
14
Summary - Formjacking - JavaScript Skimmers
15
Apply Slide - Formjacking
16
RSAConference 2020
Description:
Explore the world of JavaScript skimmers, formjacking, and Magecart in this comprehensive 51-minute conference talk from RSA Conference. Delve into the tactics used by attackers to steal valuable user data from websites, with Symantec Threat Researcher Candid Wueest as your guide. Gain insights into blocking nearly one million such attacks monthly, and learn step-by-step how to protect your infrastructure from compromise and potential hefty fines. Discover the typical formjacking sequence, witness a live demo, and understand various infection methods, script activation techniques, and data exfiltration processes. Examine formjacking toolkits, discuss challenges in mitigation, and acquire practical tips to safeguard your systems. Suitable for those with a general understanding of HTTP requests and HTML pages, this talk equips you with essential knowledge to combat this prevalent cybersecurity threat.

JavaScript Skimmers, Formjacking and Magecart - All You Need to Know

RSA Conference
Add to list
0:00 / 0:00