Re: Defeating Citibank Virtual Keyboard protection using screens

看板Bugtraq作者時間18年前 (2007/05/10 03:24), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/14 (看更多)
On 7 May 2007 yashks@gmail.com wrote: > Severity: Critical Erm, you do realize malware has been doing this for a long long time now, right? Virtual keyboards come as a solution for fighting one type of phishing and one type alone. OCR or screenshots of mouse position on-click, for example, are happening daily. In most cases, it isn't really required to take screenshots: http://blogs.securiteam.com/index.php/archives/678 Gadi. > > Platforms Affected: > > Microsoft Corporation: Windows 98 Any version > Microsoft Corporation: Windows Me Any version > Microsoft Corporation: Windows XP Any version > Microsoft Corporation: Windows 2000 Any version > Microsoft Corporation: Windows 2003 Any version > Microsoft Corporation: Windows NT 4.0 Any version > Citi-Bank: Citi-Bank Virtual Keyboard Any version > > Browsers: > Microsoft Internet Explorer Any version > Mozilla FireFox Any version > Any browser runs on Win32 platform ( With slight modification ) > > Original URL : http://www.tracingbug.com/index.php/articles/view/23.html > > Regards, > Yash K.S <yashks@gmail.com > | www.tracingbug.com >
文章代碼(AID): #16GY0A00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 2 之 14 篇):
文章代碼(AID): #16GY0A00 (Bugtraq)