Re: Defeating Citibank Virtual Keyboard protection using screens

看板Bugtraq作者時間18年前 (2007/05/18 02:28), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串13/14 (看更多)
> If malware is running on the user's computer, can it change the > destination of a funds transfer invisibly to the user, and still have > the verification work? Theoretically, this is possible. An advanced client-side MITM attack could be crafted, altering packets on-the-fly and returning a false confirmation page. i.e.: normal response: "$100 USD has been transferred from your@email.com to evil@hacker.com" altered response: "$100 USD has been transferred from your@email.com to your@recipient.com" -John Martinelli RedLevel.org Security
文章代碼(AID): #16J9wu00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 13 之 14 篇):
文章代碼(AID): #16J9wu00 (Bugtraq)