Bugtraq mailing list archives

Defeating Citibank Virtual Keyboard protection using screenshot method


From: "aditya kuppa" <aditya1010 () gmail com>
Date: Fri, 18 May 2007 01:48:32 +0530

How about this Trojan ;)
http://www.hispasec.com/laboratorio/troyano_video_en.htm
looks great method to get the Password if the inputs are
scrambled,rotated randomly after each entry etc.
Combination of trojan like this +a simple keylogger +a MITM can defeat
all possible authentication mechanism Multi Factor,channel
authentications like OTP,SMS based  logging   etc
Regards
AK
Researcher


Current thread: