Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Defeating Citibank Virtual Keyboard protection using screenshot method May 07 2007 10:02AM
yashks gmail com (4 replies)
Re: Defeating Citibank Virtual Keyboard protection using screenshot method May 10 2007 10:53PM
Jan Heisterkamp (janheisterkamp web de)
RE: Defeating Citibank Virtual Keyboard protection using screenshot method May 09 2007 06:10PM
Jim Harrison (Jim isatools org) (1 replies)
RE: Defeating Citibank Virtual Keyboard protection using screenshot method May 09 2007 11:14PM
Nick FitzGerald (nick virus-l demon co uk) (1 replies)
Re: Defeating Citibank Virtual Keyboard protection using screenshot method May 09 2007 05:56PM
Gadi Evron (ge linuxbox org)
Re: Defeating Citibank Virtual Keyboard protection using screenshot method May 09 2007 05:53PM
Reversemode (advisories reversemode com)

Hi Yash,

> Severity: Critical
> Platforms Affected:
>
> Microsoft Corporation: Windows 98 Any version
> Microsoft Corporation: Windows Me Any version
> Microsoft Corporation: Windows XP Any version
> Microsoft Corporation: Windows 2000 Any version
[CUT]
...

You are talking about a documented feature, neither a flaw nor a
vulnerability. How can be an API rated?

>Vendor Response:

>No Response from Vendor yet

I cannot imagine Windows with BitBlt disabled... :)

This is a known method widely used in banking trojans since a long time
ago.

Anyway, thanks for sharing your research.

cheers,
- Rubén.

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus