BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Defeating Citi-Bank Virtual Keyboard Protection Aug 05 2005 11:11PM
Daniel Bonekeeper (thehazard gmail com)
First, seems that this kind of "virtual keybord" is, by design, weak.
The data posted to the webserver is the same as the content on the
IPIN field (there is no such a encoding or another thing to mask what
was typed). A more secure example of a virtual keyboard can be found
at:

https://www2.bancob...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus