WebApp Sec mailing list archives

Re: Defeating Citi-Bank Virtual Keyboard Protection


From: intel96 <intel96 () bellsouth net>
Date: Fri, 12 Aug 2005 16:56:10 -0400

I tested this application against several password protected fields and out of 10 it only obtain 1.
Saqib Ali wrote:

Virtual keyboards don't help much. Tools similar to what you have
developed have existed for a while now. See
http://www.lostpassword.com/asterisk.htm  , it does the same thing as
your CitiPassLogger.exe . And it works regardless of the input method.


On 8/5/05, Debasis Mohanty <debasis () hackingspirits com> wrote:
Recently I discovered a method to defeat the much hyped Citi-Bank Virtual
Keyboard Protection which the bank claimed that it defends the customers
against malicious programs like keyloggers, Trojans and spywares etc.




Current thread: