[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <46420A7E.4040407@reversemode.com>
Date: Wed, 09 May 2007 19:53:02 +0200
From: Reversemode <advisories@...ersemode.com>
To: Securityfocus <bugtraq@...urityfocus.com>
Cc: yashks@...il.com
Subject: Re: Defeating Citibank Virtual Keyboard protection using screenshot
method
Hi Yash,
> Severity: Critical
> Platforms Affected:
>
> Microsoft Corporation: Windows 98 Any version
> Microsoft Corporation: Windows Me Any version
> Microsoft Corporation: Windows XP Any version
> Microsoft Corporation: Windows 2000 Any version
[CUT]
...
You are talking about a documented feature, neither a flaw nor a
vulnerability. How can be an API rated?
>Vendor Response:
>No Response from Vendor yet
I cannot imagine Windows with BitBlt disabled... :)
This is a known method widely used in banking trojans since a long time
ago.
Anyway, thanks for sharing your research.
cheers,
- Rubén.
Powered by blists - more mailing lists