[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.LNX.4.58.0508052250570.26269@dione>
Date: Fri Aug 5 21:56:33 2005
From: lcamtuf at dione.ids.pl (Michal Zalewski)
Subject: Defeating Citi-Bank Virtual Keyboard Protection
On Fri, 5 Aug 2005, Jeremy Bishop wrote:
> You'd need to squeeze in some OCR code as well, or figure it out
> manually (or maybe use the same techniques as for getting around
> "captchas").
Well, if carders can be bothered to review hours of recorded material from
ATM-mounted cameras to grab PINs, they would be more than happy to review
some JPEGs by hand; make the logger activate only when a specific group of
SSL sites is displayed - and voila, live and prosper (then eventually go
to jail).
/mz
Powered by blists - more mailing lists