Re: [Full-disclosure] Defeating Image-Based Virtual Keyboards and Phishing Banks (fwd)

2006-11-29 Thread Matthew Flaschen
If anyone's interested, a while ago I made a greasemonkey user script that bypasses the virtual keyboard on ING Direct (http://userscripts.org/scripts/show/3998) Matt Flaschen Gadi Evron wrote: > Copied from a post by Noam Rathaus on the SecuriTeam Blogs, following up a > post by HispaSec. This i

[Full-disclosure] Defeating Image-Based Virtual Keyboards and Phishing Banks (fwd)

2006-11-27 Thread Gadi Evron
Copied from a post by Noam Rathaus on the SecuriTeam Blogs, following up a post by HispaSec. This is about breaking virtual keyboards implementations, and the encryption some of them use (most of them send the data in clear text with the image). HispaSec was a reference by which we found the banks'