Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Defeating Citibank Virtual Keyboard protection using screenshot method
From: Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net>
Date: Fri, 11 May 2007 00:42:14 +0200

On 2007-05-10 Florian Weimer wrote:
* David Gillett:
But your point above:
"without installing malware on the victim host"

Although true on some level, is bogus for the purpose of this work,
as it being written makes an automatic assumption on working only
after malware is installed.

  The principle of "defence in depth" is that each security measure
adds to overall security by providing protections that continue to
operate even if other defences have been breached.

Isn't it more like combining several things which aren't
unconditionally secure by themselves, in the hope that the result is
something you can actually live with?

That would hardly qualify as "in depth".

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]