A novel technique for defeating virtual keyboards - Exploiting insecure features of modern browsers

No Thumbnail Available

Date

2011

Authors

Nadkarni, T.S.
Mohandas, R.
Pais, A.R.

Journal Title

Journal ISSN

Volume Title

Publisher

Abstract

Advancement in technology is a necessity of time, but as new techniques are introduced, new security vulnerabilities are discovered and exploited in practice. In this paper we are presenting a new approach to defeat virtual keyboards using a new method for capturing parts of a browser screen. The page rendered in the browser is captured by using the canvas element provided by HTML5. We have specified the technical details of how this functionality is exploited and created a malicious extension for Mozilla Firefox browser. This extension captures screenshots of web pages rendered in the browser and sends them to a remote server. In addition, we have suggested mitigation strategies to prevent misuse of such browser functionalities. � 2011 Springer-Verlag.

Description

Keywords

Citation

Communications in Computer and Information Science, 2011, Vol.191 CCIS, PART 2, pp.685-692

Endorsement

Review

Supplemented By

Referenced By