A novel technique for defeating virtual keyboards - Exploiting insecure features of modern browsers
No Thumbnail Available
Date
2011
Authors
Nadkarni, T.S.
Mohandas, R.
Pais, A.R.
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Advancement in technology is a necessity of time, but as new techniques are introduced, new security vulnerabilities are discovered and exploited in practice. In this paper we are presenting a new approach to defeat virtual keyboards using a new method for capturing parts of a browser screen. The page rendered in the browser is captured by using the canvas element provided by HTML5. We have specified the technical details of how this functionality is exploited and created a malicious extension for Mozilla Firefox browser. This extension captures screenshots of web pages rendered in the browser and sends them to a remote server. In addition, we have suggested mitigation strategies to prevent misuse of such browser functionalities. � 2011 Springer-Verlag.
Description
Keywords
Citation
Communications in Computer and Information Science, 2011, Vol.191 CCIS, PART 2, pp.685-692