Jump to content

Recommended Posts

Posted

Internet Explorer Data Leakage

 

On the 1st of October, 2012, we disclosed to Microsoft the following security vulnerability in Internet Explorer, versions 6–10, which allows your mouse cursor to be tracked anywhere on the screen—even if the Internet Explorer window is minimised. The vulnerability is particularly troubling because it compromises the security of virtual keyboards and virtual keypads.

 

spider.io — Internet Explorer Data Leakage

Posted

I've been reading about this the past few days... It's not really that big of a deal.

 

You can track mouse movements, but it doesn't tell you what is on the screen.

 

As for compromising on-screen keyboards... They [the attacker] would have to know WHICH page it was on [on a particular website], the layout of the page, the mouse's original location prior to the exploit being run and the layout of the onscreen keyboard. Plus any account information NOT entered with the on-screen keyboard.

 

If they can get all that they don't need the exploit.

Posted
I disagree, looking at Windows 8 and it's on screen keyboard with tablets, it wouldn't be difficult at all to reconstruct passwords and so on over time. Could well be a very dangerous flaw indeed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...