Jump to content

Login Pin + Screenshot Logger Protection -New RSOF Thread-


Recommended Posts

 

Would be equally easy to steal using a decent keylogger / RAT.

 

 

 

 

 

 

 

PoC for how it could be easily stolen:

 

 

 

 

 

 

 

if ( (color under pointer == red) && ( event == mouseDown))

 

 

 

{

 

 

 

save printScreen to same file as keylogger data

 

 

 

}

 

 

 

 

 

 

 

The person who is in control of the keylogger then just looks for which number is missing, aka which the mouse is over. However most of the keylog distributors do not write their own keloggers but instead use a widely available one, but it still would not be hard to bypass with an easily modified program.

 

 

 

 

 

 

 

Would swtiching the color backround of the buttons around do anything

 

 

 

 

 

 

 

If each button was a different background, it would just take a little bit more time to work around, but is still just as easy 2 steal as a bankpin.

You make it sound like running through a few level 87 monsters is hard which it really shouldn't be at your level.

riptide_mage.png

riptide_mage.png

Link to comment
Share on other sites

 

 

Would be equally easy to steal using a decent keylogger / RAT.

 

 

 

 

 

 

 

PoC for how it could be easily stolen:

 

 

 

 

 

 

 

if ( (color under pointer == red) && ( event == mouseDown))

 

 

 

{

 

 

 

save printScreen to same file as keylogger data

 

 

 

}

 

 

 

 

 

 

 

The person who is in control of the keylogger then just looks for which number is missing, aka which the mouse is over. However most of the keylog distributors do not write their own keloggers but instead use a widely available one, but it still would not be hard to bypass with an easily modified program.

 

 

 

 

 

 

 

Would swtiching the color backround of the buttons around do anything

 

 

 

 

 

 

 

If each button was a different background, it would just take a little bit more time to work around, but is still just as easy 2 steal as a bankpin.

 

 

 

 

 

 

 

What about picture backgrounds?

f203f1850c.png
Link to comment
Share on other sites

Great idea, might stop some macros too. You can count that as a support.

Link to comment
Share on other sites

This is a good idea, however, maybe a better idea would be to have an on-screen keyboard at the bottom, that is optional to use. So, people that are afraid they might have a keylogger on their computer (or people that are just extremely paranoid), can use that instead, and people that don't think they have a keylogger on their computer (or people who don't care at all), can just type it in like they're used to doing. Also, you could maybe have something like they do with the log-in music button, where you could turn it off or on, whichever you prefer. Good idea though, I've been thinking about this for a while actually :wink:

Link to comment
Share on other sites

2 words: On screen keyboard

 

 

 

The on screen keyboard triggers the exact same responses as a regular keyboard. In other words, it's just as vulnerable.

 

 

 

A keyboard sends signals to your system when a key is pressed. The on screen keyboard simply reads a click of a button in it, and replecates the signal. Keyloggers look for this signal and copy it.

f203f1850c.png
Link to comment
Share on other sites

sopport, but maybe make it optional, because it might get super annoying for people that are world hopping to buy runes, or to find an empty world for training.

ArchSupport.png

Soulthresher: dont think outside of the box, stay inside. the box is your freind

Clicky for the Blog 'o Range

Race to 100 ranged with BBQ_muffin

DarkDude98: Pfft, Real men use Bow and Arrows to get 99 range

Link to comment
Share on other sites

i use the onscreen keyboard, works just like this, and no need for a pin, just type name and pass with on screen keyboard

 

If you'd read earlier in this thread, you would have realized that the OSK is useless for blocking a keylogger.

 

 

 

 

 

 

 

 

 

 

 

 

 

Crimsoncow42, I support this idea. 8-)

 

 

 

~Mr. Devnull

tifuserbar-dsavi_x4.jpg and normally with a cool mind.

(Warning: This user can be VERY confusing to some people... And talks in 3rd person for the timebeing due to how insane they are... Sometimes even to themself.)

Link to comment
Share on other sites

Assuming this is, you enter your pass and than bank pin (for dual protection) than I support. However if its only the bank pin than I would be against it, you cna crack a 4 digit code (though with difficulty under the bank pin system).

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.