A Security Concern in MS-Windows: Stealing User Information From Internet Browsers Using Faked Windows



This demo application creates faked window controls of the username and password, and places them on top of the real controls whenever the user opens the hotmail login page (at http://www.hotmail.com) using Microsoft Internet Explorer 6.0. When the user clicks the "Sign In'' button, a message pops up with the username and password entered by the user. Obviously, this application simply demonstares how usernames and passwords can be captured by different processes, and does not record or transmit the password.

faked_win.exe - Main executable (MS-Windows).