Wednesday, September 3, 2008

Don't just simply "Ctrl-C"!

We do copy various data by Ctrl + C for pasting elsewhere.
This copied data is stored in clipboard and is accessible from the net by a combination of Java scripts and ASP.

Do not keep sensitive data (like credit card numbers, bank login/ passwords, PIN, date of births, etc.) in the clipboard while surfing the web.

Instead make a practice of typing them always.

It is extremely easy to extract the text stored in the clipboard to steal your sensitive information.

Just try this,

1) Copy any text by Ctrl + C

2) Now, click the Link:

3) You will see the SAME text you copied is accessed by this web page.

1 comment:

ayandy said...

Good advice! Never knew about it before.

I tried it and the script doesn't work on Firefox at all... and on IE7 the security settings will prompt for clipboard access... so I've been alright so far. Must keep it in mind though.