Hackers and professional penetration testers can run it on computers that they have already taken control of.

The point of KeeFarce is to actually obtain the contents of the password database.

This prevents malicious apps from scraping random access memory and bringing back the credentials.

Encrypted credentials from password manager swiped using hacking tool

The extracted data is in clear text and includes user names, passwords, notes, and URLs.

If KeeFarce was folded into Metasploit or other hacker frameworks, it could end up being very scary.

However, it looks like KeeFarce is here to ensure that nobody forgets it.

spot_img

source: www.techworm.net