MSFN Forum: [SEC] How to protect ourselves against keyloggers? - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

[SEC] How to protect ourselves against keyloggers? Rate Topic: -----

#1 User is offline   Wai_Wai 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 13-July 04

  Posted 04 April 2006 - 01:50 PM

How to protect ourselves against keyloggers (or anything similar)?

Hey.
Apart from the obvious method of installing a anti-virus OR anti-keylogger program, what lese could we do to stop keyloggers (or anything similar) from stealing our important data/passwords etc. ?

Thank you. :yes:

Gouki: Title edited. Rules.


#2 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 04 April 2006 - 01:54 PM

First, PLEASE read this forum rules.

As for your 'problem' ...

Physical access to machines (no need to Operating System access), is a pretty good problem. Big part of Keyloggers can be connected between the keyboard and the computer. Invisable to the 'distracted' eye, since they are really small 'gadgets'.

As for software based keyloggers, I think the best idea is to instruct users (in a company scenario) to be carefull with eMails and IM. Other than that, maybe keeping an eye open on the services running.

Take care.

P.S: Please try and follow the rules the next time.

#3 User is offline   LLXX 

  • MSFN Junkie
  • PipPipPipPipPipPipPipPipPip
  • Group: Banned
  • Posts: 3,399
  • Joined: 04-December 05

Posted 04 April 2006 - 09:10 PM

Firewall will alert you if anything is trying to send keylogs out through the network.

You also have to be careful of what you download and run.

#4 User is offline   Wai_Wai 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 13-July 04

  Posted 05 April 2006 - 11:53 AM

Thanks for your reply.

I wonder if there're some other preventive methods (apart from security-software-based help like Firewall/anti-keyloggers) could be done to prevent keyloggers to record our keyboard activities.

How about if a user type the password via a visual keyboard (by clicking keys on the screen)?
Does it help?

#5 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 05 April 2006 - 12:01 PM

Yes. That would help, allot. However, that would not make it completly secure (Well, *nothing* is totally secure).

Implementing an on screen keyboard would help allot, however, there are 'keyloggers' for mouse movements. Randomly changing the buttons from the on screen keyboard, every time it starts, would be a solution to this.

My bank has it and it works like a charm.

#6 User is offline   Wai_Wai 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 13-July 04

  Posted 06 April 2006 - 09:06 AM

View PostGouki, on Apr 5 2006, 12:01 PM, said:

Yes. That would help, allot. However, that would not make it completly secure (Well, *nothing* is totally secure).

Implementing an on screen keyboard would help allot, however, there are 'keyloggers' for mouse movements. Randomly changing the buttons from the on screen keyboard, every time it starts, would be a solution to this.

My bank has it and it works like a charm.


Thanks.

Does it matter what onscreen keyboards I use?
Any recommendation?

Is it possible for hackers to record my monitor?

Other than the abovementioned, any other precautions? ;)

#7 User is offline   Gouki 

  • MSFN Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,168
  • Joined: 19-March 05

Posted 06 April 2006 - 11:21 AM

It is possible to record your monitor, however, they would need a server side application running at your system. This can be preventedd by carefully choosing what you download and install.

As for suggestions to the OSK ... Sorry, but I have no idea of wich one is best.

Better than all of this? Buy a blackbox (firewall) :)

#8 User is offline   HyperHacker 

  • Just plain nuts
  • PipPipPip
  • Group: Members
  • Posts: 473
  • Joined: 01-May 05

Posted 08 April 2006 - 03:49 AM

When I enter a password on a public computer, I enter the letters in random order. Like instead of entering "password" I might enter "ord", then click before the first character and type "asw", then click after the "a" and type another "s", and so on. By clicking rather than using the arrow keys, it comes out garbled in a key log.

#9 User is offline   Wai_Wai 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 13-July 04

  Posted 08 April 2006 - 10:47 AM

View PostHyperHacker, on Apr 8 2006, 03:49 AM, said:

When I enter a password on a public computer, I enter the letters in random order. Like instead of entering "password" I might enter "ord", then click before the first character and type "asw", then click after the "a" and type another "s", and so on. By clicking rather than using the arrow keys, it comes out garbled in a key log.


This trick sounds interesting.
Tease the hyperhacker :P

This post has been edited by Wai_Wai: 08 April 2006 - 10:53 AM


#10 User is offline   Delprat 

  • Poll: Why are you reading this ?
  • PipPipPip
  • Group: Members
  • Posts: 481
  • Joined: 18-May 05

Posted 08 April 2006 - 11:13 AM

View PostWai_Wai, on Apr 8 2006, 06:47 PM, said:

View PostHyperHacker, on Apr 8 2006, 03:49 AM, said:

When I enter a password on a public computer, I enter the letters in random order. Like instead of entering "password" I might enter "ord", then click before the first character and type "asw", then click after the "a" and type another "s", and so on. By clicking rather than using the arrow keys, it comes out garbled in a key log.


This trick sounds interesting.
Tease the hyperhacker :P

Too bad, it's easy to work around :
1/ brute force cracking is far easier when you had "keylogged" the right characters
2/ mouse clicks and/or time between key presses allows to know "words" to permit into the password

In fact the only good password is the one which changes randomly after each use :lol:

++

This post has been edited by Delprat: 08 April 2006 - 11:15 AM


#11 User is offline   LLXX 

  • MSFN Junkie
  • PipPipPipPipPipPipPipPipPip
  • Group: Banned
  • Posts: 3,399
  • Joined: 04-December 05

Posted 09 April 2006 - 01:21 AM

View PostHyperHacker, on Apr 8 2006, 04:49 AM, said:

When I enter a password on a public computer, I enter the letters in random order. Like instead of entering "password" I might enter "ord", then click before the first character and type "asw", then click after the "a" and type another "s", and so on. By clicking rather than using the arrow keys, it comes out garbled in a key log.
Also won't work if the keylogger doesn't log keys in-order, but just hooks editboxes and retrieves their contents. A few of them do this. However, it's still a little extra security at little cost.

#12 User is offline   Wai_Wai 

  • Member
  • PipPip
  • Group: Members
  • Posts: 139
  • Joined: 13-July 04

  Posted 09 April 2006 - 05:13 AM

View PostLLXX, on Apr 9 2006, 01:21 AM, said:

View PostHyperHacker, on Apr 8 2006, 04:49 AM, said:

When I enter a password on a public computer, I enter the letters in random order. Like instead of entering "password" I might enter "ord", then click before the first character and type "asw", then click after the "a" and type another "s", and so on. By clicking rather than using the arrow keys, it comes out garbled in a key log.
Also won't work if the keylogger doesn't log keys in-order, but just hooks editboxes and retrieves their contents. A few of them do this. However, it's still a little extra security at little cost.


:yes:
So a visual keyboard is a solution to "Delprat & LLXX problems", right? ;)
No one has any idea what visual keyboard should I use?

#13 User is offline   Delprat 

  • Poll: Why are you reading this ?
  • PipPipPip
  • Group: Members
  • Posts: 481
  • Joined: 18-May 05

Posted 09 April 2006 - 07:36 AM

View PostWai_Wai, on Apr 9 2006, 01:13 PM, said:

So a visual keyboard is a solution to "Delprat & LLXX problems", right? ;)
No one has any idea what visual keyboard should I use?


Hit <Win>+U on your keyboard, click on the "visual keyboard" line, then press the "start" button... :thumbup :whistle:

About "editboxes hooking", that's for "badly" written apps... some doesn't use "masked editboxes", but "editboxes with real *" (bad explanation, but i hope you'll understand).
I've also seen a "password safe" app whith a masked editbox, but with a false password behind the mask (not the one typed in) :wacko:

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy