//flex table opened by JP

Click to See Complete Forum and Search --> : Security Question re: Key logger programs


GrefMofovich
06-08-2005, 11:52 PM
Not that I have anything to hide, anything subversive or otherwise communistic, but is there a way to prevent your typical key logger spyware with some sort of bypass or redirect of the signal or... something? Ideally there wouldn't be some foreign entity filling in webforms for me too. Because if I know anything about anything, key loggers remain completely undetectable to spyware suites... unless they're famous, and then they're discarded and new ones are made.

God bless America and it's imperator. :)

-GM

Hola hoop
06-09-2005, 02:26 PM
Thats not entirely true to say keyloggers are undectable to spyware. Pest patrol would find some key loggers and more than anything else. there would have to be some form of communication between your computer and the "hackers" computer.
This is usually done on a periodic bases, say once a month when the details are uploaded.

Keyloggers dont fill out forms and such, they simply record nothing more. One good way to check for them is with a good port scanner as the ports 1243, 27374 and port 6667 TCP are probed for the SubSeven keylogger, but a re-direct....doubt it. You would need to know the destination of where the info was being sent and then somehow change the path, which you can usually only do on the computer who sent the program as your comp becomes the server once infected, just like a remote access tool. You can deny the request for remote access, but you cannot stop the request being made if the program is on your comp and up and running with permissions.

http://hacker-eliminator.com/keylogger.gif

GrefMofovich
06-13-2005, 03:54 AM
Originally posted by Hola hoop
Thats not entirely true to say keyloggers are undectable to spyware. ...

But how can any am prog (anti-malware) distinguish between a legitimate reading of keypresses from undesired reading? It really can't. Then, even if you could pick out the one transmit you'd want to stop out of ALL the network traffic going on in a modern system, how would you know what to look for?

Don't trust small time companies with their amazing products that "do even more than all the other am programs you've bought before"...

Anyway, I guess no one will want to steal my maple story (http://www.mapleglobal.com) password enough for me to lose bubble bath time over it. Just wondering if any ex-CIA agents read this and can hook me up with a voice-operated input device that makes letters appear like a from keyboard while making it look to keypress checkers like I'm typing in mongolian epic poetry.
-GM

Hola hoop
06-13-2005, 09:49 AM
Distinguishing between legimate keypresses and undesirable ones? There is no such thing im afraid because all keypresses are deemed legimate as you are right in front of the comp.
That is not how they detect them
They do so by
Identified signature unique to keylogging software (already released versions)
Script monitoring (the keylogger will be storing the info in certain formats, could also detect registry change or unauthorised access change once trojan is either installed or becomes active)
The connection (between your comp and the host comp)

If you want the characters to appear in different format then you need to use encrytption, even then this would not help as you would still need to type the password in (usually the field variable is "hidden" but is still recorded in plain text format.

In other words.....if sumone wanted to steal your passwords then they probably could. Just be aware and cautious and get a good firewall and script blocker to give you more control. At least that way you can prevent a keylogger from sending the details back, but very hard to stop it collecting data in the first place.

:t