Linux for Travelers - Keyloggers https://www.linuxfortravelers.com/taxonomy/term/271/0 en Beware of Hardware Keyloggers https://www.linuxfortravelers.com/look-for-hardware-keyloggers <p>It is not common, but computers can have <a href="http://en.wikipedia.org/wiki/Hardware_keylogger">hardware keyloggers</a> attached to them. If a computer has a hardware keylogger on it, it will be able to record your keystrokes even if you are using a Linux live CD.</p> <p>There is a solution though. While using an <a href="http://www.combobulate.com/node/22">on-screen keyboard</a> will not protect you against software keyloggers, an on-screen keyboard should protect you against hardware keyloggers. So the combination of a Linux live CD and the use of an on-screen keyboard to enter your passwords should protect against both hardware keyloggers and software keyloggers.</p> <h2>The Risk of Hardware Keyloggers in Public Internet Cafes</h2> <p>I suspect that hardware keyloggers are not common in public Internet cafes. It is much easier for Internet criminals to use malicious software to do their work for them remotely. Physical devices attached to the computer increase their chances of getting caught.</p> <p>While most public computers have spyware, viruses, and trojans, very few have hardware keyloggers. In any case, here are some tips:</p> <h2>What Do Hardware Keyloggers Look Like?</h2> <p>I've linked to some images of hardware keyloggers below. The most common hardware-based keyloggers are a physical device that fits between the end of the plug of the keyboard and the box of the computer:</p> <ul> <li><a href="http://www.keyghost.co.nz/images/KeyGhost_SX_Mini_Swoosh.jpg" rel="nofollow">A hardware keylogger that fits between keyboard and computer</a></li> <li><a href="http://getusb.info/wp-content/uploads/2006/07/071306a.jpg" rel="nofollow">A hardware keylogger for USB keyboards</a></li> <li>A <a href="http://www.keyghost.com/images/kginst1.jpg" rel="nofollow">before</a> and <a href="http://www.keyghost.com/images/kginst2.jpg" rel="nofollow">after</a> shot of a computer with hardware keylogger installed. Notice the extra length of cable in the &quot;after&quot; image.</li> <li><a href="http://keyphantom.com/images/Prdt_Cable_Personal_Lg.gif" rel="nofollow">Another hardware keylogger</a></li> </ul> <h2>Hardware Keylogger Lookalikes</h2> <p>Be aware that not every device that fits between a keyboard and a computer is a keylogger. There are <a href="http://www.chinatraderonline.com/Files/USB-Series/USB-Connectors/USB-to-PS2-Adapter-21155568810.jpg">similar-looking devices</a> that are made to convert one type of plug to another (for example USB to PS/2). These adapter plugs are harmless.</p> <h2>How to Protect Yourself Against Hardware Keyloggers</h2> <p>It's always good to take a moment to look at the connection between the keyboard and the computer before you use a public computer. That is not the only kind of hardware keylogger though. There are also hardware keyloggers that can be put inside keyboards, or in other hard-to-detect places. By using a Linux live CD in combination with an <a href="http://www.combobulate.com/node/22">on-screen keyboard</a>, you should be able to bypass hardware keyloggers.</p> <p><a href="https://www.linuxfortravelers.com/look-for-hardware-keyloggers">read more</a></p> https://www.linuxfortravelers.com/look-for-hardware-keyloggers#comment Fraud Prevention Tips Keyloggers Windows Security Linux Security Thu, 10 Aug 2006 23:25:10 -0400 LFT 99 at https://www.linuxfortravelers.com Keylogger Exploit https://www.linuxfortravelers.com/keylogger-exploit <p>A recent <a href="http://www.theregister.co.uk/2006/03/31/ie_exploit_bbc_bait/">story on the Register</a> describes a computer attack that shows how easily a Windows computer can become infected with a keylogger:</p> <blockquote><p>"Surfers who follow this link are taken to a spoof copy of the BBC story hosted on a maliciously constructed site that exploits the unpatched createTextRange vulnerability in an attempt to install key logging software on victim PCs.</p> <p>This key logger monitors activity on various financial websites and uploads captured information back to the attacker, security firm Websense warns."</p></blockquote> <p>It is very easy to infect a Windows computer with malicious software, which is why strong precautions should be taken when using public computers for financial purposes.</p> <p><a href="https://www.linuxfortravelers.com/keylogger-exploit">read more</a></p> https://www.linuxfortravelers.com/keylogger-exploit#comment Keyloggers Malware Windows Security Thu, 27 Jul 2006 17:17:59 -0400 LFT 97 at https://www.linuxfortravelers.com