<body>

Hands-on Project 2-2

Date: Thursday, June 03, 2010


Hands-on Project 2-2 :Use of Keylogger

What is a keylogger?
Keylogger is a small hardware device or a program that monitors each keystroke a user types on the computer’s keyboard. As the user types, the keystrokes are collected and saved as text. As a hardware device, a key logger is a small device inserted between the keyboard connector and computer keyboard port.


Keystroke Recoder downloaded from www.softdd.com/keystrokerecorder/index.html.



A screen capture of the keyboard collector settings.



Logs of text that I typed that were captured.


Keyboard Collector does not appear to be running.It is cloaking itself.


Reflection:
In this hands-on project, I get to use the software keylogger. Software keylogger is a program that silently captures all keystrokes, including passwords and sensitive information. Such program will hide themselves so that they cannot be easily detected even if a user is searching for them. I had open Task Manager and tried to find the “keyboard collector” in Application and Process. But as seen in the screen shot, such program does hide themselves and thus I could not find it. I had also done a search on web to find out more about keyloggers. I saw that there are many different form of key logger, such as Keyboard overlays which is used on ATM machines to capture people's PINs and Acoustic keyloggers which works by monitoring the sound produced by each character on the keyboard that makes a subtly different acoustic signature when stroked. But of course, most of the keylogger are applied in illegal ways. Countermeasures are also available to against keylogger. One common way is to use Anti-spyware that are able to detect keyloggers and quarantine, disable or cleanse them. Another way is to use One-time passwords (OTP), I had being using internet banking service, but I could not understand why they need one-time passwords as it’s really nuisance that I have to key in the OTP for every action. Now, since I understand the risk of keylogger, I can also understand one-time passwords are implemented to protect accounts from keylogging attacks as well as replay attacks.

Labels: ,


林小颍's work ^—^V