Thread: Defeating Keyloggers

    Defeating Keyloggers

    Hii all jst for curiousity if we workin on some shared PC and not sure about the security scene of the machine can we use ONSCREEN Keyboard which windows provide us to type our passwords and other important info,I know it will be too slow to write but can we be sure that supplied info is secured ????? or modern keyloggers will log those too ??


    Yep that will get around key loggers - but be aware some of them have a functionality to record mouse clicks and take screen shots!
    Nokia is right. Wasn't there a thread here regarding new keyloggers that can capture Mouse Click locations? I remember hearing about it recently.

    Nokia is pretty much correct, it will defeat keyloggers that are looking for signals from an HID or other input device (keyboard)...particularly the hardware keyloggers that can be attached inline to a PS2 cable. But as Nokia also said, screen shots, mouse clicks, etc. are also vulnerable.

    As I tout from time to time, Defense in Depth! Taking measures and then saying "Ok, we are completely secure" simply is a pipe dream. You can not be sure the supplied password and info is completely guarunteed secure. You never can; you can only do your best to prevent as much as possible while keeping a system useable. If you think any or all actions will make you completely and unquestionably secure, you are fooling yourself.
    Ok I got it, I know about screenshot taking keyloggers but I think they take it randomly :/
    or they jst record the whole thing when this osk.exe (on screen keyboard) is runnig ??.I mean it will be a lil difficult for them to decipher from screen shots the password I typed. Well I think it can be a "safe" (not that much) practice.


    Keyloggers are just one problem on public or shared systems. If you are using a shared or public system and don't know the security profile of the system, you are best served to not attempt to access private or secure sites (bank accounts, credit card sites, etc). Your sessions to these sites can be captured by other spyware/malware that may infect the system along with keyloggers. Even the use of the on-screen keyboard doesn't help. It must convert the mouse-clicks to data and then send it. The nasties infecting the system will grab that information just as quickly and effectively as the keylogger will grab keystrokes.

    When using public or shared systems, think of it as standing on a busy city street corner and shouting out all your private information to whoever is listening, and handing out your driver's license, credit card, bank card, SSN and other ID to whoever walks by.

    An alternative approach that may work in SOME circumstances, and please note that I said SOME circumstances, and that I swear that I will only spend 90% of your life savings on beer and lose women..............the rest I shall waste

    A floppy...........yeah! one of those funny 3.5" things............has a text file on it.....a table of data.............YOUR DATA.

    Use a normal data entry screen and just copy and paste.............that will stuff a keylogger, as you have not pressed any keys, and you have not selected anything from a virtual keyboord

    OK, there are a hell of a lot more security issues there, but those exist anyway and this is about KEYLOGGERS per se.

    As for screen captures, well that is another issue............and my method is faster so reduces the window of opportunity?

