Friday, July 23, 2010

Question 2 – Keylogger

A key logger could be in the form of software or hardware and it collects and records all key strokes that are typed. The recorded information could be used by a computer attacker to gain access to information or the computer system.
Software keylogger
A software key logger could be installed via a computer virus or a Trojan.
The collected information will then be emailed to a pre programmed email id. Also these programs does not run as applications on the installed computer and is difficult to detect.
Hardware keylogger
A hardware component that could be inserted between the key board connector cable and the computer keyboard port. The attacker must have physical access to the computer to install and remove the device once the information is captured.
Due to the small size and the fact the key board is connected at the back of the computer these are also very difficult to detect once installed.
Installing a keylogger software
Below steps demonstrate how to install a software key logger on a computer and how the data will be captured once it is in operation.
Step 1 - Download key logger
The particular keylogger used for this task is Keyboard Collector and can be downloaded from
Keystorke Recorder & www.softdd.com

or
Keystorke Recorder & www.cnet.com
Below screen is displayed if you follow link 1.


Step 2 - Install & run key logger
If the computer is installed with anti virus software it may be required to stop it for the duration of the below tasks or modify settings to allow the keylogger software to be downloaded and installed. Download and install the keylogger software. Once download is complete click the .exe file to install.

Step 3 - View recorded log
Once the software is running perform normal computer activities. I opened a notepad file and typed in some text. Then click on keyboard collector icon to execute it and click on view logs. Below screen shows it has captured the text I typed into the notepad file.

Step 3 - Detect keyboard collector
The keylogger software is designed to run undetected on the installed computers. On a windows computer click task manager, then applications and keyboard collector will not appear to be running in the applications as shown below.
Additional step - Detect keyboard collector
Examining the running processes kcol23.exe was found as shown below.
Uninstall keyboard collector
Uninstall using the uninstall provided on the keyboard collector software. However this did not appear to remove all the components and the directory where it was installed and the kcol23.exe still remained. They required to be deleted manually and activate the antivirus software if it was stopped.

No comments:

Post a Comment