WebApp Sec mailing list archives

Re: keyloggers?


From: "Greg Stiavetti" <gstiavetti () rentoneonline com>
Date: Tue, 5 Apr 2005 15:15:02 -0700

There are devices on the market (hardware) that go inline with the keyboard cable, completely undetectable by keylogger detection software, that can capture and replay every keystroke. ( does not work on USB keyboards, only PS2 style).

Rule Of Thumb - "Don't Bank Where You Eat".

http://www.keyghost.com/  Been on the market for years.



----- Original Message ----- From: "SB" <vidyabalaji () gmail com>
To: <webappsec () securityfocus com>
Sent: Friday, April 01, 2005 12:48 PM
Subject: keyloggers?


Hi!

Any recommendations of Best Practices when accessing your Online
Banking account from an Internet Cafe?  Assuming your bank does not
provide two factor authentication, are there any specific checks you
can do, tools you can run on a  machine to ensure it is not Logging
keystrokes, caching UID/pwds etc

Any suggestions or advice in this area is greatly appreciated

Thanks

SB




Current thread: