We continue the series of presentations of different techniques used to capture and record e-mail and IM account passwords.

With the risk of repeating ourselves, we want to make it very clear, that our purpose for providing this information is NOT to encourage you to use this information to steal passwords, but rather to inform you of the risks associated with such actions and methodologies. Whatever you choose to do with these information is up to you, and we will not be responsible for any activities you perform.

In this article we will present three techniques:
- Sniffing
- Impersonation
- Keylogger

Sniffing

If two people share the same network, it may be possible for one to sniff the others’ packets as they sign-on. The traffic between your computer and the internet site you are accessing it is possible to be recorded and “played-back.”  It is not a simple technique to perform, but is possible if both computers are close to one another and they are sharing the same a hub. Again, this is illegal and we do not recommend this activity.

Impersonation

It is possible to impersonate a program on a computer by launching an application window that look like something else. For instance, let’s say you login to the MSN service and visit a website (in this case a hostile website). It would be possible for this website to pop-up some application windows that look like something very familiar. They could look almost identical to application windows that an user would expect from his local computer. Thus the user might be tricked into providing or submitting information to the hostile website. If these could trick you into entering your personal information such as user name and password, then you could end-up sending your password to the attacker. Application windows such as these could be created to imitate virtually any program or series of actions. Your browser could identify your operating system and your IP address can be identify by your ISP. In this respect a hostile website could target you with a series of screen shots that look exactly as they should on your system.

The key aspect is that the screen shots are not coming from your computer, but are coming from the hostile website. First, creating such a hostile website is fraudulent and illegal. We do not recommend anyone to perform this activity. To protect yourself against this type of attack, configure your browser for high security and activate warnings for any code that is executed on your computer.

KeyLogger

A KeyLogger is a software program or piece of hardware that records all keyboard keystrokes to an encrypted file which can then be read at a later time. It’s easy to identify the password(s) from the file later. Similar to the Trojan, this technique also requires that someone type the password. There are two main types of KeyLoggers: hardware and software.

A hardware KeyLogger can be installed or mounted between the keyboard cable and the computer and can be activated with a few keystrokes. It is then left in place until after the information you are looking to recover is typed. At a later time the equipment is removed and the file of keystrokes is examined for obtaining the password. Hardware KeyLogger is undetectable by anti-virus software.

Software KeyLogger is installed on the target computer or on your own computer and has the same function, however, it is a little bit more complex to use since it must be installed to run stealthily to be effective. A KeyLogger could be used to steal passwords or information from someone who is using an office computer or sharing a computer. It is possible that installing such a device or piece of software to be illegal depending upon whether the target has a presumption of privacy when using the computer on which the KeyLogger is installed.

In this respect we can recommend you All-Spy KeyLogger or to visit an independent source such as: www.keylogger.org

 


Subscribe to get the latest news on monitoring solutions, spy tools, keyloggers, parental control tools, etc.

Enter your email address:    

Delivered by FeedBurner


You Should Also Check Out This Post:

More Active Posts: