Re: Password Protection

From: tito.basa (mochafrap_at_mix.ph)
Date: 09/27/04

  • Next message: Craig Searle: "Red Hat & Oracle hardening"
    Date: Mon, 27 Sep 2004 14:53:49 +0800
    To: demon@designer.bg
    
    

    Michael wrote:

    >Hi,
    >
    >I'm keeping a watch on the List for short time. And I have a
    >question : What are the techniques to protect a password from being
    >keylogged without any Anti-Keylogging Software.
    >
    >I thought of virtual keyboards, and other non-keyboard techniques but
    >modern keyloggers can take screenshots too. So It's useless.
    >
    >
    hmmm...my usual headache are those keyloggers installed on public
    Internet cafes here...
    i had an internal developer make a site for us to use an on-screen keyboard
    without mouse clicks. Effective against 'keyloggers' taking screenshots of
    every mouse click but not against people watching your back :)

    but a combination of keyboard and the on-screen one does the trick
    aside from anti-keylogger software installed.
    Best way is to educate our clients on how to avoid keyloggers installed
    in the first place.

    :)


  • Next message: Craig Searle: "Red Hat & Oracle hardening"

    Relevant Pages

    • Password Protection
      ... I'm keeping a watch on the List for short time. ... What are the techniques to protect a password from being ... modern keyloggers can take screenshots too. ...
      (Security-Basics)
    • Re: [Full-disclosure] Defeating Citi-Bank Virtual Keyboard Protection
      ... > spyware application that records a section of screen in the immediate ... manually (or maybe use the same techniques as for getting around ... keyloggers would move in a direction similar to Internet Explorer BHOs, ... It doesn't directly target virtual keyboards so ...
      (Full-Disclosure)
    • keyloggers
      ... In MS windows there is "On-Screen Keyboard" or virtual keyboard. ... is there any software that can detect keyloggers? ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)
    • Re: randomizing keyboard input
      ... It might slow down non-hardware keyloggers. ... So if I capture a few paragraphs of keystrokes it should be fairly easy to determine the correct letter exchanges. ... What you need is keyboard that encrypts the keystrokes and then software reversed it. ...
      (Pen-Test)
    • Re: randomizing keyboard input
      ... framework the randomizes the keyboard input. ... keylayout on boot, then find a way to decrypt this for an applications. ... were trying to find a way past keyloggers. ...
      (Pen-Test)