Security Basics mailing list archives

Re: Nessus/keyloggers


From: shawnmer <shawnmer () io com>
Date: Fri, 8 Aug 2003 18:11:19 -0500 (CDT)

Hi,

Keyghost might fit the bill for the keylogging part <http://www.keyghost.com>. 
For a scan tool, check out trinux <http://trinux.sf.net> or Knoppix-std 
<http://www.knoppix-std.org>.

Thanks,

-scm


nn:netsec novice

nn>I would like to demonstrate the importance of physical security to 
nn>management by presenting information I was able to easily obtain by 
nn>accessing one of our 'publically' available PCs residing on our private 
nn>network.  What I had in mind was to run a keylogger and perhaps nessus from 
nn>a machine for a short period of time and present the output.  I pictured 
nn>installing a keylogger and a reconaissance type tool on a thumbdrive - leave 
nn>it there for a period of days and then retrieve.  Does anyone have 
nn>suggestions on a keylogger or nessus type tool that could be easily 
nn>installed on portable media that could then be carried away for analysis?  I 
nn>want to provide as realistic scenario as possible.  IE - someone leaves a 
nn>thumb drive attached for a day for keylogger or someone walks in and powers 
nn>the PC off and then boots of a Linux based CD to run a scan and then easily 
nn>collects data?
nn>
nn>Thanks for any ideas!!
nn>
nn>_________________________________________________________________
nn>Add photos to your e-mail with MSN 8. Get 2 months FREE*.  
nn>http://join.msn.com/?page=features/featuredemail
nn>
nn>
nn>---------------------------------------------------------------------------
nn>----------------------------------------------------------------------------
nn>


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: