Security Basics mailing list archives

Re: Key Loggers


From: "Rense Buijen" <Rense () dct-mail com>
Date: Sat, 25 Oct 2003 13:44:58 +0200

Hello,

To follow what the process is doing try: strace -f -p <PID>

Greetings,

Rense

-----Original Message-----
From: Ivan Hernandez [mailto:ivan.hernandez () globalsis com ar] 
Sent: vrijdag 24 oktober 2003 21:56
To: s7726 () yahoo com
Cc: Security-Basics
Subject: [despammed] Re: Key Loggers

s7726 wrote:

Is there a way to determine if a running process is logging keys? Can
you
say look at whether or not it is implementing hooks or something? I am
interested to know if someone has put a key logger on a few machines.


Thank you


S7726 at yahoo dot com
 


I would first (in doubt) disconnect the machine from the network and 
start analysing the traffic, then search for any changing file each time

you press a key !
also writing a strange word and searching for it can be useful sometimes
ivan hernandez


------------------------------------------------------------------------
---
Visual & Easy-to-use are not words that you think of when talking about 
network analyzers. Are you sick of the three window text decodes?
Download ClearSight Network's Analyzer and see a new network analysis
tool that 
makes the complex - easy
http://www.securityfocus.com/sponsor/ClearSightNetworks_security-basics_
031021
------------------------------------------------------------------------
----


----------------------------------------------
Filtered by despammed.com.  Tracer: RAA003681067035995
Remember: you can forward any spam that slips through the filters
to the abuse desk here at Despammed.


---------------------------------------------------------------------------
Visual & Easy-to-use are not words that you think of when talking about
network analyzers. Are you sick of the three window text decodes? Download ClearSight Network's Analyzer and see a new 
network analysis tool that
makes the complex - easy
http://www.securityfocus.com/sponsor/ClearSightNetworks_security-basics_031021
----------------------------------------------------------------------------


Current thread: