| Account Disabled with 2,011 posts. | | Join Date: Sep 2008 Location: A DUDE WITH ATTITUDE! ALIEN. Experience: Intermediate++ | |
Dear go4saket,
Kindly read this again, because the above post was my creation! 1) Keylogging the keyboard can be done at several levels and for a "good" keylogger ,reading your supposedly"encrypted" keystrokes is child's play!
2)The notion that Virtual keyboards, meaning live, on-screen keyboards are immune, is a computer myth! This brings in the "advanced" keylogger who takes snaps of the mouse movements over the Virtual keyboard and leisurely decrypts them to shovel out all the sensitive data stroked in!
3) Military and the Government are having huge problems, though they have the best in the business security software, which mitigates the prob. to a certain extent!
4) Key logging occurs at various levels, as mentioned above and the most difficult to even detect is the hardware kernel/Driver key logging! A rogue driver is installed and is equal or more difficult to detect ,but an "advanced" user(not me) with a sophisticated anti-Rootkit equipment "may" detect the rogue!Thus, this can be compared to a deep, deep Rootkit infection!
5) The best defense against hardware(Rogue driver) key loggers is preventing them from getting installed, by blocking Driver installations. That's where "HIPS" comes in useful and Limited User Account enabling can help!
6) A Better-Than-Good internet Security Suite is recommended, as key loggers can enter as "malware".
7) lotuseclat79 was advising me a brisk walk to the bank to withdraw the dough required to buy a software ,off the shelf! How true is his advise!
I thank the @O.P, for bringing up this topic as the solution is as of now a "mirage"! This excerpt is culled from a 2009 conference in San Diego on various computer security topics : Safe Passage for Passwords and Other Sensitive Data Jonathan McCune and Adrian Perrig, Carnegie Mellon University; Michael Reiter, University of North Carolina
The prevalence of malware such as keyloggers and screen scrapers has made the prospect of providing sensitive information via web pages disconcerting. We present a system that totally circumvents the legacy input path, thereby excluding the operating system and the entire software stack running thereupon from the TCB for sensitive input, without a VMM. We allow the user to specify strings of input as sensitive, and ensure that these inputs reach the legacy platform already in a protected state. link : http://www.isoc.org/isoc/conferences...uthentication1 "Practice what you preach"is my way! I DO NOT TOTALLY TRUST THE INTERNET FOR FINANCIAL TRANSACTIONS.PERIOD! Since i have nothing to lose, i fly like a butterfly on the net, with KIS2009 , Secunia psi,MBAM, SAS, Scotty(WinPatrol) the doggie, Windows Defender( It's good), Comodo Memory Firewall, FireFox 3.5.1 with the recommended add-ons as the preferred browser, G Zapper, Intelligent (Alien knowhow) and safe browsing (VVVital), Spybot S&D with T-T, Defraggler and an updated HOSTS FILE! Absolute Over-kill! I scan daily with MBAM,SAS (both bought and updated daily), Run Secunia for a fitness certificate, KIS run daily,etc! Finally, the first thing i do with my PC is Cclean the temp. files and run Defraggler on alt. days!  .As of now, i am sorry that there is no Magic bullet to kill the key loggers, especially the "savvy"ones! What A-V and/or Security suite is on your PC?
regards,
perfume( lingers on and on!). Best wishes! |