My laptop got infected last week by some key logging program. Fortunately, my I.T. savvy mate got rid of it, however, it was on my computer for (I'm guessing) about 4 days before I realised it was there. I changed the passwords of poker and bank account but how exactly do they work? Would someone know what sites I go on and what passwords I was using as I was typing them? Or would my sites/passwords be stored somewhere for some **** to look at in say a few days time?.....? Like I said, I changed my passwords, but that was on a different pc/network and about 4 days later.
Keyloggers work using the same method I've mentioned in other threads on here whereby you intercept the data being passed to Windows API functions.
A very basic keylogger would store nothing but keystrokes, but more likely, they would store what applications or websites you had focused at the time of the keystrokes.
There are various ways to transfer the data from an infected machine to the keylogger owner. Assume they have succeeded.
Keyloggers work using the same method I've mentioned in other threads on here whereby you intercept the data being passed to Windows API functions.A very basic keylogger would store nothing but keystrokes, but more likely, they would store what appli
Let your bank and poker site know, you might be able to get new login details, which makes the information the keylogger has even less useful than it is now.
BlufDaddy 17 Jan 16:08 Dibble, do you get laid much?
Thinly disguised bluff wants to check out dibbles' back door?
Let your bank and poker site know, you might be able to get new login details, which makes the information the keylogger has even less useful than it is now.BlufDaddy 17 Jan 16:08 Dibble, do you get laid much?Thinly disguised bluff wants to che
My defence against phishing websites (ones that pretend to be from your bank/paypal etc asking for log in details) is to fill in the forms with genuine looking made up names and account numbers.
I like to imagine the Nigerian faces lighting up when they get what looks like a genuine reply and then the realisation after several attempts to log in that they have been done!
I think everyone should send back false details - imagine getting a million replies with false info on!
My defence against phishing websites (ones that pretend to be from your bank/paypal etc asking for log in details) is to fill in the forms with genuine looking made up names and account numbers.I like to imagine the Nigerian faces lighting up when th
There's a good story in there and I am told by a few sources who know more about this sort of thing that it's real.
Have you read this site about scambaiting?http://www.419eater.com/There's a good story in there and I am told by a few sources who know more about this sort of thing that it's real.
With scambaiting, you're assuming they manually try to login to each account they've successfully phished.
I'm conjecturing here but I think it's likely the scammers would have a script that automates login attempts to the real bank with phished details and discards those that fail. That's how I would do it, assuming the real bank doesn't have an obfuscated text entry field (those fields you see on websites where it says enter the text you see in this box, where the text has been distorted).
With scambaiting, you're assuming they manually try to login to each account they've successfully phished. I'm conjecturing here but I think it's likely the scammers would have a script that automates login attempts to the real bank with phished det
Still, at least would tie up their software in that case. Plus I think most banks would have more than a simple password/username, so difficult to do automatically.
Still, at least would tie up their software in that case. Plus I think most banks would have more than a simple password/username, so difficult to do automatically.
It would only tie up the software for just a few seconds until the authentication request fails.
As I mentioned, obfuscated text input defeats scripting.
It would only tie up the software for just a few seconds until the authentication request fails.As I mentioned, obfuscated text input defeats scripting.
Use Spyware Doctor (with anti-virus included) all the time - you have to buy it but it pretty much kicks ass and stops anything.
Spyware doctor is free if you download the Google pack (type Google pack in Google!) and only tick the one box to prevent the rest of their crap.
I would also recommend malewarebytes.
Then run ccleaner and tidy up that registry!
stu 17 Jan 17:06 Use Spyware Doctor (with anti-virus included) all the time - you have to buy it but it pretty much kicks ass and stops anything. Spyware doctor is free if you download the Google pack (type Google pack in Google!) and only tick the
Giving the scammers false account numbers would cause them to leave traces of their activity when they tried to open the account. Whether anyone makes use of these to identify and block them is another matter. What doing this will almost certainly do is verify your email address to the spammers who sent you the message in the first place and possibly also your ip address. This is not information you really should be giving away.
Giving the scammers false account numbers would cause them to leave traces of their activity when they tried to open the account. Whether anyone makes use of these to identify and block them is another matter. What doing this will almost certainly
Giving the scammers false account numbers would cause them to leave traces of their activity when they tried to open the account. Whether anyone makes use of these to identify and block them is another matter.
Nah, they're more likely to attempt logins through compromised machines rather than their own.
What doing this will almost certainly do is verify your email address to the spammers who sent you the message in the first place and possibly also your ip address. This is not information you really should be giving away.
If your machine is secure, then there's really not much danger in someone having your IP address. Besides, most home users have a sticky dynamic IP address so their IP will change from time to time anyway.
You only really need a static IP address if you're planning to host a web server, or for security reasons with 3rd parties eg some of my clients host sensitive data that I can only access with my username&password if I attempt to login from a pre-specified IP address.
I have an RSA SecurID token for one bank account which is a great way to prevent unauthorised withdrawals. It generates a random 6 digit number every 60 seconds which is required to make a withdrawal.
"M" 18 Jan 20:18 Giving the scammers false account numbers would cause them to leave traces of their activity when they tried to open the account. Whether anyone makes use of these to identify and block them is another matter. Nah, they're more like
BlufDaddy 18 Jan 16:58 Would probably take about an extra 2 hours to write the code to handle that.
Surely lot more difficult though - plus I never have to select an entire password/code, just different combinations of parts of it.
BlufDaddy 18 Jan 16:58 Would probably take about an extra 2 hours to write the code to handle that. Surely lot more difficult though - plus I never have to select an entire password/code, just different combinations of parts of it.
Controlling the mouse in a way that is indistinguishable from a real human is pretty straightforward.
Scraping the HTML to find out what character numbers from the password are being asked for is also straightforward. Once you've logged in enough times, they'll have your password.
They might even have it the very first time you log in if, like virtually all net users, you use the same password for every different site you visit. Just check the characters you entered against known complete passwords you've entered for other sites and if they're the same, the chances are you're using the same password.
Controlling the mouse in a way that is indistinguishable from a real human is pretty straightforward. Scraping the HTML to find out what character numbers from the password are being asked for is also straightforward. Once you've logged in enough t
Some good points - just out of interest Bluf, what do you think of using packages like SD, would stop the keyloggers before they get to you, or do you think it misses much? From personal experience I've found it very thorough.
Some good points - just out of interest Bluf, what do you think of using packages like SD, would stop the keyloggers before they get to you, or do you think it misses much? From personal experience I've found it very thorough.
I've not actually used Spyware Doctor but what it probably does is scan for the methods commonly associated with dodgy software such as rootkits and API hooking. There are some legitimate uses of these techniques so they probably also have some smart filtering to make sure it doesn't flag safe programs. Based on that, I would think SD (or something comparable) is software worth having.
For me, the concern is more about losing work if my machine has been compromised so regular backups are essential.
I've not actually used Spyware Doctor but what it probably does is scan for the methods commonly associated with dodgy software such as rootkits and API hooking. There are some legitimate uses of these techniques so they probably also have some smar
I have an RSA SecurID token for one bank account which is a great way to prevent unauthorised withdrawals. It generates a random 6 digit number every 60 seconds which is required to make a withdrawal.
This type of security is now available for full tilt, 5000 points for a piece of hardware, or 3000 for mobile phone application.
I still would not be comfortable giving anyone who scams people for a living any more information than I needed to, which for me is none.
I have an RSA SecurID token for one bank account which is a great way to prevent unauthorised withdrawals. It generates a random 6 digit number every 60 seconds which is required to make a withdrawal.This type of security is now available for full ti