Key Loggers are software or hardware tools which are used to capture the user’s keystrokes from keyboard. It is sometimes used by the companies to measure the productivity of an employee in a clerical work. However, they pose more of a threat than benefits.
Keyloggers are easily available in the market and can be used by a malicious party to spy on the computer usage of others and stealing users private data.
How to avoid falling to prey to the keyloggers ?
When you are on the Internet, you can never be 100% sure of your security not being compromised. But, here are a few tips to avoid becoming an easy prey to the crackers.
1) Always try to avoid accessing your online accounts from public cybercafes.
2) Do not allow anyone else to use your personal computer and always keep your computer locked and protected with a password.
3) Do not visit malicious sites and do not install random software's which can be insecure.
4) Install a good Antivirus software on your computer
5) Always scan a removal storage device(like floppy, Flash drive etc) for possible virus infections before starting to access content from it.
6) Do not use a simple password. Your password should be long and should contain letters, alphabets and special characters.
7) Try not to use dictionary words in your password. It will make the cracker's job easy.
How to confuse key loggers
Here, we discuss on how to confuse the key logger by making it log some gibberish data instead of our valid password. But please note that this is not 100% full proof concept. In fact, nothing is foolproof on the Internet. We only aim to make it harder for the cracker.
Types of Key Loggers
Two types of key loggers are prevalent in the market:- Software and Hardware key loggers.
1) Hardware key loggers are much easier to detect. They are mostly attached between the keyboard and the CPU. A manual inspection should be enough in most of the cases.
2) Software key loggers on the other hand are much more complex and hence difficult to deal with. Most of them record keystrokes, mouse events, clipboard activity etc. So the best option will be to scramble the keystrokes smartly.
How to tackle the software key loggers ?
Let’s say we have to enter a password ‘pass’.
1. Bring the focus on the password box, type any random alphabets. Now, Select the randomly entered alphabets with the mouse and type P. So we have entered the first letter of the password.
2. Again click on the password box and type a random key. Select the last two letters with your mouse and type the next valid key of your password. Delete the other randomly entered alphabets.
In this case we managed to enter 2 unwanted characters as against one in the first step.
Continue in a similar way to finish typing the password. You can choose any number of random characters between your password.
So, now if we look at the output of the key logger, it will log something like this:
[click]2[click]p[click]uty[click]g[click]a[click]hgf[click] s[click]er[click]"[click]s
Another cool trick would be to enter the password in a reverse manner, that is, entering the alphabet "s" first. Then bringing the mouse focus to the starting and entering the 3rd alphabet and so on. In fact, you can type the alphabets of your password in a random order..
This method can be used for entering the user name too, since most banks have account numbers as the user id. Also, if required, you can take use the same for typing a URL, so that the key logger does not recognize the website you are visiting.
Another way is utilizing the browser’s search bar or address bar to camouflage the password.
For example, Click the password box and type a letter of the password. Now click the browser’s address bar or search bar and type some unwanted letters. Alternate between the password box and address/search bar till you finish. The result will be the same as the former method.
How to find the hardware key loggers ?
Hardware key loggers are easy to detect. They are hardware devices , which are attached between the keyboard and cpu port. If you are suspicious about them, you just have to take a look on the back side of the cpu cabinet and see if something is attached between the keyboard and the cpu port. The gif image will give you a better idea.
Here is another image which shows the before and after affect of the harware keyboard logger.

Please feel free to comment on this article and present more ideas on avoiding this menace. Last update : 12-10-2007 10:09
|
|
|