DISCLAIMER: I AM NOT A SECURITY EXPERT, NOR DO I CLAIM ANY INFORMATION HERE IS CORRECT. THIS BLOG IS FOR MY OWN PERSONAL AMUSMENT AND APPOLIGIZE IN ADVANCE THAT YOU READ IT EVERY DAY. THEREFORE, USE THE INFORMATION AT YOUR OWN RISK.
There is a new hot topic in the world of WoW. It’s called Keyloggers. It’s all over everywhere to defend yourself, check your computer, do something! Make sure your account is safe! What the hell does all this mean? How exactly do I do that?
Let’s start with what it is.
SearchSecurity.com defines a keylogger as:
A keylogger, sometimes called a keystroke logger, key logger, or system monitor, is a hardware device or small program that monitors each keystroke a user types on a specific computer's keyboard.
It goes on to state:
A keylogger program does not require physical access to the user's computer. It can be downloaded on purpose by someone who wants to monitor activity on a particular computer or it can be downloaded unwittingly as spyware and executed as part of a rootkit or remote administration (RAT) Trojan horse. A keylogger program typically consists of two files that get installed in the same directory: a dynamic link library (DLL) file (which does all the recording) and an executable file (.EXE) that installs the DLL file and triggers it to work. The keylogger program records each keystroke the user types and uploads the information over the Internet periodically to whoever installed the program.
Ok, now we know what it is, what the hell do we do about it? There are a number of things you can do to make sure you are as safe as you can get:
Monitoring what programs are running
A user should constantly observe the programs which are installed on his or her machine. Also, devices connected to PS/2 and USB ports (which have both been hacked) can be used to secretly install a keylogger and then remove it (along with the user's data) by the perpetrator.
Anti-spyware
Anti-spyware applications are able to detect many keyloggers and cleanse them. Responsible vendors of monitoring software support detection by anti-spyware programs, thus preventing abuse of the softwares.
Firewall
Enabling a firewall does not stop keyloggers per se, but can possibly prevent transmission of the logged material over the net if properly configured.
Network monitors
Network monitors (also known as reverse-firewalls) can be used to alert the user whenever an application attempts to make a network connection. This gives the user the chance to prevent the keylogger from "phoning home" with his or her typed information.
Automatic form filler programs
Automatic form-filling programs can prevent keylogging entirely by not using the keyboard at all. Form fillers are primarily designed for web browsers to fill in checkout pages and log users into their accounts. Once the user's account and credit card information has been entered into the program, it will be automatically entered into forms without ever using the keyboard or clipboard, thereby reducing the possibility that private data is being recorded. (Someone with access to browser internals and/or memory can often still get to this information; if SSL is not used, network sniffers and proxy tools can easily be used to obtain private information too.)
It is important to generate passwords in a fashion that is invisible to keyloggers and screenshot utilities. Using a browser integrated form filler and password generator that does not just pop up a password on the screen is therefore key. Programs that do this can generate and fill passwords without ever using the keyboard or clipboard.
On-screen keyboards
Program-to-program (non-web) keyboards
It is sometimes said that a third-party (or first party) on-screen keyboard program is a good way to combat keyloggers, as it only requires clicks of the mouse. However, this is not true, because for most on screen keyboards (such as the onscreen keyboard that comes with Microsoft Windows XP), a keyboard event message must be sent to the external target program to type text. Every software keylogger can log the text sent as typed characters from one program to another with an on-screen keyboard, and additionally, some programs also record or take snapshots of what is displayed on the screen. (Screenshot recorders are a concern whenever entire passwords are displayed; fast recorders are generally required to capture a sequence of virtual key presses.)
Drag & Drop
Most keyloggers cannot intercept texts which are drag & dropped from one window to another. With the help of this technique, sensitive data could be transferred, for example, from a password manager to the target application.
Several of the articles I have read this morning go on to state that if you aren’t using the keyboard, there is no record for the keylogger to record. Therefore in theory, (see the disclaimer at top before doing this), you can put your information into a text file, then just copy and paste it into the fields. The problem with this is it would appear that any program that does a screen shot in addition to logging keys will still pick up on that.
The easiest way to avoid keyloggers is to never click links on a web site unless you know the site. For instance, I do not guarantee any link posted here, although I have visited every link listed so if they are infected we are both screwed.
I hope this helps some of you decide how to protect yourselves against this threat to our fun.
References:
Wikipedia
SearchSecurity.com
Labels: General Wow, Keylogger, Life