Click here to get back home

detecting keyloogers

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
detecting keyloogers Altria 06-13-2005
Posted by Altria on June 13, 2005, 1:20 pm
Please log in for more thread options
Hello All,
I have a public environment and usually when i troubleshoot the area I log
onto local ws as Administrator. Is there a way of telling if keyloggers have
been installed on workstations? How do I know that my administrator account
for the local ws is not being compromised?

TIA,
Altria




Posted by Durby Groy on June 14, 2005, 4:35 pm
Please log in for more thread options
Install Microsoft Free AntiSpyware and do a scan ?


> Hello All,
> I have a public environment and usually when i troubleshoot the area I log
> onto local ws as Administrator. Is there a way of telling if keyloggers
> have been installed on workstations? How do I know that my administrator
> account for the local ws is not being compromised?
>
> TIA,
> Altria
>




Posted by Mark Gamache on June 15, 2005, 11:51 am
Please log in for more thread options
if they are your machines and you are the administrator, the only way to be
sure is to lock the machines down yourself. This includes BIOS passwords so
that users can't boot from CDs etc. Physical access is a huge risk. Then
the OD must be locked down. Depending on the environment, you may want to
create software restriction policies. Strong AV and such are important too.
Assuming that no one is given administrator privileges, a properly
configured workstation will stay clean. There is no single tool or trick to
make sure you are safe. Defense in depth....

If any machine is suspected in the least, wipe it. You can boot from a
Linux or winXPE CD and get data off. That way you know the OS is clean.

Cheers,

--
Mark Gamache
Certified Security Solutions
http://www.css-security.com



> Hello All,
> I have a public environment and usually when i troubleshoot the area I log
> onto local ws as Administrator. Is there a way of telling if keyloggers
> have been installed on workstations? How do I know that my administrator
> account for the local ws is not being compromised?
>
> TIA,
> Altria
>




Posted by S. Pidgorny on June 19, 2005, 9:30 pm
Please log in for more thread options
Some vendors os SSL VPN do claim that they'll detect keyloggers - but they
require admin rights to inspect and still I find those claims hard to
believe. And, in a hostile environment you might have hardware key loggers
inside the system case!

I hvent checked yet but attaching own keyboard (usb/bluetooth) might be a
good option, as most key loggers don't pick up secondary keyboards while
running

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> if they are your machines and you are the administrator, the only way to
be
> sure is to lock the machines down yourself. This includes BIOS passwords
so
> that users can't boot from CDs etc. Physical access is a huge risk. Then
> the OD must be locked down. Depending on the environment, you may want to
> create software restriction policies. Strong AV and such are important
too.
> Assuming that no one is given administrator privileges, a properly
> configured workstation will stay clean. There is no single tool or trick
to
> make sure you are safe. Defense in depth....
>
> If any machine is suspected in the least, wipe it. You can boot from a
> Linux or winXPE CD and get data off. That way you know the OS is clean.
>
> Cheers,
>
> --
> Mark Gamache
> Certified Security Solutions
> http://www.css-security.com
>
>
>
> > Hello All,
> > I have a public environment and usually when i troubleshoot the area I
log
> > onto local ws as Administrator. Is there a way of telling if keyloggers
> > have been installed on workstations? How do I know that my administrator
> > account for the local ws is not being compromised?
> >
> > TIA,
> > Altria
> >
>
>




Posted by Altria on June 23, 2005, 9:30 am
Please log in for more thread options
Thanks guys for your reply......
I realize security is mighty depth but I am hoping that I would be able to
get some insight from the veterans.

Thanks again,
Altria
> Hello All,
> I have a public environment and usually when i troubleshoot the area I log
> onto local ws as Administrator. Is there a way of telling if keyloggers
> have been installed on workstations? How do I know that my administrator
> account for the local ws is not being compromised?
>
> TIA,
> Altria
>




Similar ThreadsPosted
Software to dectect Keyloogers, etc. May 15, 2008, 3:00 pm
detecting lame passwords February 12, 2008, 11:55 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap