Protect your password in a cyber cafe and on public computers
Results 1 to 11 of 11

Thread: Protect your password in a cyber cafe and on public computers

  1. #1
    Join Date
    Mar 2007
    Posts
    1,900

    Lightbulb

    Sometime you must have gone to a cyber cafe or used public computers to access the internet or mail.

    Public computers are most prone to password hacking. Anyone can simply install a keylogger software to hack your password. Keylogging is one of the most insidious threats to a users personal information. Passwords,credit card numbers,etc.

    It is very easy for the keylogger to harvest passwords. Each and every keystroke (whatever you type on the keyboard) gets recorded in the keylogger software and the person installing it can easily view what you have typed in.

    For example,if you go to hotmail.com and check your mails. Say your ID is [email protected] and password is snoopy2,the keylogger software records your usename and password in its log file as

    [email protected]

    Risky isnt it???!!!

    Theres a solution to this problem and you can easily fool the software!!

    The keylogger software sees and records everything,but it doesnt understand what it sees,it does not know what to do with keys that are typed anywhere other than the password or user name fields.

    So between successive keys of the password if you enter random keys,the keylogger software wont ever come to know where you typed in what..

    In the process of recording the keys,the string that the keylogger receives will contain the password,but embedded in so much random junk that discovering it is infeasible.

    So...

    1. Go to hotmail.com or yahoo.com or any other site where you need to insert a password or PIN.

    2. Type in your user ID.

    3. Type in the first characterof the password.

    4. Click on the address bar in the browser,type in some random charachters.

    5. Again go to password field and type in the second character of the password and probably third too.

    6. Again go to the address bar and type in a few more random characters.

    7. Back to the password field and the next characters of the password.

    Keep on repeating the process till you type in the full password in the password field.

    Instead of the password snoopy2,the keylogger now gets:
    www.hotmail.comspqmlainsdgsosdgfsodgfdpuouuyhdg2

    Heres a total of 26 random characters have been inserted among the 7 characters of the actual password!!!

    No doubt it takes a little bit of more time than the usual process,but you are safe and secure that way!!!

  2. #2
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    The only problem is that if the keylogger on the PC also takes screen shots, you're sunk.

    With all due respect, it is never safe to use a public PC to log into any site that requires a user name or password...

  3. #3
    Join Date
    Mar 2007
    Posts
    1,900
    No i guess your right!

  4. #4
    Join Date
    Dec 2000
    Location
    Dallas, TX USA
    Posts
    2,916
    I would never use a public computer to log on to my (for example) bank. However, I can imagine a situation when I needed mail access enough to risk it. Dude111's technique is worth a try. Even it there is a keylogger and it records screen shots I suspect most hackers wouldn't take the time to figure out what it meant. Much easier to move on to all the users who logged on in the clear.

    Security is never perfect. Weigh the risk against the value of that which we wish to protect.

    And change your password when you get to a (relatively) secure computer.

  5. #5
    Join Date
    Mar 2007
    Posts
    1,900
    Most of them probably wouldnt think that someone would try this anyway i dont think....

  6. #6
    Join Date
    Jul 2009
    Posts
    1
    What is your opinion on http://kyps.net, a service that ensures that you can login without revealing the password?

  7. #7
    Join Date
    Dec 2000
    Location
    Dallas, TX USA
    Posts
    2,916
    I don't see any flaws in the procedure that might reveal passwords to key loggers.

    The question is "Do you trust KYPS?".

  8. #8
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    The question is "Do you trust KYPS?
    I think you know my answer...

  9. #9
    Join Date
    Mar 2007
    Posts
    1,900
    I think you know mine also!!

  10. #10
    Join Date
    Dec 2000
    Location
    Dallas, TX USA
    Posts
    2,916
    Usually I wouldn't trust a web site, even those I recognize (if we can't trust Microsoft, and they have disclosed user info, who can we trust?).

    However, this site appears to be associated with several distinguished researchers in computer science, including Andreas Pashalidis of the University of Essex, UK. If forced to use a public computer I might use KYPS. But I would still change my password ASAP.

  11. #11
    Join Date
    Jul 2001
    Posts
    448
    This basic "fool the keylogger" technique may have worked 15 years ago. Since then, keyloggers now save the window name in addition to the keys typed in, and they also monitor the clipboard. Some take screenshots, or record everything in such a manner that what you were doing can be played back.

    Avoid public computers at all costs, even friends' computers. Some people don't realize how valuable their e-mail account is until it gets raided.
    Hammer owner, will fix computers free of charge.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •