5 ms·
a few questions I'm wondering about, if anyone can help: - how do those PW stealers work? are they similar to the Steam one, where it'd delete existing creds a
by nchelluri 10y ago
a few questions I'm wondering about, if anyone can help:
- how do those PW stealers work? are they similar to the Steam one, where it'd delete existing creds and then sniff newly entered ones?
- can this thing detect certain apps like FileZilla and then say "user entered <FTP site creds>" and send individual fields, and is that what is meant by supporting say FTP and FileZilla?
- what does PHP support mean? maybe looks for common stuff like php.ini, various other conf files like FPM, and tries to find DB/cache connection creds?
there's one other thing I'm wondering about, which is the light/easily crackable encryption of the keylogger's internals, and I vaguely remember reading about Google's encryption on the new recaptcha and people talking about all this stuff like complicated encryption routines baked into the client side JS that I really didn't understand except at a handwavy level, and wonder if that's the kind of thing some, say, intelligence/espionage outfit could use.
very interesting/engaging (fun) article, all in all, for me. and I appreciated the understatement of the (well-deserved) plug at the end.
- jacquesm 10y agoKeyloggers simply record all key presses so if you delete the credentials for a game and someone then tries to run that game the first thing you catch is the credentials to log in again. The most obvious way is to hook the message stream from the window manager to the applications, windows provides some convenient hooks for this.
- nchelluri 10y agoas for the first point, yup, I understood that from the article; I probably should have used "similar to Steam" rather than "like Steam". I mostly meant, you'd get a long stream of characters and you'd have to manually try to dejumble them. Whereas, I believe if you go by your second point, you can see "Ok, the user put username <x> in the username textfield, password <y> in the password field, address <a> in the address textfield, port <p> in the port textfield" and so on, which would make for a more structured data dump. Maybe not possible or feasible for every single application, but if you could get the highest usage targets, like the most common FTP clients, or Steam as they have apparently done, and the browser password storage stuff (or fields for say, most common banking sites, PayPal, etc.) then you could save yourself a lot of time.
- dylz 10y agoMost of them usually show specifics, the keylog file is often less of a jumble and more of like: {TAB}{TAB}{CURRENT WINDOW: Steam - Log in}{TAB}username{LEFTCLICK}password{LEFTCLICK}{CURRENT WINDOW CHANGED: Steam: Home}
- nchelluri 10y agoThat's not terrible. It would be fairly easy, almost trivial, to write a Perl/Ruby/... script to capture a large chunk of useful credentials.
- ufmace 10y ago> can this thing detect certain apps like FileZilla and then say "user entered <FTP site creds>" and send individual fields, and is that what is meant by supporting say FTP and FileZilla? Could well be. I haven't messed with Win32 in a while, but I'm pretty sure that you can sniff the contents of other applications' windows and dialogs. With a little work, you should be able to take a common app and work out how to detect it's login windows, find the username and password and other relevant fields, and pull out the contents. I know if I was writing a hostile keylogger, I'd go to a lot of trouble to know exactly what was entered where, instead of having to see a long stream of keyboard input and figure out what the usernames and passwords are, and what services they go with.
- sb8244 10y agoWinspy++ offered the ability to look at the content of password fields in native applications IIRC. It's been a few years since I've done anything on Windows.
- sidarape 10y ago> - can this thing detect certain apps like FileZilla and then say "user entered <FTP site creds>" and send individual fields, and is that what is meant by supporting say FTP and FileZilla? FileZilla simply use a file in your personnal directory to store passwords exactly like your browser too.
- huj123 10y agoSteam used to have password crackers out there, not sure about now