LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Slackware (https://www.linuxquestions.org/questions/slackware-14/)
-   -   How to detect keylogger etc (https://www.linuxquestions.org/questions/slackware-14/how-to-detect-keylogger-etc-884504/)

Knightron 06-06-2011 04:58 AM

Um, i'm not a hacker or hacker expert, lol, but the impression i got was that hackers don't normally go about boasting their abilities to everyone and anyone? Are you sure this guy just didn't know one or a couple of common known vulnerability and used them to exploit your machine; if this is the case, then it won't take long for the problems to stop, now you've taken even this little bit of action.

Martinus2u 06-06-2011 07:57 AM

There is already sufficient advice in this thread. Just one more aspect: since obviously there is no relationship of trust between you and your employer you should use the time while they pay you to find alternative employment. I am unfamiliar with US law, but over here the actions of the "security expert" are subject to criminal law. Ie. once reported to the police the crown prosecutor or state attorney will take matters into his hands. In order to make them hit as hard as possible you need to collect unrefutable evidence. Good luck.

narz 06-07-2011 06:38 AM

What work are you in if you don't mind my asking. Based on what you described, your workplace sounds shady and run by thugs.

narz 06-07-2011 06:51 AM

Quote:

Originally Posted by tallship (Post 4376607)
#2.) I'm a homophobe too, yet many of my very best friends swing the other way.

hmm...how are you homophobic if many of your very best friends are gay? Either I don't know what homophobia is or that makes no sense.

H_TeXMeX_H 06-07-2011 07:13 AM

http://dictionary.reference.com/browse/homophobe
"a person who fears or hates homosexuals and homosexuality."

So it is fear or hate, just to make it more confusing.

What I don't like is them flaunting their homosexuality just because they can, in all these gay parades and s***. Honestly, I don't care what they do in their rooms, but to flaunt it like that is sick, IMO. I can't say I hate them, but I don't like being around them. There is also the increased chance of spreading STDs.

You know I think this thread has gone off topic and has run its course. I hope someone closes it.

tallship 06-07-2011 08:04 AM

Quote:

Originally Posted by narz (Post 4378697)
Either I don't know what homophobia is

yeah this threads run it's course alright.

FYI, I have a very real fear with regards to members of my own gender who have sexual designs for me.

That is homophobia and there's nothing wrong with being the way I am.

I choose my friends based on issues of merit, trust, mutual respect for each other's feelings, and other ethical and moral issues - not their gender preferences.

If your intent was to mock me, then let me ask you this:

Do I laugh at you because you barf at the site of an elevator? Answer: NO.

Nuff said.

Gerard Lally 06-07-2011 08:41 AM

Quote:

Originally Posted by Var (Post 4376111)
Hello,

In my job, I have to deal with a fairly psychopathic and untrustworthy person who is unfortunately the company's computer security expert, who is also an admitted hacker.

Without hackers there would be no Slackware for you and probably no internet either.

Quote:

I recently installed Slackware to prevent him from spying on my basic activities, deleting my windows and moving my mouse pointer, as he did when I had Windows on my PC.
You call it spying; how do you know he's not just doing his job? I look after a couple of small- to medium-sized businesses and part of my brief is to ensure the users don't bring malicious software into the network deliberately or inadvertently. This occasionally involves a quick check-up via remote access - the permission of the employer is taken for granted and the employees understand, rightly or wrongly, that the expertise of the network admin - i.e., me - is likely to be greater than their own expertise, so they leave me to it. Anyone changing the operating system on a PC belonging to the business would in all likelihood be sacked straight away.

Quote:

However I now need to make sure he isn't going to do the same with my Slackware installation. Other than reinstalling Slackware periodically, what can I do to detect spyware like a keylogger, or to detect that he has rootkitted commonly used parts of the distro to provide a backdoor etc?
Not a lot. Malicious software is always ahead of the curve. Unless you're a security expert who dedicates his time to malicious software research you won't be able to cover all angles. In my opinion the best security is provided by a default install of operating systems like NetBSD and OpenBSD. BSD Magazine ran an article on OpenBSD desktops in the enterprise recently, but I very much doubt if your company would go along with it.

quickercarter 08-20-2013 03:14 AM

Quote:

Originally Posted by H_TeXMeX_H (Post 4376119)
It is difficult if he has physical access to the machine, so yes encrypting the drive would be a very good idea to prevent a Myjad keylogger in the first place. I would also use a BIOS or boot password to prevent him from messing things up there, or booting other disks.

If you can't do that, you can use rkhunter, chkrootkit, and clamav to detect rootkits, viruses, malware, etc ... assuming he doesn't mess with them.

Personally, I would catch him on video and report him to the authorities, because this is not legal.

Most people thing of keyloggers as malicious software, but don't forget about hardware keyloggers that can be plugged into a USB port. Obviously these are easy to detect on a laptop, but on a desktop they could potentially go unnoticed for months.

Beyond checking to make sure nothing unwanted is plugged in, you can choose from a number of free software options that detect keyloggers. Two of the better free choices, although pay versions are available for both are Zemana and SpyShelter.

GazL 08-20-2013 03:44 AM

I don't know you, and I've never heard of either of those, but as a general observation: downloading and running an executable that some anonymous and unknown person on a forum recommends to you will make you more likely to install a keylogger than detect one.


Anyway, this is a 2 year dead topic and thread-necromancy is generally discouraged here at LQ, Please don't revive old threads.


All times are GMT -5. The time now is 03:12 PM.