LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-04-2011, 08:47 AM   #1
Var
LQ Newbie
 
Registered: Jun 2011
Posts: 6

Rep: Reputation: Disabled
How to detect keylogger etc


Hello,

In my job, I have to deal with a fairly psychopathic and untrustworthy person who is unfortunately the company's computer security expert, who is also an admitted hacker. I recently installed Slackware to prevent him from spying on my basic activities, deleting my windows and moving my mouse pointer, as he did when I had Windows on my PC. However I now need to make sure he isn't going to do the same with my Slackware installation. Other than reinstalling Slackware periodically, what can I do to detect spyware like a keylogger, or to detect that he has rootkitted commonly used parts of the distro to provide a backdoor etc?

BTW I've never considered encrypted a hard drive but now that I'm dealing with this idiot I would be open to that.

Thanks.
 
Old 06-04-2011, 09:05 AM   #2
Alien Bob
Slackware Contributor
 
Registered: Sep 2005
Location: Eindhoven, The Netherlands
Distribution: Slackware
Posts: 8,559

Rep: Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106
If he is deleting your windows and moving your mouse pointer without your consent, he is harrassing you at work and you can report him to his superiors for that. I am slightly amazed that you have not yet done so.

A "company security expert"? Sounds more like a 15 year old.

If you do not give him root access to your Slackware computer it will be hard for him to hack into it. If he has physical access to your computer (when you are out of the office) then it will be a lot easier for him to install rootkits and keyloggers. In that case, encrypt your hard drive. You may want to put the unencrypted /boot partition on an external USB stick or else he may find ways around the encryption by adding spyware to the initrd.

Eric
 
1 members found this post helpful.
Old 06-04-2011, 09:06 AM   #3
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
It is difficult if he has physical access to the machine, so yes encrypting the drive would be a very good idea to prevent a keylogger in the first place. I would also use a BIOS or boot password to prevent him from messing things up there, or booting other disks.

If you can't do that, you can use rkhunter, chkrootkit, and clamav to detect rootkits, viruses, malware, etc ... assuming he doesn't mess with them.

Personally, I would catch him on video and report him to the authorities, because this is not legal.
 
1 members found this post helpful.
Old 06-04-2011, 09:29 AM   #4
the3dfxdude
Member
 
Registered: May 2007
Posts: 730

Rep: Reputation: 358Reputation: 358Reputation: 358Reputation: 358
Also install a pad lock on your machine in addition to everything else.
 
Old 06-04-2011, 09:31 AM   #5
Var
LQ Newbie
 
Registered: Jun 2011
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by Alien Bob View Post
If he is deleting your windows and moving your mouse pointer without your consent, he is harrassing you at work and you can report him to his superiors for that. I am slightly amazed that you have not yet done so.
Oh, I've already complained about him for other reasons. He is a macho homophobe tough-guy type from Eastern Europe. My supervisors, who are immigrants to the US from the same country, acted like nothing was wrong and then made a point of showing me what good friends they are with him. This is a guy who has been physically intimidating toward me beginning in the 1st week of work but he is a glad-hander so everyone likes him.

Quote:
A "company security expert"? Sounds more like a 15 year old.
He's in his 20's. I told him he's stuck in adolescence and he eagerly agreed.
 
Old 06-04-2011, 09:35 AM   #6
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
I know what you mean, and I might even know what country it is ... but I won't say.
 
Old 06-04-2011, 09:37 AM   #7
Var
LQ Newbie
 
Registered: Jun 2011
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by H_TeXMeX_H View Post
I know what you mean, and I might even know what country it is ... but I won't say.
It's near the Balkans. But their macho types haven't massacred anyone lately.

Last edited by Var; 06-04-2011 at 09:44 AM.
 
Old 06-04-2011, 10:02 AM   #8
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Also, watch out for these things, just in case:
http://en.wikipedia.org/wiki/Hardware_keylogger
 
Old 06-04-2011, 10:16 AM   #9
Alien Bob
Slackware Contributor
 
Registered: Sep 2005
Location: Eindhoven, The Netherlands
Distribution: Slackware
Posts: 8,559

Rep: Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106Reputation: 8106
Quote:
Originally Posted by Var View Post
Oh, I've already complained about him for other reasons. He is a macho homophobe tough-guy type from Eastern Europe. My supervisors, who are immigrants to the US from the same country, acted like nothing was wrong and then made a point of showing me what good friends they are with him. This is a guy who has been physically intimidating toward me beginning in the 1st week of work but he is a glad-hander so everyone likes him
If you're in the US, then nothing can stop you from going over their heads and file a harrassment claim with the local authorities. Especially if your superiors are "in the same bed" with that guy so to speak.

Eric
 
Old 06-04-2011, 10:18 AM   #10
the3dfxdude
Member
 
Registered: May 2007
Posts: 730

Rep: Reputation: 358Reputation: 358Reputation: 358Reputation: 358
After reading that wiki page, H_TeXMeX_H suggested, it might be better to take your keyboard and mouse with you.

Edit: Just to be clear, the reason why I say this is that it would be way too easy to disassemble those and install the keylogger on the inside.

Last edited by the3dfxdude; 06-04-2011 at 10:40 AM.
 
Old 06-04-2011, 10:27 AM   #11
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
If he was a former hacker (or is one now) it very hard to cover all possibilities if he has physical access. It might be worth it to go over their heads like mentioned before.

If you can't here's a list of what I would do:

Encrypt HDD.
Put BIOS password, and boot ONLY from HDD.
Use strong passwords for all your passwords.
Check for hardware keylogger BEFORE booting (will steal all your passwords).
Don't use anything wireless, especially keyboard (can be hacked).
Have a case with a lock on it (I do).
NEVER leave your computer running with you away from it, ALWAYS do a cold shutdown before leaving it out of your sight.
Install and use a firewall, rkhunter, chkrootkit, clamav, etc.

Last edited by H_TeXMeX_H; 06-04-2011 at 10:30 AM.
 
Old 06-04-2011, 10:40 AM   #12
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,225

Rep: Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320
If the guy had remote access software on your Windows machine and kept interfering with your work, then he had created a hostile work environment and you should have started looking for another job. If your response was to switch operating systems and he didn't notice or care, then your company's security expert was an incompetent idiot and you should have started looking for another job.

Last edited by dugan; 06-04-2011 at 10:45 AM.
 
Old 06-04-2011, 10:49 AM   #13
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Quote:
Originally Posted by dugan View Post
If the guy had remote access software on your Windows machine and kept interfering with your work, then he had created a hostile work environment and you should have started looking for another job. If your response was to switch operating systems and he didn't notice or care, then your company's security expert was an incompetent idiot and you should have started looking for another job.
Yeah, but remember that jobs are harder to find now.
 
Old 06-04-2011, 11:08 AM   #14
dugan
LQ Guru
 
Registered: Nov 2003
Location: Canada
Distribution: distro hopper
Posts: 11,225

Rep: Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320Reputation: 5320
Quote:
Originally Posted by H_TeXMeX_H View Post
Yeah, but remember that jobs are harder to find now.
Which is why he should start looking immediately.
 
Old 06-04-2011, 11:18 AM   #15
Var
LQ Newbie
 
Registered: Jun 2011
Posts: 6

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by dugan View Post
If your response was to switch operating systems and he didn't notice or care, then your company's security expert was an incompetent idiot and you should have started looking for another job.
He noticed immediately. He began looking over the cubicle divider to see what I was doing the moment that I shut Windows down. When I rebooted from the Slackware64 install DVD he became even more interested, but didn't say anything. Since then he has done a lot of a-hem coughing when I'm around. But I agree, I'd have to be crazy to not be looking for a new job.

Last edited by Var; 06-04-2011 at 12:29 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
keylogger? |2ainman Linux - Security 4 08-21-2013 03:48 AM
Keylogger for Linux kirtan Linux - Software 2 12-21-2010 01:51 AM
lkl Keylogger kirtan Linux - Software 2 12-18-2010 04:51 AM
about keylogger abrenar Linux - Security 3 02-24-2009 03:26 AM
Possible keylogger? StefaX Linux - Security 3 01-27-2009 05:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 02:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration