* Tool captures user login information on public workstations
endif; ?>PUBLISHER’S NOTE: Please note that, as of 9/29/03, all of your valued Network World Fusion newsletters will be delivered to you from nwfnews.com. If you use filters to manage your newsletters based on domain name, please adjust accordingly.
Lisa Napoli recently wrote an interesting summary in The New York Times of a computer crime involving public workstations that were compromised using keystroke loggers.
Apparently a computer criminal named Juju Jiang installed keystroke-logging software (Invisible KeyLogger Stealth) on public Internet terminals at Kinko’s shops in Manhattan, gathered user IDs and passwords from unknowing users of those terminals, and used those to break into their computers and Internet-related accounts for nefarious purposes. After he was arrested in December and confessed to his crimes, he was released on bail and immediately continued his criminal activity. He pleaded guilty in July to “five counts of computer fraud and software piracy” and is awaiting sentencing:
https://www.nytimes.com/2003/08/07/technology/circuits/07kink.html
The problem of unauthorized software on public terminals is as old as remote access. One of the first pranks/crimes perpetrated on mainframe systems when remote access was enabled in the 1960s was the classic keystroke-logging logon Trojan. A criminal hacker would write (or just run) a simple program that simulated the logoff message and the initial dialogue of a logon; the victim, thinking that he or she was interacting with the operating system, would dutifully enter user ID and password, only to be informed that there had been a problem. Entering the user ID and password again would log the user on uneventfully. Alert users noticed that a logoff message flashed briefly on screen before being erased; this clue led to the discovery that in fact the initial logon had been recorded by the Trojan in a disk file that could be retrieved by the malefactor later.
The Invisible KeyLogger Stealth for Windows 2000/XP is a particularly powerful tool for capturing keystrokes. Amecisco’s description includes this chilling passage:
“In addition to a flexible and friendly keystroke log viewer, IKS is extremely configurable. We provide an easy-to-use install utility. You can rename the program file, and specify the name and the path of the log file. You only need to copy one file onto the target computer for the logging to take place. There is almost no way for the program to be discovered once the program file and the log file are renamed by the install utility. An exhaustive hard drive search won’t turn up anything. And the running process won’t show up anywhere.”
You can understand why the Kinko’s administrators did not notice the keylogger.
In my next column, I’ll look at how one can protect public workstations to reduce the damage caused by unauthorized access and unauthorized software.




