Thứ Tư, 7 tháng 10, 2009

Virtual keyboard to secure your online transaction

Do you think hackers cannot capture your username & password which you use to access your online banking easily?

Think again, once your pc has been infected with trojan or worm with capability to capture your keystrokes then you would be most probably sending your financial data to the crooks.

Five types of keylogger software program that can capture your keystrokes.

  1. Hypervisor based. It's is malware operating system that work underneath your operating system.
  2. Kernel based. It resides at the kernel level of the os, very hard to write and combat. It has permission to access to any information typed on the keyboard.
  3. Hook based. It is triggered by keyboard events which the os notifies it and the keylogger just record the keystrokes.
  4. Passive methods. This is done by using APIs like GetAsyncKeyState(), GetForegroundWindow(), etc. to poll the state of the keyboard or to subscribe to keyboard events. Slows your pc.
  5. Form Grabber based. It logs web form submissions by recording the web browsing onSubmit event functions. Data is recorded before submission over the internet and bypasses https encryption.


Money is the Main Reason

The main reason cyber criminals target this information is for money.

Interesting email conversation between two hackers, Farid Essebar (codename : Diabl0 ) and Atilla Ekici (codename : Coder )

"They can't find me," wrote Atilla Ekici, a 23-year-old Turk, in an email to his accomplice, a 19-year-old Moroccan called Farid Essebar. "Ha, ha, ha," replied Mr. Essebar. Source : Cassell Bryan-Low, The Wall Street Journal

Zotob virus / trojan enables other malicious software to be installed. For example, it enables malicious key logging programs to record credit card information.

Police found about 1600 the numbers of stolen credit cards with them.


Virtual KeyBoard

To protect your information next time when you access your paypal account or bank account is to use virtual keyboard provided by anti-virus software.

I am using Kaspersky Internet Security 2009 and it has this feature to protect us from this kind of malicious program.

Virtual keyboard is a special service embedded into Kaspersky Internet Security 2009 that prevents data interception entered from the keyboard.


To use Kaspersky Virtual keyboard.

  1. Open your Kaspersky Internet Security Program.
  2. Click Online Security
  3. Click Virtual KeyBoard.


Now, you can enter your username and password safely in the login the form of your bank website.

Please remember that virtual keyboard cannot protect your data if you are entering your data to phishing sites or has been hacked.

Please check the authenticity of the website before entering your username and password to the website. For details on checking ssl certificate, please click here.

Prevention is better than Cure !




Không có nhận xét nào:

Đăng nhận xét