OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Levi Ruiz (lruizPNICORP.COM)
Date: Wed Apr 04 2001 - 17:11:42 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Well, to combine this with another idea on the list of using a
    seperate, identical receiver, hookup a keyghost to the receiver,
    provide power through the keyboard connector (use a PS with decent
    amperage, I would do 1A to make sure the receiver and keyghost get
    the current they need) on the keyghost to power bith it and the
    logitech receiver, then have it key up with the keybaord and record
    away. Every couple days or so you could download the keyghost info
    and then put it back.

    Not only would this be small, it is portable as well so you could
    move it around to different workstations if you wanted to gather data
    from multiple places. This should bypass any encryption (if it even
    exists) due to the fact that the receiver would decrypt it before it
    sent it to the computer

    - -----Original Message-----
    From: Erik Tayler [mailto:erikDIGITALOFFENSE.NET]
    Sent: Monday, April 02, 2001 2:15 PM
    To: VULN-DEVSECURITYFOCUS.COM
    Subject: Re: wireless keyboards

    First. This really doesn't have anything to do with the original
    topic, but that's ok. I would just like to put my card in the pile,
    as I am impressed with the KeyGhost [www.keyghost.com]. A co-
    worker of mine bought one, and it is a quality product. A way to
    possibly incorporate the KeyGhost into this conversation... Let me
    give an example.

    Someone is using a Logitech which uses an "advanced digital
    technology" -Logitech ... Could one still use a KeyGhost in that
    manner, placing the dongle upstream of the receiver? Not really an
    important topic, just somewhat interesting.

    Erik Tayler
    Security Analyst
    Digital Defense Incorporated
    http://www.digitaldefense.net

    Blake Frantz wrote:
    >
    > While not trying to sound like commercial. I have used the
    > keyghost standard version and thus far am very impressed with its
    > size and
    > functionality. You can also get the log digestion application that
    > attempts to extract login information
    > "something<tab>something<enter>" and URLs. Just my two cents.
    >
    > Blake
    >
    > =================================================================
    > The Government, like diapers, should be replaced regularly, and
    > often for the same reasons.
    >
    > On Mon, 2 Apr 2001, Carl Douglas wrote:
    >
    > > ---------------------- Forwarded by Carl Douglas/CIMG/CVG on
    > > 04/02/2001 05:22 PM ---------------------------
    > >
    > >
    > > Carl Douglas
    > > 04/02/2001 05:22 PM
    > >
    > > To: percivalNS1.DEVNULL.NL
    > > cc:
    > > Subject: Re: wireless keyboards (Document link: Database 'Carl
    > > Douglas',
    > > View '($Sent)')
    > >
    > > see: http://www.keyghost.com
    > >
    > >
    > >
    > >
    > > percivalNS1.DEVNULL.NL on 04/02/2001 02:15:44 PM
    > >
    > > Please respond to percivalNS1.DEVNULL.NL
    > >
    > > To: VULN-DEVSECURITYFOCUS.COM
    > > cc: (bcc: Carl Douglas/CIMG/CVG)
    > > Subject: wireless keyboards
    > >
    > >
    > >
    > > Subject: wireless keyboards
    > > I was wondering, is it possible to sniff keystrokes on wireless
    > > keyboards and such? How do we approach?
    > >
    > > Just trying to raise a discussion :-)
    > >
    > > Taylan
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > > --
    > >
    > > NOTICE: The information contained in this electronic mail
    > > transmission is intended by Convergys Corporation for the use of
    > > the named individual or entity to which it is directed and may
    > > contain information that is privileged or otherwise confidential.
    > > If you have received this electronic mail transmission in error,
    > > please delete it from your system without copying or forwarding
    > > it, and notify the sender of the error by reply email or by
    > > telephone (collect), so that the sender's address records can be
    > > corrected.
    > >

    -----BEGIN PGP SIGNATURE-----
    Version: PGP 7.0.1

    iQA/AwUBOsudKcbgHXR4hb1iEQIOgACfddgywqveUGSB8EcF84CIDTTEKi0AnjwJ
    SEHf89ExRANmWT6/FReJGYX/
    =7IQs
    -----END PGP SIGNATURE-----