top_left top_right
bottom_left
Next Event: Unknown | Forum Rules | QGL Website | Event Registration
openFolder AusForums.com
iconwatfolderLineopenFolder LANs
iconwatfolderLineopenFolder QGL
iconwatfolderLineopenFolder QGL Forum
Author
Topic: Keyloggers.
pARODY
Posts: 339
Location: Brisbane, Queensland
Had a great email thread today at work about keyloggers and the last 24hours has had a massive surge in new delivery methods. I've personally seen and captured old Gumblar infectors now delivering keyloggers for games instead of just their usual botnet drops.

The most fun delivery method we've seen is a vulnerability in QuickTime's MS DirectShow implementation (CVE-2009-1537). Bundle that with Xvid having a bug that could be used against users (http://www.xvid.org/)


Basic version, update your PDF reader, all of them I've seen have various ways of being exploited. Update xvid and update your Windows for the DirectShow bug.

Not much AV coverage for the keylogger though. :(

Update your stuff and watch out for .PDF files and .SWF files from suspect sites.
system
--
infi
Posts: 12551
Location: Brisbane, Queensland
hmm interesting info.
Spook
Posts: 25335
Location: Brisbane, Queensland
i thought keyloggers all came from wow forums
reload!
Posts: 4638
Location: Brisbane, Queensland
and guitars
Obes
Posts: 7686
Location: Brisbane, Queensland
i thought keyloggers all came from wow forums

You'd be wrong.

Usually cross site scripting exploits inside adverts on totally legit sites.
reload!
Posts: 4639
Location: Brisbane, Queensland
whoa whoa whoa WHOA

stop the f***ing presses.

did obes just get trolled?
JakeG
Posts: 624
Location: Brisbane, Queensland
Back in the day my gunbound account got keylogged.. :< (used to play at infernolan).
pARODY
Posts: 346
Location: Brisbane, Queensland

Bumping this.

Avertlabs did some research on some of the new keyloggers out there and its packed with comedy gold. 2 different keyloggers seen in the wild at present have changed their return delivery method from email to SQL directly to a DB in brazil/china. Stupid malware coders left the credentials to post into the DB in the code.

http://www.avertlabs.com/research/blog/index.php/2009/06/22/more-password-theft-shenanigans/
euphoria
Posts: 1247
Location: Gold Coast, Queensland
lol
Hashy
Posts: 269
Location:
You'd be wrong.

Usually cross site scripting exploits inside adverts on totally legit sites.
Nice straight-faced, pretentious reply to a joke bro.
paveway
Posts: 9939
Location: Brisbane, Queensland
haha reload
system
--
Not a new post since your last visit.
New Post Since your last visit
Back To Forum
Advertise with Us | Privacy Policy | Contact Us
© Copyright 2001-2026 AusGamers Pty Ltd. ACN 093 772 242.
Hosted by Mammoth Networks - Australian VPS Hosting
Web development by Mammoth Media.