2.2 Implants: Types, Ways of Injection, and Methods of Protection
125
2.2.4 Implant Types
2.2.4.1 Keyloggers
One of the most popular types of implants is represented by keyloggers. Such implants
are aimed at interception of operating system as well as determining their legal
privileges and computer resource access rights.
Keyloggers are not a new thing in the computer world. There were times when
they were developed for OS/370, UNIX, and DOS. Their behavior in a general
case is fairly traditional: a standard keyboard spy by deceit acquires user passwords
and then rewrites these passwords to a location from which the intruder can easily
extract them. The differences between keyboard spies lie only in the method used by
them to intercept user passwords. Accordingly, all keyloggers are divided into three
types—imitators, filters, and proxies.
2.2.4.2 Imitators
Keyloggers of these types use the following algorithm. The intruder embeds a
program module into the operating system, which prompts the user to register in
order to enter the system. After that, the embedded module (imitator) goes in the
standby mode, waiting for the user to enter user identifier and password. After the
user identifies themselves and enters their password, the imitator saves these data to a
location accessible by the intruder. After that, the imitator initiates the logout procedure (which can be done by software means in most cases), and the unsuspecting
user sees another, real invitation to enter the system.
The tricked user, seeing the prompt to enter the password once again, concludes
that they have made a mistake during the previous attempt and obediently repeats
the entire login procedure once again. Some imitators for the purpose of persuasion
display a convincing message about a mistake made by the user. Like this one:
“Incorrect password. Try again”.
Writing an imitator does not require any special skills from the creator. It will
take just several hours for an intruder able to program using one of the universal
programming languages (e.g., BASIC) to do this. The only difficulty that an intruder
might face is the need to find the relevant software function implementing logout
from the system.
Password interception is often facilitated by no other than operating system developers, who do not devote much time to creation of complex registration forms.
Such dismissive attitude is typical for most versions of the UNIX operating system,
in which the registration prompt consists of two text lines, which are displayed
alternately on the terminal screen: login: and password.
You don’t have to be especially bright to fake such invitation. However, complication of the appearance of the prompt does not create any obstacles for the hacker
who decides to inject an imitator into the operating system. To do this, it is necessary
125
2.2.4 Implant Types
2.2.4.1 Keyloggers
One of the most popular types of implants is represented by keyloggers. Such implants
are aimed at interception of operating system as well as determining their legal
privileges and computer resource access rights.
Keyloggers are not a new thing in the computer world. There were times when
they were developed for OS/370, UNIX, and DOS. Their behavior in a general
case is fairly traditional: a standard keyboard spy by deceit acquires user passwords
and then rewrites these passwords to a location from which the intruder can easily
extract them. The differences between keyboard spies lie only in the method used by
them to intercept user passwords. Accordingly, all keyloggers are divided into three
types—imitators, filters, and proxies.
2.2.4.2 Imitators
Keyloggers of these types use the following algorithm. The intruder embeds a
program module into the operating system, which prompts the user to register in
order to enter the system. After that, the embedded module (imitator) goes in the
standby mode, waiting for the user to enter user identifier and password. After the
user identifies themselves and enters their password, the imitator saves these data to a
location accessible by the intruder. After that, the imitator initiates the logout procedure (which can be done by software means in most cases), and the unsuspecting
user sees another, real invitation to enter the system.
The tricked user, seeing the prompt to enter the password once again, concludes
that they have made a mistake during the previous attempt and obediently repeats
the entire login procedure once again. Some imitators for the purpose of persuasion
display a convincing message about a mistake made by the user. Like this one:
“Incorrect password. Try again”.
Writing an imitator does not require any special skills from the creator. It will
take just several hours for an intruder able to program using one of the universal
programming languages (e.g., BASIC) to do this. The only difficulty that an intruder
might face is the need to find the relevant software function implementing logout
from the system.
Password interception is often facilitated by no other than operating system developers, who do not devote much time to creation of complex registration forms.
Such dismissive attitude is typical for most versions of the UNIX operating system,
in which the registration prompt consists of two text lines, which are displayed
alternately on the terminal screen: login: and password.
You don’t have to be especially bright to fake such invitation. However, complication of the appearance of the prompt does not create any obstacles for the hacker
who decides to inject an imitator into the operating system. To do this, it is necessary
