156
2 Computer Viruses, Malicious Logic, and Spyware
events, respectively. A hook can be installed for a given stream or for all system
streams. Hooks for all system streams are very convenient for designing a keylogger.
Code of the hook event handler needs to be located in DLL. This requirement is
due to the fact that the DLL with hook event handler is projected by the system into
the address space of all GUI processes. An interesting feature is the fact that DLL
mapping is performed not at the moment of installation of the hook, but when the
GUI process receives the first message that corresponds to the hook parameters.
The attached CD contains the demo version of a hook-based keylogger. It records
keyboard input in all GUI applications and duplicates the input text in its window.
This example can be used to test anti-keylogger programs.
The hook method is fairly simple and effective but has a number of disadvantages.
The first disadvantage is the fact that DLL with the hook is projected to the address
space of all GUI processes, which can be used to detect the keylogger. Moreover,
registration of keyboard events is only possible for GUI applications; this can be
easily checked using a demo program.
2.4.2.2 Keyboard Input Tracking with the Help of Keyboard Polling
This method is based on periodic polling of the keyboard state. Polling of state of
keys in the system is provided by the special function GetKeyboardState returning
an array of 255 bytes, in which each byte contains the state of a certain key. This
method does not require introduction of DLL into GUI processes; as a result, such
keylogger is more difficult to find.
However, status of a key changes at the moment when the stream reads keyboard
messages from its queue; as a result, this method is only applicable for tracking of
GUI applications. This disadvantage is not found in the function GetAsyncKeyState,
which returns the status of the key as of the moment of polling.
The attached CD contains the demo version of a cyclic keyboard polling-based
keylogger—application KD2.
The disadvantage of keyloggers of this type is the necessity of periodic polling of
the current keyboard state with a fairly high rate of at least 10–20 polls per second.
2.4.2.3 Keyboard Input Tracking with the Help of Interception of API
Functions
This method hasn’t gained much popularity; however, it can be successfully used to
design keyloggers. The methods of interception of API functions are detailed in the
article dedicated to rootkits. The difference between a rootkit and a keylogger in this
case is not great—a keylogger will intercept functions for the purpose of monitoring
instead of modifying operating principles and call results.
The simplest way can be interception of functions GetMessage, PeekMessage, and
TranslateMessage of the User32 library, which will allow monitoring of all messages
received by GUI applications.
Précédent

- 177/839

Suivant