Penetration Testing Tip #22: Keystroke loggers and spy software / hardware

Hits: Failed to execute CGI : Win32 Error Code = 3


As part of a penetration testing, there is a time and place for keystroke loggers. As part of a security or audit teams, you may need keyloggers should someone be suspected of illegal or inappropriate use of company resources. Parents sometimes place these on home machines to "monitor" what their underage children surf or email. Spouses also snoop on spooses.

My focus is supporting network and PC admins. Be aware that this exists. Physical security is appropriate for workstations with confidential info. Consider reviewing how secure your CEO, CIO, legal officer, owner, .. PC really is. Could anyone walk up after hours and install one of these jewels? What about the hardware versions that only require physical access?

If there is a site that should be listed here or if a link goes dead, .