Showing posts with label Internet Security. Show all posts
In the modern world, Internet has become
a wonderful place to gain knowledge, exchange ideas, share information,
make new friends and whatnot. Even though, you can do all of this by
remaining anonymous behind your monitor, your real life identity and
personal details can still be at the risk of falling into the hands of
strangers. This is where the term “doxing” comes into play!What is Doxing?
Doxing
simply refers to the process of gathering or deducing other people’s
information such as name, age, email, address, telephone number,
photographs etc. using publicly available sources such as the Internet.
In other words, doxing is the act of using the Internet to search for
personal details about a person.
Doxing is done by initially taking a
piece of information (such as “name” or “email address”) and keeping it
as a base to find out other possible details about the person. The term
“doxing” is derived from the word “document tracing” which means to
retrieve documents about a particular person or company in order to
learn more about them.
Doxing Techniques:
Today, Internet has grown to such a size
that it contains almost any information that you’ve ever imagined! All
you’ve to do is use the right techniques to search for what you want.
Here is a list of doxing techniques that are most commonly used by
Internet geeks and ethical hackers:
Using Google:
Google is undoubtedly a powerful tool
that plays a key role in doxing. Since Google indexes almost anything on
the Internet (sometimes even the private information), it is possible
to dox for details such as email ID, address, phone numbers and
photographs of a person or company. Once you obtain the search results
for your query, carefully examine the description part which in most
cases contain the piece of information that you are looking for.
Social Networking Websites:
As most Internet users are found to be
active on social media, social networking sites such as Facebook and
LinkedIn provide a virtual goldmine of information necessary to perform
doxing. As most users are unaware of online security issues, they have
weak privacy settings on their profile. This makes it easy for the
attackers to gain access to personal information such as photographs,
real names, location, job, partner’s name etc.
Reverse Cell Phone LookUp:
A “Reverse Cell Phone Lookup”
is simply a process of finding someone’s personal details such as name,
age, address and related information by using their cell phone number
and vice versa. There are many online services out there such as cell phone registry that provide access to the personal details about a given person based on his/her phone, name and email ID.
Whois Searches:
If a person or company has a website (or
domain name) associated with them, you can easily perform a “whois
search” for their website to obtain personal details such as full name,
address, email and phone number. Just visit whois.domaintools.com
and enter the domain name for which you want to perform a whois search.
It will show up all the details associated with the domain name.
Why Would Anyone Want to Perform Doxing?
Most people perform doxing out of
general curiosity about a person or company. However, there are some
wicked minds out there who do this for the purpose of blackmailing or
taking revenge by exposing the information that they have gathered about
the person.
What are the Consequences of Doxing?
It can be slightly irritating and
embarrassing when private data fall in the hands of people who are not
intended to have access to such information. However, things can go even
worse if the doxed information such as a person’s social activities,
medical history, sexual preference and other vital bits of information
is made public. This can have a serious threat to health, livelihood or
relationship of the victim.
Steps to Protect Yourself from Doxing:
The following are some of the most commonly targeted pieces of information that can be easily obtained through doxing:
- Full name
- Age, gender and date of birth
- Location and place of birth
- Email addresses and username
- Phone number
- Social networking profiles, websites and blogs
So, it is always a good practice to keep
the above bits of information hidden. Even though it is not possible to
do this in all cases, you can still take care to protect as much
information as you can from going public. You can consider the following
additional tips for further protection:
- Do not upload personal photographs on web albums such as “Picasa”. Even if you do, make sure that your album is hidden from public and search engines.
- If you do not intend to show up your profile on search engines, it is a wise choice to make all the Internet profiles private.
- Maximize the privacy settings of your social network profiles. Make sure that your individual albums and photographs have their privacy settings configured.
- Do not use the same email address for all you accounts. Instead, create separate email IDs for individual activities such as gaming, forum participation, banking accounts etc.
Is Doxing a Crime?
Doxing is definitely not a crime when
used within the ethical standards and no harm is being caused to anyone.
However, if doxing is done to cause intentional damage such as
harassment, blackmailing or taking revenge it might well be considered
an offence.
Clickjacking attack allows to perform an action on victim website, Mostly Facebook and Twitter accounts are targetable.When an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the the top level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to other another page, most likely owned by another application, domain, or both. It may be similar to CSRF Cross Site Request Forgeries Attack.
Clickjacking is a term first introduced by Jeremiah Grossman and Robert Hansen in 2008 to describe a technique whereby an attacker tricks a user into performing certain actions on a website by hiding clickable elements inside an invisible iframe.
Using a similar technique, keystrokes can also be hijacked. With a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led to believe they
are typing in the password to their email or bank account, but are instead typing into
an invisible frame controlled by the attacker.
At present this attack mostly use on social network websites like Facebook and twitter, Because this attack is used by convinced victim for click on the link and Social Network website might be very useful for attack on victim.
Code:
<style>
iframe { /* iframe from facebook.com */
width:300px;
height:100px;
position:absolute;
top:0; left:0;
filter:alpha(opacity=50); /* in real life opacity=0 */
opacity:0.5;
}
</style>
<div>Click on the link to get more followers:</div>
<iframe src="/files/tutorial/window/clicktarget.html"></iframe>
<a href="http://www.google.com" target="_blank" style="position:relative;left:20px;z-index:-1">CLICK ME!</a>
<div>You'll be get 10000 followers..!!</div>
Output:
Click on the link to get more followers
Click Me
You'll be get 10000 followers..!!
Download
ClickJacking Tool
For Defence:
Clickjacking Protection
For more information:
OWASP
You can now easily monitor your room,
office or workplace for activities going on during your absence without
having to invest on expensive hidden cameras. If you’ve ever wondered to
find a way to turn your PC webcam into a spy camera, here is a simple
and effective solution. This can be really handy to monitor your
children and pets in home or even catch a cheating spouse red handed!
For this, all you need is a computer with an Internet connection and a
webcam attached to it.
If your computer meets the above simple requirements, then you are all set to go. The site called UGOlog.com
provides a free solution to simply transform your webcam into a
powerful spy camera in just a few steps. You can sign-up for a free
account and start using the service immediately.
Since UGOlog service runs as a web
application from within the browser, there is no need to install any
additional software on your computer. That means, when your spouse or
children look through the installed programs, they don’t find anything
that arouses suspicion.
The following are some of the advantages of using UGOlog service over other software programs or a conventional spy camera:
- Firstly, the service comes for free, so that you don’t need to buy anything to start with.
- Unlike software programs such as “Webcam Monitor” which is complicated to configure and lacks stealth operation, UGOlog needs no installation and is simple to setup.
- UGOlog comes with powerful features such as as motion detection, email alerts, and interval snapshots.
- You have the option to view the camera remotely from anywhere just by logging into your UGOlog account.
Once you’ve created your account, you can take up a quick tour and browse through the configuration guide
to begin using the service. The free version of UGOlog limits the
service for only 1 webcam and 50 MB of storage space. If you wish to
setup more than one camera and need additional space for recording more
videos, you can easily switch for paid plans as per your convenience.
As the use of Internet is increasing, the
chances of your computer getting hacked are also increasing
dramatically. There is plenty of file sharing and web surfing that is
being done, which makes your computer vulnerable for attack. But this
article will help you in deciding what steps to take if your computer
gets hacked.How to Find if Your Computer is Hacked?
It is important to know when your computer has been actually hacked and when it is just behaving weird:
- Sometimes it’s just simple and the hacker may leave some note or warning to prove that your computer is actually hacked.
- You are not able to access your various mails and social media accounts or at worst you are not able to access your computer.
Steps to Take if Your Computer Gets Hacked:
1. Check the Impact of Damage
After using your computer for some time
you would know what type of infection you are facing whether it’s
malware, virus, trojan, keylogger (spyware) or anything else. In case a
keylogger application is installed, you can use a good antispyware
program to remove the infection. However, formatting the hard drive is a
better option if the infection is severe. You should try to back-up all
the important and confidential files that you may have in your computer
before formatting.
2. Damage Control
You should run antivirus programs to determine the extent of damage. Users of Windows OS can run “Malware bytes” which can be found freely and recognises various harmful applications which antivirus cannot. Sophos Mac antivirus is a free application which can be used by Mac users.
3. Removal
After running several scans you will know
what is the extent of damage you are facing. After making the list of
viruses and malware that have infected your computer, next thing you
need to find is what the impact of damage is. For that you must check
the details about those viruses and malware programs to know how they
rank in terms of damages they can have in your computer. You must carry
out the searches from a neutral device which is not hacked and search
for removal tools for those malware programs which have infected your
computer. Unfortunately, if after several tries you are not able to
clean your computer then the only option left is to re-install your
operating system.
4. Offline Hacking
This is true that Internet is the most
common way to hack a computer, but it is possible that anybody can hack
your system using USB devices. The process of removal of the infection
is the same in this case as well. The best precaution you can take to
avoid such situations is to password protect your computer OS and BIOS.
This makes it difficult for anyone to gain access to your computer.
Conclusion:
The best thing that you can do is to
protect your computer by using fully updated antivirus and a good
firewall. It is also wise to have a protection tool for windows
registry. To protect your files, you can use encryption tools so as to
encrypt the data on your hard disk. As there is no 100% foolproof way to
prevent hacking it is always better to take precautionary measures.
Every computer on the Internet has a
unique IP address allotted to it which makes it possible to trace it
back to its exact location. Even though the concept of Internet Protocol
address has been designed for its transparency and traceability, in
some cases this questions the privacy of the Internet user where one
would not like to reveal his/her identity to the outside world.
Well, if you are one such person who is in search of ways to hide your IP address online,
then you are at the right place. In this post, I will discuss some of
the easy and popular ways to mask your IP address so that your identity
and privacy is kept safe.
Why Hide IP Address?
The following are some of the common reasons why people want to mask their IP address online:
- By hiding the IP address, people can browse websites anonymously without leaving the trace of their identity.
- To access websites and portals that are not available to the IP addresse’s their Geo location.
- Stay safe from intruders and hackers by showing a fake IP to the world.
- Hiding IP means hiding geographical location.
- Hiding IP prevents leaving a digital footprint of their online activity.
How to Hide Your IP?
Some of the most common ways to hide IP and safeguard your online identity are discussed below:
1. Using a VPN Proxy – The Safe and Secure Way to Hide Your IP
Using a trusted VPN service is the best
way to hide your IP during your online activities. Here is a list of
most popular and highly reliable VPN services that you can go for:
- VyprVPN: VyprVPN offers the world’s fastest VPN services to its clients and supports wide range of operating systems including Windows, Mac, Android and iOS.
- Hide My Ass VPN: Hide My Ass is one of the most popular and trusted VPN service that allows people to easily conceal their IP address and protect their online privacy.
The following are some of the advantages of using a VPN service over any other method of concealing your IP address:
- In addition to hiding your IP, a VPN service encrypts all your web traffic to keep you safe from hackers and intruders.
- Unlike other IP hiding methods (discussed in the latter part of this article) which affects your speed of browsing, a VPN service keeps your Internet speed fast without affecting its performance.
- You have a long list of countries and states to select from as your place of origin. For example, if you are originally from United Kingdom, you may choose an IP address that belong to United States so that the websites that you visit will see you as from US and not UK.
- By selecting an IP address of your choice, you can easily bypass location blocks and even access restricted websites that are not available for your country.
2. Website Based Proxy Servers
This is another popular way to quickly
mask IP address on the Internet. Since it is a web based service, users
need not have to install any piece of software program on their
computer. The following are some of the popular websites that offer free
services to hide IP address:
The downside of using these free services
to hide your IP address is that most of them become overloaded and are
too slow to use. In addition, some of them will not offer a secured
connection (SSL) and you will often be presented with annoying ads and
pop-ups during the course of your browsing.
3. Browser Configured Proxy Servers
There are hundreds of freely available
open proxies that can be found on the Internet. You can obtain the IP
address of one of those freely available proxy servers and configure
your browser to start hiding your original IP address. However, as they
are openly available to public, most of them are either dead or perform
too slow under normal conditions.
Which Service to Choose?
If you only want to hide your IP address for
a specific amount of time and are not concerned with the performance,
go for the free web based services. On the other hand, if you have the
necessity to hide your IP on a regular basis, need high security and
performance, go for paid VPN services like Hide My Ass or VyprVPN.
For very many people, security is one of
the most important issues when it gets to sending their files into the
cloud. They worry that their files will be seen or even compromised by
other persons because that is what took place in the past. The user
accounts used to be hacked, cloud storage systems failed and personal
files and data were exposed. Therefore, how can you successfully prevent
that from ever happening even when the account gets hacked or something
happens to your provider of cloud storage?The answer to that question is encryption
Encryption can be defined as the process
of making one’s files unreadable with a pass phrase or an encryption key
so that even when another person gains access to the files, it does not
matter because the intruder will only be able to see gibberish. To be
able to see very properly what is in the file, one must have a key.
This article contains the two different
ways through which one can make his or her files secure and be able to
safely use cloud storage without any worries.
Available options
Essentially, when it gets to encrypting files in the cloud, one has two options from which he or she can choose, that is:
- He or she may choose the cloud storage with a built in encryption.
- Make use of a service which encrypts folders and/or files for him or her.
Cloud storage service with built-in encryption
Regardless of your choice, both of the
ways to encrypt data to store in cloud have advantages and
disadvantages. If you decide to go with the dedicated secure cloud
service, you might be required to change the entire setup of
transferring files to that specific service, familiarize yourself with
the way it works and probably give up on a certain third party support,
mainly if you come from the most well-liked cloud storage and syncing
service, that is “Dropbox”. Alternatively, you have got everything under
one hood and you do not have to worry any more about file security and
integrity.
Service for encryption only
If you are using a service which is
dedicated to encrypting your files, you will be having more control over
which files you would like to encrypt and where you would like them to
be stored. For instance, you may choose Dropbox, if at all you like the
service; and not give up after encrypting the files properly.
Conversely, your files might take longer to be properly synced in case
you are getting them encrypted using third party apps.
Conclusion
Either way, it is believed to be very
necessary to protect one’s files using the most proper encryption, most
especially if he or she is using Dropbox for managing his or her
critical files such as contracts, password databases, or any other
personal or business files which may be considered to be very important.
Depending on an individual, some would
like to install another software on their computers just for the purpose
of encryption, while others not. Those who don’t may take advantage of
the idea of signing up for a dedicated cloud solution which has built-in
local encryption for all the files. Some of such solutions available
include SpiderOak, Wuala and Cubby. If online viruses are among the
things troubling you, you may also consider making use of the Norton Contact Phone number so as to inquire about how you can be helped.
There are over 1.3 billion users on Facebook, out of which around 81 Million users are Fake (Fake Facebook profiles).
Somebody creating a Fake profile of yours is not a Big deal for
Facebook unless you represent a law enforcement agency or an Expensive
Legal firm. Most fake Facebook profiles are set-up by adolescents in
relationships seeking to destroy reputation of their ex-partner.Identity theft is common on Facebook, But somebody using your image to harass or play with other people you know, thereby defaming you is really embarrassing and malicious.
While you can always report such imposters profile to Facebook using their Report form, it takes hell lot of time for Facebook to review the profile and disable it. Also Facebook will never disclose to you any details about the fake profile, like when it was created and from which Computer it was operated. Facebook will provide Information regarding fake profile only when there is Police intervention and this is very long process.
Moreover police will not go through the hassle of contacting Facebook and behave like a loyal dogs to track down the imposter unless the matter is very serious. Once you have the IP address of fake profile user, you will then need to get a court-order for the ISP to reveal the information and billing address of the person involved. Remember If the fake profile user had used a proxy server to hide real-IP, it would be very difficult to track down the real IP address.
Here in this post we will show you how exactly you can Find an IP address of a fake Facebook user and even nab the culprit.
Facebook chat runs on XMPP protocol now which is not peer-2-peer, so it is not possible to determine the IP address of the user through Facebook Chat using Netstat command. All we will be doing is use some social engineering skills and default ‘Banner grabbing‘ technique of a web server.
Banner Grabbing is an enumeration technique used to get information about a particular computer system on a network/internet (Information like: Operating system, browser, IP address, etc.)
1. Collect as much information about the fake profile as you can and identify all of the people who are connected to the profile. Make a list of connected people to this account who are your real life friends.
2. Select any one of your close friend or relative on that list (select most trusted person). The person which you have selected will be doing all the job for you. If there is nobody you can trust on this list then ask any of your trusted friend to Befriend this fake profile user.
3. Ask your Friend to start chatting with this fake user casually everyday. (Remember whatever you do should remain between you can your friend. do not let it spread among other close friends)
4. Now Go to http://iptracking.geniushackers.com and fill in your valid email address and enter any name in the ‘Link Name’ field. Click Generate.
5. In the next page you will get a unique link. Just copy this unique link that will look something like this one:
http://iptracking.geniushackers.com/friendship.php?linkid=0gds65g1s2dg169741f32428a9
6. Next goto https://goo.gl and paste your ‘Unique URL’ (that is too long) in the text field and click shorten URL. You will get short URL that will look something like this: http://goo.gl/5HJY2s.
7. Ask your friend to send this shortened URL to the Fake profile user along with some nice message via chat such that he should click on that URL. Example message:
“Hey wassup? i found this really nice story, read here: http://goo.gl/5HJY2s“
Steps for Tracing fake profile user and catching the culprit:
Now that you have found out the IP address of the fake user, its time to know more about this fake user.
9. Goto http://www.iptrackeronline.com and enter the ‘IP address’ of the fake user, click submit query.
10. On the new page, scroll down a bit and you will get to see all the details like ISP, Area-code, Postal-code, etc. regarding his IP address along with a Map.
11. Relate these details with the suspect. If you are not able to suspect anyone then approach your attorney or lawyer, he will file the necessary documents for the ISP to disclose the subscriber details for the IP address.
12. If you are suspecting anyone but not sure if its him then repeat the steps 3 to 8 for this suspect. You can take help of the same friend and ask him to craft some different message accompanied by IP tracking link for this suspect.
13. As soon as your suspect clicks this link, you will have his IP address. Now match his IP address with the IP address of the Fake user. If there is a match, well congrats!! you have successfully nabbed the culprit.
Hope this helps.
How a Domain Name is Hijacked and How to Protect it
Posted by Unknown
Tag :
Hacking,
Internet Security
The act of hacking domain names is commonly known as Domain Hijacking.Domain hijacking is a process by which Internet Domain Names are stolen from its legitimate owners. It is also known as domain theft. Before we can proceed to know how to hijack domain names, it is necessary to understand how the domain names operate and how they get associated with a particular web server (website).
The Operation of a Domain Name is as Follows:
Any website say for example abcd.com consists of two parts. The domain name (abcd.com) and the web hosting server
where the files of the website are actually hosted. In reality, the
domain name and the web hosting server (web server) are two different
parts and hence they must be integrated before a website can operate
successfully. The integration of domain name with the web hosting server
is done as follows:
- After registering a new domain name, we get a control panel where in we can have a full control of the domain.
- From this domain control panel, we point our domain name to the web server where the website’s data (web pages, scripts etc.) are actually hosted.
What Happens When a Domain Name is Hijacked?
To hijack a domain name, you just need to gain
access to the domain control panel and point the domain name to some
other web server other than the original one. So, to hijack a domain you
need not gain access to the target web server.
How the Domain Names are Hijacked?
To hijack a domain name, it is necessary to gain access to the domain control panel of the target domain. For this you need the following ingredients:
- The domain registrar name for the target domain.
- The administrative email address associated with the target domain.
These information can be obtained by accessing the WHOIS data of the target domain. To get access to the WHOIS data, go to whois.domaintools.com, enter the target domain name and click on Lookup. Once the whois data is loaded, scroll down and you’ll see Whois Record. Under this, you’ll get the “Administrative contact email address”.
To get the domain registrar name, look for the words something like: “Registered through:: XYZ Company”. Here XYZ Company is the domain registrar. In case if you do not find this, scroll up and you’ll see ICANN Registrar under the “Registry Data”. In this case, the ICANN registrar is the actual domain registrar.
The administrative email address
associated with the domain is the backdoor to hijack the domain name. It
is the key to unlock the domain control panel. So, to take full control
of the domain, the hacker will have to hack the administrative email
associated with it. Email hacking has been discussed in my earlier post:
How to hack an email account.
Once the hacker takes full control of this email account, he will visit the domain registrar’s website and click on forgot password in the login page. There, he will be asked to enter either the domain name or the administrative email address
to initiate the password reset process. Once this is done, all the
details to reset the password will be sent to the administrative email
address.
Since the hacker has the access to this
email account, he can easily reset the password of domain control panel.
After resetting the password, he logs into the control panel with the
new password and from there he can hijack the domain within minutes.
How to Protect the Domain Name from Getting Hijacked?
The best way to protect the domain name
is to protect the administrative email account associated with the
domain. If you loose this email account, you loose your domain. You can
read my earlier post on how to protect your email account from being hacked. Another best way to protect your domain is to go for a private domain registration.
When you register a domain name using
the private registration option, all your personal details such as your
name, address, phone and administrative email address are hidden from
the public.
Whenever a hacker performs a WHOIS
lookup for your domain name, he will not be able to find your name,
phone or the administrative email address. Thus, the private
registration provides an extra security and protects your privacy. Even
though it costs a few extra bucks, is really is worth for its
advantages.
The tips provided in this post not only
applies to your email account, but can also be used to protect any other
online account such as your bank logins, Paypal or your social
networking account.
Today, it is a common problem for many
Internet users to have their email accounts compromised by hackers. But
this arises one BIG question in my mind!
“Is it so easy to hack an email account? OR Is it so difficult for people to protect their email account from getting hacked?”.
The single answer to these two questions is “Absolutely NOT!“. It is neither easy to hack an email nor difficult to protect an email account from being hacked.
If this is the case, then what is the reason for many people to lose their accounts?
The answer is very simple. They do not
know how to protect themselves from getting hacked! In fact, most of the
people who lose their online accounts to hackers are not the victims of
hacking but the victims of trapping. They get hacked
not because they are hacked by some expert hackers, but because they are
fooled to such an extent that they themselves give away their password.
Now I will mention some of the most common pitfalls by which people often fall victims and get their accounts compromised. In addition to this, I will also give information on how to avoid these pitfalls and stay protected.
1. Website Spoofing (Phishing Scam)
Website spoofing, also known as phishing
is the act of creating a fake website with the intention of misleading
the visitors. The website will be created by a different person or
organization (other than the original) especially for the purpose of
cheating. Normally, the website will adopt the design of the target
website and sometimes has a similar URL.
For example a spoofed website
of Yahoo.com appears exactly same as Yahoo Website. So, most people
would believe this as the original site and lose their passwords. The
main intention of spoofed websites is to fool users and take away their
login details. For this, the spoofed sites offer fake login pages.
These fake login pages resemble the original login pages of sites like
Yahoo, Gmail or Facebook. Since they resemble the original login page,
people believe that it is true and give away their login details to the
hackers by trying to login to their accounts.
Solution:
- Never try to login/access your online account from the sites other than the original site.
- Always type the URL of the site in the address bar to get into the site. Do not click on a hyperlink to enter the site.
2. By using Keylogger (Spyware)
The other commonly used method to steal
password is by using a Keylogger. A Keylogger is nothing but a spyware.
The detailed description of keylogger and its usage is discussed in the
post How to Use Keyloggers.
If you read this post you’ll come to know that it is too easy to steal
the password using a keylogger program. If you just access your account
from a computer installed with keylogger, you definitely lose your
password. This is because the keylogger records each and every keystroke
that you type on the computer’s keyboard.
Solution:
Protecting yourselves from a keylogger scam is very easy. Just install a
good anti-spyware program and update it regularly. This keeps your PC
secure from a keylogger. For more information, you may read my other
post on How to Protect your Computer from keyloggers?
3. Accessing your Email from a Public Place
Do you access your email from public
places like cyber cafes? If so, you are definitely under the risk of
losing your password. In fact, many people lose their email account in
cyber cafes. For the owner of the cyber cafe, it is just a cakewalk to
steal your password. For this, all he need to do is install a keylogger
program on his computers. So, when you login to your email account from
this PC, you give away your password to the cafe owner. Also, there are
many Remote Administration Tools (RATs) which can be used to monitor
your browsing activities in real time.
This doesn’t mean that you should never
use cyber cafes for surfing the Internet. I know, not all the cyber cafe
owners will be so wicked. However, it is recommended not to use public
places for accessing confidential information. If it comes to the matter
of security never trust anyone, not even your friend.
Keyloggers have been a major problem
today as it does not require any prior knowledge of computers to use it.
So, it is often used by hackers to steal passwords, credit card numbers
and other confidential data from your computer. Below are some methods
through which you can protect your computer from keyloggers:1. Use a Good Antivirus
This is the first and the basic step
that you need to take in order to protect your computer from keyloggers
and other online threats. Use a good antivirus such as Kaspersky,
Norton or McAfee and update it regularly.
2. Use a Good Antispyware
If you are a frequent Internet user,
then you could be exposed to a number of spywares on a regular
basis. Since keylogger is basically a spyware, it is better to install a
good antispyware program. Make sure that the antivirus and the
antispyware you use do not conflict with each other.
3. Antilogger can be Handy
Antiloggers are the programs that detect
the presence of keyloggers on a given computer. Over the past few
years, I have tested a lot of anti-logging programs and have found Zemana Antilogger as the best one.
Normally, a keylogger can easily be
detected by a good antivirus program, but hackers may use some methods
such as hexing, binding or crypting to make it harder for the antivirus
program to detect it. In this case, Zemana Antilogger comes handy as
this program is specially designed to protect your PC against harmful
keyloggers.
4. Online Scanning
When ever you receive a suspicious file, you scan it with online scanners such as Multi engine antivirus scanner
which scans your file with 24 popular antivirus engines and reports it
back to you if the file is recognized as a virus or spyware. This
ensures that none of the malicious programs can escape from being
detected as there are 24 different antivirus engines involved in the
scanning process.
5. Use Sandboxie
Sandboxie
is another great program to help you protect your computer against
harmful keyloggers and spywares. Sandboxie runs your computer in an
isolated space which prevents your program from making permanent changes
to other programs in your computer.
When ever you receive a file that looks
suspicious, just run the program with Sandboxie so that, you can test it
without the risk of making permanent changes to your computer.
To run a program in Sandboxie, follow the steps as mentioned below:
-
Open the Sandboxie tool and click on sandbox menu on the top.
-
Now go to Default sandbox.
-
Then click on run any program.
-
Now select the file you wish to run in sandboxie and click open.
6. Keyscrambler
Keyscrambler
is one of the best program that offers protection against
keyloggers. It is a small program which encrypts your keystrokes so
that, even if your computer has a keylogger installed on it, only the
encrypted keystrokes are captured by the keylogger and not the actual
ones.
The free version of Keyscrambler
currently supports Firefox, IE and a few other applications. However its
premium version supports more than 160 applications.



