Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Exploits-HackingTools
[Top] [All Lists]

[REVS] Biologger - A Biometric Keylogger

Subject: [REVS] Biologger - A Biometric Keylogger
Date: 9 Sep 2007 18:07:15 +0200
The following security advisory is sent to the securiteam mailing list, and can 
be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  Biologger - A Biometric Keylogger
------------------------------------------------------------------------


SUMMARY

In the paper linked in the end IRM realized a proof-of-concept 
implementation of a biometric keylogger, or "Biologger". While 
conventional keyloggers are typically used to obtain passwords or 
encryption keys to circumvent specific security measures, IRM's Biologger 
will aim to capture biometric-related data between a biometric device and 
other processing units, to be used and exploited in a number potential 
attack vectors against the biometric system, such as manipulation of 
biometric data and control signals, as per traditional man-in-the middle 
attacks.

DETAILS

Conclusion:
The aim of this whitepaper is not to discourage the use of biometric 
access control systems, but to encourage security by design with such 
products and their deployments, and to highlight the possibilities open to 
attackers or malicious employees with no more than the ability to 
intercept traffic between such device s and other processing units. 
Biometric device manufactures and system integrators cannot rely on 
security though obscurity alone for the overall security of their devices 
and systems. Deployment of biometric access control system within existing 
infrastructures such as IP networks should involve careful identification 
of the network traffic routing and the accessibility to biometric-related 
data on those networks. Without adequate protection of the 
confidentiality, integrity and availability of biometric access control 
devices and their data, the threat of "Biologging" activities within those 
enterprises employing such access control is real.


ADDITIONAL INFORMATION

The information has been provided by  <mailto:andy.davis@irmplc.com> Andy 
Davis.
The original article can be found at:  
<http://www.irmplc.com/index.php/69-Whitepapers> 
http://www.irmplc.com/index.php/69-Whitepapers



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: 
list-unsubscribe@securiteam.com 
In order to subscribe to the mailing list, simply forward this email to: 
list-subscribe@securiteam.com 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any 
kind. 
In no event shall we be liable for any damages whatsoever including direct, 
indirect, incidental, consequential, loss of business profits or special 
damages. 




<Prev in Thread] Current Thread [Next in Thread>
  • [REVS] Biologger - A Biometric Keylogger, SecuriTeam <=