Javascript Keylogger Test

Discussion in 'other anti-malware software' started by CloneRanger, Aug 22, 2011.

Thread Status:
Not open for further replies.
  1. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    It's always a pleasure reading your sharp thoughts about software, m00nbl00d! I'll add you as a friend, as you seem to be as interested as I am in security!
     
  2. gambla

    gambla Registered Member

    Joined:
    Sep 4, 2007
    Posts:
    166
    Location:
    Frankfurt, Germany
    I'm pretty sure that Chrome would block all of these KLs too. So i fully trust NoScript for FF, but i always see it as only one security layer.
     
  3. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Without NoScript: fail
    With NoScript and site allowed: fail
    With NoScript and site blocked: pass

    Whether the lauching of the executable or internet connection of the executable is blocked by the software does not matter for the test. The keylogging is done by the javascript, and would then normally be sent to an attacker, however it is sent to an internal IP adress and the executable is just a local server receiving the sent keystrokes.

    Also, I'm not sure if the keylogger is compatible with all browsers and versions, it doesn't seem to work on some, and I don't think that is because of protection from the browser. The keylogger is already a year old after all.
     
  4. Ibrad

    Ibrad Registered Member

    Joined:
    Dec 8, 2009
    Posts:
    1,972
    A majority of the AV labs are not detecting the file.
     
  5. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    That is what I had expected, thanks
     
  6. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Thanks guys for testing so far :thumb: Still a few possible Anti-KL's missing that could be tested though, if you get the chance :) I only wish i had been able to as well :(

    Interesting that many AV/AM's are still failing to notice it after over a year :D I guess it "might" be due that www etc being way off their radar :p But the main purpose of this test is not their detection etc, but rather if Anti-KL's intercept & block it etc :)

    Quite revealing how different browsers are able to handle it, or not !
     
  7. Scoobs72

    Scoobs72 Registered Member

    Joined:
    Jul 16, 2007
    Posts:
    1,113
    Location:
    Sofa (left side)
    Both Spyshelter and Zemana fail on Win7 x64 - not a peep out of either of them. I couldn't get the keylogger to run on XP or Vista x86. However, I'm not at all convinced that this keylogger has any similarities to the approaches used by real malware, hence the failure to detect/prevent it by most applications. Because of its 'local server' approach it appears to be hooking Winsock dll's rather than the approach of Zeus-type malware of hooking Wininet.dll for outbound http communication. Hence the reason neither Spyshelter or Zemana would detect or block it.
     
  8. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    very true
     
  9. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Thanks for the new test tool.
     
  10. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It doesn,t run on my system. :mad:
     
  11. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    To be fair, OA has all the power to handle it correctly, but I'm not sure that the current development team is able to gain from that power :(
     
  12. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Interesting, especially as SS is "supposed" to be x64 compatable !

    :thumb:

    Nor mine or a few others :(
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.