ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    HP Laptops Found with Keylogger Built Into Audio Driver

    Scheduled Pinned Locked Moved News
    hplaptopsecuritykeyloggerbleeping computer
    64 Posts 16 Posters 10.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • gjacobseG
      gjacobse @scottalanmiller
      last edited by

      @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

      So very important to know... if you have one of these HPs and you take it to Geek Squad or return it to HP or send it out for recycling: it is easily full of your very, very private data, stuff that you never yourself recorded on the machine!

      I generally never let MY computer go without first DoD'ing the drive.... And if the system died (my ACER) I keep the HDD... nothing was wrong with it any way.

      No logger found in my old system -

      0_1494528121143_underwood5small[1].jpg

      1 Reply Last reply Reply Quote 2
      • MattSpellerM
        MattSpeller
        last edited by

        Good lord, someone's getting fired + put on trial for that one

        scottalanmillerS coliverC 2 Replies Last reply Reply Quote 3
        • scottalanmillerS
          scottalanmiller @MattSpeller
          last edited by

          @MattSpeller said in HP Laptops Found with Keylogger Built Into Audio Driver:

          Good lord, someone's getting fired + put on trial for that one

          One can only hope.

          travisdh1T 1 Reply Last reply Reply Quote 4
          • coliverC
            coliver
            last edited by scottalanmiller

            https://arstechnica.com/security/2017/05/hp-laptops-covert-log-every-keystroke-researchers-warn/

            1 Reply Last reply Reply Quote 1
            • coliverC
              coliver @MattSpeller
              last edited by

              @MattSpeller said in HP Laptops Found with Keylogger Built Into Audio Driver:

              Good lord, someone's getting fired + put on trial for that one

              Haha, oh man that's funny.

              1 Reply Last reply Reply Quote 0
              • travisdh1T
                travisdh1 @scottalanmiller
                last edited by

                @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

                @MattSpeller said in HP Laptops Found with Keylogger Built Into Audio Driver:

                Good lord, someone's getting fired + put on trial for that one

                One can only hope.

                Stop reading my mind before I scroll down far enough to see your reply 😛

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  keylogger.jpg

                  DustinB3403D 1 Reply Last reply Reply Quote 0
                  • DustinB3403D
                    DustinB3403 @scottalanmiller
                    last edited by

                    @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

                    keylogger.jpg

                    That password though. . . I mean come on "football23" no capitals, or special characters. . . Would you even need a keylogger for that?

                    travisdh1T 1 Reply Last reply Reply Quote 0
                    • S
                      scotth
                      last edited by

                      I have one here.
                      I made the log file read only.
                      Let's have a little fun.

                      momurdaM 1 Reply Last reply Reply Quote 3
                      • travisdh1T
                        travisdh1 @DustinB3403
                        last edited by

                        @DustinB3403 said in HP Laptops Found with Keylogger Built Into Audio Driver:

                        @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

                        keylogger.jpg

                        That password though. . . I mean come on "football23" no capitals, or special characters. . . Would you even need a keylogger for that?

                        My guess for a single cracking machine (8 video cards for massively parallel compute), about 2 minutes.

                        1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403
                          last edited by

                          Yeah I actually just shipped one of these laptops back yesterday!

                          Good thing it was only a trial device and we did nothing with it.

                          1 Reply Last reply Reply Quote 0
                          • momurdaM
                            momurda @scotth
                            last edited by

                            @scotth Is the log file showing all keystrokes before you made it readoly?

                            S 1 Reply Last reply Reply Quote 0
                            • S
                              scotth @momurda
                              last edited by

                              @momurda No. Zero byte file at this time. I haven't checked alternative streams yet.

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                scotth @scotth
                                last edited by scotth

                                @scotth said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                @momurda No. Zero byte file at this time. I haven't checked alternative streams yet.

                                Interesting. While attempting to open the file, I get denied access due to another process.

                                Edit: It's currently marked as readonly and hidden.

                                JaredBuschJ 1 Reply Last reply Reply Quote 0
                                • JaredBuschJ
                                  JaredBusch @scotth
                                  last edited by

                                  @scotth said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                  @scotth said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                  @momurda No. Zero byte file at this time. I haven't checked alternative streams yet.

                                  Interesting. While attempting to open the file, I get denied access due to another process.

                                  Edit: It's currently marked as readonly and hidden.

                                  The executable will delete it and recreate it though.

                                  1 Reply Last reply Reply Quote 0
                                  • momurdaM
                                    momurda
                                    last edited by momurda

                                    Math is probably wrong, but
                                    football23
                                    10 chars password
                                    36 possiblities per character space only using lowercase letters and numbers
                                    36^10 possibilities roundabout.
                                    3,656,158,440,062,976
                                    If you do 100MillionHashes/second,
                                    365,615,644 seconds or 101,559 hours or 4231 days or 11.5 years

                                    But since football is in the dictionary it is likely much easier if your algorithm does dictionary before trying random strings. Either way, it is much easier to do if youre recording keystrokes.

                                    @scotth Can you undo the read only bit and reboot that laptop see what happens?

                                    DustinB3403D S travisdh1T 3 Replies Last reply Reply Quote 0
                                    • DustinB3403D
                                      DustinB3403 @momurda
                                      last edited by

                                      @momurda It would take about a single day for the average computer to brute force that password.

                                      anthonyhA 1 Reply Last reply Reply Quote 1
                                      • S
                                        scotth @momurda
                                        last edited by

                                        @momurda Not right now. I may play around with it tonight. Comodo has a crazy task manager that I'll run on it tonight

                                        1 Reply Last reply Reply Quote 0
                                        • travisdh1T
                                          travisdh1 @momurda
                                          last edited by

                                          @momurda said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                          But since football is in the dictionary it is likely much easier if your algorithm does dictionary before trying random strings. Either way, it is much easier to do if youre recording keystrokes.

                                          Yep, dictionary word = not even bothering with brute forcing.

                                          1 Reply Last reply Reply Quote 1
                                          • anthonyhA
                                            anthonyh @DustinB3403
                                            last edited by

                                            @DustinB3403 said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                            @momurda It would take about a single day for the average computer to brute force that password.

                                            What if the authentication back-end implemented a lockout or throttling policy? Like after X attempts the account is locked out and/or authentication responses are delayed by X time?

                                            travisdh1T 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 1 / 4
                                            • First post
                                              Last post