Author Topic: A Yahoo Keylogger?  (Read 1884 times)

0 Members and 1 Guest are viewing this topic.

Psychtor

  • Guest
A Yahoo Keylogger?
« on: March 04, 2008, 05:44:07 PM »
I don't use Yahoo search engine very often so I only noticed yesterday that Yahoo has a search suggestion keyword function, live as you type.

Other people may be familiar with this but I'm not so I would like to hear others input.

It acts like a keylogger or actually it is a keylogger in my opinion and each letter of the word you type on your keyboard, that same key, as if you pressed "r" or whatever, acts as and doubles as the "enter" key as if you were submitting form information by using the enter key and "something" involved with the markup in that page has your browser automatically connect to the internet with the "r" information and feeds back information from Yahoo which basically are words that appear in a drop down menu.

In my opinion the malicious potential for this function is staggering because it notes and transmits the keystrokes in real time, absent offering real time info on the screen it is invisible, doesn't have an executable (.exe, .hta), employs a completely trusted process on a trusted site, doesn't use a "log" file to hold information for future retrieval, will not appear in a process viewer, goes straight through a firewall and goes unrecognized by antivirus and various scanners.

I believe that protection-ware that works in real time and or browsers themselves should pick up on something like this and warn the user with an option to continue warning since one can only imagine the harm that could be caused if the user stumbled across a or was victim of a counterfeit website impersonating a bank or other that used such a function as this minus any tell tale info appearing on the screen such as search keyword suggestions.

It would make a nice addition to both Avast Home and Pro.
« Last Edit: March 04, 2008, 06:17:35 PM by Psychtor »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33912
  • malware fighter
Re: A Yahoo Keylogger?
« Reply #1 on: March 04, 2008, 10:57:52 PM »
Hi Psychtor,

These are two different things: searchengine position keyword function and keyloggers
http://www.priorartdatabase.com/IPCOM/000162091/
Yes, search engines are able to make user profiles (hopefully completely anonymous and yes they land on several desks every night, and yes people pay for your click stream, we know they do). If that should be a concern to your privacy, use a proxy, use TrackMeNot inside a Torpark browser with Privoxy, and Yahoo or Google will find it a bit harder to profile you personally. There is also the possibility to use Scroogle for a search engine, that is not storing your queries, but agree as you go online you have lost your privacy and are almost transparent to some or else you have to go deep into the inhabitable jungle and play a drum to communicate or let a pigeon fly. If they have three satellite points on you electronically you can be traced within a couple of inches, and if they deny it they are lying. Big Brother has long arrived here, and these are facts, learn to live with it, and feel more secure,

polonus


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!