Re: [TSCM-L] {5096} USB key logger

From: Jason Dibley <Jason..._at_qcc.co.uk>
Date: Mon, 18 Oct 2010 15:12:18 +0100

>From - Sat Mar 02 00:57:23 2024
Received: by 10.224.213.197 with SMTP id gx5mr461441qab.14.1287369722826;
        Sun, 17 Oct 2010 19:42:02 -0700 (PDT)
X-BeenThere: tscm-l2006_at_googlegroups.com
Received: by 10.229.101.82 with SMTP id b18ls268173qco.0.p; Sun, 17 Oct 2010
 19:41:58 -0700 (PDT)
Received: by 10.229.212.137 with SMTP id gs9mr429967qcb.15.1287369718441;
        Sun, 17 Oct 2010 19:41:58 -0700 (PDT)
Received: by 10.229.212.137 with SMTP id gs9mr429966qcb.15.1287369718417;
        Sun, 17 Oct 2010 19:41:58 -0700 (PDT)
Return-Path: <ber..._at_netaxs.com>
Received: from webmail1.paetec.net (webmail1.paetec.net [209.92.1.171])
        by gmr-mx.google.com with ESMTP id j6si1740632qcu.10.2010.10.17.19.41.58;
        Sun, 17 Oct 2010 19:41:58 -0700 (PDT)
Received-SPF: neutral (google.com: 209.92.1.171 is neither permitted nor denied by best guess record for domain of ber..._at_netaxs.com) client-ip 9.92.1.171;
Authentication-Results: gmr-mx.google.com; spf=neutral (google.com: 209.92.1.171 is neither permitted nor denied by best guess record for domain of ber..._at_netaxs.com) smtp.mailūr..._at_netaxs.com
Received: from webmail1.paetec.net (webmail1 [127.0.0.1])
        by webmail1.paetec.net (8.13.8/8.13.8) with ESMTP id o9I2fv0v013007
        for <tscm-..._at_googlegroups.com>; Sun, 17 Oct 2010 22:41:57 -0400
Received: (from apache_at_localhost)
        by webmail1.paetec.net (8.13.8/8.13.8/Submit) id o9I2fvx5013006
        for tscm-..._at_googlegroups.com; Sun, 17 Oct 2010 22:41:57 -0400
X-Authentication-Warning: webmail1.paetec.net: apache set sender to ber..._at_netaxs.com using -f
Received: from 184-77-177-50.par.clearwire-wmx.net
 (184-77-177-50.par.clearwire-wmx.net [184.77.177.50]) by webmail.uslec.net
 (Horde Framework) with HTTP; Sun, 17 Oct 2010 22:41:57 -0400
Message-ID: <20101017224157.18402b16heohboys_at_webmail.uslec.net>
Date: Sun, 17 Oct 2010 22:41:57 -0400
From: "ber..._at_netaxs.com" <ber..._at_netaxs.com>
To: tscm-l2006_at_googlegroups.com
Subject: Re: [TSCM-L] {5090} USB key logger
References: <43E1A65ED32E444C9DBE53F853C1E4784C61B50971_at_qccsrv13.qcc.local>
In-Reply-To: <43E1A65ED32E444C9DBE53F853C1E4784C61B50971_at_qccsrv13.qcc.local>
MIME-Version: 1.0
Content-Type: text/plain;
 charset=ISO-8859-1;
 DelSp="Yes";
 format="flowed"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
User-Agent: Internet Messaging Program (IMP) H3 (4.3.4)

A good place to start would be to determine the manufacturer and to
contact them. Here's a good place to start identifying the device's
maker:

http://www.google.com/images?hl&q=%22usb%20keylogger%22&psjumie=UTF-8&source=og&sa=N&tab=wi&biw24&bihW9

-ed


Quoting Jason Dibley <Jason..._at_qcc.co.uk>:

> Dear Group,
>
> I have an incident running where we have found a USB key logger on a
> computer. We have tried many of the different default three key
> combinations to open the device, but thus far all have failed. I
> suspect that the password had been changed from the default.
>
> Do any list members have know of any other default pass combinations
> other than the ones below:
>
> SBK
> XVP
> 123
> Vghostlog
> SVL
> VMP
> KBS
>
> Any suggestions would be appreciated, before we have to consider
> other methods to open it.
>
> Kind Regards
>
> Jason Dibley
>
> Jason Miles Dibley Dip Eng (hons) MSyI CCO
> Company TSCM Director
> QCC Interscan Ltd.
> Buchanan House,
> 24-30 Holborn,
> London EC1N 2LX,
> England.
> Web: http://www.qcc.co.uk/
>
> February 2009: QCC Interscan Ltd launches an informative new
> website. Please visit our new site at
> www.qcc.co.uk<www.qcc.co.uk%20> , for the true facts about
> information theft and how to mitigate it.
>
> February 2010: Searchlight QCC Launches the worlds first reliable
> GSM eavesdropping detection system.
>
>
>
>
>
> --
> You received this message because you are subscribed to the Granite
> Island Group "TSCM-L Professionals List" group which is the oldest,
> and the largest TSCM group on Earth. To post to this group, send
> E-Mail to TSCM-..._at_googlegroups.com, to contact the list owner and
> moderator please send an E-Mail message to jm..._at_tscm.com.
>
> This group is sponsored by Granite Island Group http://www.tscm.com/
> to improve the profession of hunting spies, and to educate others in
> the craft of technical counter-intelligence. Granite Island Group
> performs bug sweeps like it's a full contact sport; we take no
> prisoners, we don't play fair, and we give no quarter. Our
> professional goal is to simply, and completely stop the spy.
>
> Granite Island Group Offers World Class, Professional, Ethical, and
> Competent Bug Sweeps, and Wiretap Detection using Sophisticated
> Laboratory Grade Test Equipment.
>
Received on Sat Mar 02 2024 - 00:57:23 CST

This archive was generated by hypermail 2.3.0 : Sat Mar 02 2024 - 01:11:45 CST