Risk: Informational
A company has unveiled a tool that can sniff confidential information even when a computer is locked.
DaisyDukes is a memory sniffer that resides on a USB device. A malcious person is able to plug it into an unattended machine that is turned on and reboot the machine. Depending on the user's needs, it can be configured to capture the entire contents of a computer's memory.
Sherri Davidoff, a security analyst with IntelGuardians, says that computers retain a lot of sensitive information, especially passwords, in the memory and can be easily sniffed using DaisyDukes. It has already been able to isolate passwords for Thunderbird, AOL Instant Messenger, GPG, SSH, Outlook, Putty and TrueCrypt.