Internet Security Privacy Policy

Saturday, November 3, 2007

Definition Hacking and Hacker

•What is hacking?

According to Computer Crime Research Center (US), “Hacking is unauthorized use of computer and network resources”.

•Who is a hacker?

A hacker is a gifted programmer; a programmer for whom computing is its own reward and also enjoys the challenge of breaking into other computers, networks, cracking applications, etc.

•How the hacker can hack a system?

Hackers hack by exploiting the weaknesses of the target system, network, etc, for poor configuration applications and web servers, unpatched or old software, poorly chosen or default passwords and disabled security controls.

•Why hack at all?

Hackers hack because they want it that way. There is no specific reason why they do that. Some does hacking to test their computer skills, others do that to steal specific data from the target. Once a vulnerable point is identified in the system, they definitely attempt to hack to try to gain administrative access to the machine.

•Different types of hackers

The different types of hacker are

1.WhiteHats are the hackers that try to make the movement go forward by working as system administrators, security experts and by maintaining web sites with new technologies, news events, bug reports, and much more.

2.Black hackers attack other’s systems; whereas White hackers do exactly opposite i.e., defend against attacks.

3.Crackers penetrate networks and try to take advantage of something they discover in the process; they are really malicious.

4.Script Kiddie, does not really possess any skills except for the tools, uses tools and techniques developed by WhiteHats, BlackHats and Crackers to deface sites, destroy information, and do other types of digital-vandalism.

•Basic Hacking Methodology

The basic steps for any hacking methodology are

1.Information gathering (Probe)

2.Attack (Advancement & Entrenchment)

3.Infiltration or Extraction

•Most Prevalent Hacking Attack Categories

Hackers preferably attack the organizations systems infrastructure and commercial applications. If the systems are well secured then the hacker may resort to social engineering or focus upon the target application vulnerabilities.

The four most prevalent attack categories are

1.Exploitation of Application-related privileges: Some server-based applications run with specific User or group permissions. By using Race conditions or Buffer overflow attacks these applications’ security can be compromised.

2.Client-side manipulation: Hackers bypass client-side validations by supplying incorrect data formats or data to the server in an attempt to reveal both the functionality and secured data.

3.Race Conditions: When the coding is not done properly for an application to access specific variables, files, and data or installed the appropriate checks to implement simultaneous accesses then the hacker can get unintended access to data through both trusted and untrusted server application components.

4.Buffer Overflow Attacks: Normally applications take data as an input and pass it to memory buffers for manipulation. If the coders do not put a checkpoint to check whether the size of data is too big for a buffer then they are bound to be a complications. Hackers may take this condition as an advantage and can embed their own commands within the oversized data package. Perfectly implemented, these commands can acquire System Administrator privileges to the hacker.

•Cyber attacks: What are they?

Cyber attacks happen on a nation-wide scale and includes clogging up the adversary country’s computers which handle sensitive information like logistics, communications, war strategies, shutting down their civil utilities, like national power grid, jamming radar sites, crushing military’s computers, and downing commercial websites, etc.

•Hacker’s tools

There are so many tools available in the Net and also in the market using which anybody can do the basic hacking. A few tools are

1.DSniff -- a suite of programs that can be used in penetration and auditing testing.

2.Ethereal -- the widely used network protocol analyzer.

3.AirSnort -- a wireless LAN (WLAN) tool which recovers encryption keys.

4.Netcat -- a simple Unix utility which writes and reads data across network connections, using UDP or TCP protocol.

•Hacking in day-to-day life

To name a few…

1.Application hacking

2.Email hacking

3.Password hacking

4.Key Loggers…

•The key to winning the war against hackers…

The first step is to know both the state of one’s own network and its vulnerabilities and also the tactics hackers employ and deploy. Strategic analysts proclaim the key, to escape being hacked by somebody, is network security. But again, unfamiliarity of hacker’s activities and ignorance of how to deploy firewalls and other security features effectively can make you the hacker’s favorite target.

“Hope for the best and plan for the worst” should be the motto in drawing strategies against hackers.

Article Source: http://EzineArticles.com/?expert=Pavan_M_Kumar

Read More......

Friday, November 2, 2007

ZIP then, RAR now. What’s next?

NUWAR is at it again. It has tweaked its technique one more time.

Last week, WORM_NUWAR.AOP was found arriving as a file contained in a password-protected ZIP archive, an attempt to evade file scanning. The password to the archive is in an image used as message body, an attempt to evade anti-spam technology. While NUWAR is known for its distinct social engineering schemes — either by using sensational email messages about war or love, or by using incredibly timely email details — WORM_NUWAR.AOP had an interesting scheme itself. It used email messages posing as a notification from an antivirus company. “Worm Detected!” the email message declared.

Apart from the specific detection for the file within the archive, Trend Micro also detects the malicious password-protected ZIP file as WORM_NUWAR.ZIP.

Now, a new NUWAR variant is making its rounds contained in a password-protected RAR archive. Detected by Trend Micro as WORM_NUWAR.AOS, the worm was spammed using email messages that continue what WORM_NUWAR.AOP started, albeit with a wider scope: the email messages now also declare “Virus Detected!” and “Spyware Detected”, among others. As with WORM_NUWAR.AOP, the message body is an image file. Trend Micro detects the malicious password-protected RAR archive as WORM_NUWAR.RAR. WORM_NUWAR.AOS, however, was clearly spammed, because it has a propagation routine of its own using email messages that NUWAR has been associated with — messages of love. “For You….My Love”, “I Love Thee”. Like several of its predecessors, on execution WORM_NUWAR.AOS drops NUWAR’s partner-in-crime, TROJ_SMALL.EDW, known for creating P2P-based connection between all affected computers, forming a link that ultimately assists NUWAR in its own pump-and-dump spam attack.

With the release of WORM_NUWAR.AOS, it doesn’t look like NUWAR is letting up any time soon. In just a few months, it has shown an interesting pattern of social engineering tactics. Its authors seem to be always watching out for events to exploit, or, when there is none, they come up with a new tactic altogether.

NUWAR is clearly a social engineering attack. Users are the primary target. Users should therefore be extra vigilant.

Source : Trend micro blog

Read More......

ZLOB Crosses Over

ZLOB Trojans, which proliferated in 2006, are known for using fake codec downloads as their social engineering technique to entice users into downloading the malicious software on their systems. Initially, they are also known to affect Windows-based platforms only. Today, this Trojan family seems to be crossing over to the “other side”.

Intego, who recently partnered with Trend Micro to directly distribute Mac security products, tipped Macworld of the existence of a ZLOB Trojan that affects Mac OS X. Intego reports that the malware disguises itself as video program that when opened, displays a message that a codec is needed to run the program properly. In the background, however, it downloads then launches an installer that asks the user to enter administrator password. ZLOB variants are notorious for this type of routine. Thus, Trend Micro detects the said malware as TROJ_ZLOB.GAF.

It can be downloaded from the Web site http://{BLOCKED}tracodec.com/download/ and arrives as a .DMG file, the common format used by Mac installers. Depending on the IP address that downloads the Trojan, this Web site gives back a copy of the Trojan with a different MD5sum. Note that Trend Micro created the detection OSX_ DNSCHAN.A for the DMG file and UNIX_DNSCHAN.A for the Bash script file inside the said DMG.

Malware are crossing over. Mac fandom, beware!

Data provided by Trend Micro Senior Software Engineer Feike Hacquebord. Additional information from Elizabeth Bookman

Source : Trendmicro

Read More......

Thursday, October 18, 2007

Spyware Protection - Is Your PC Protected ?

No doubt that we use computer in almost every part of our life. Be it at work or at home, computer just as important as other necessity. One part of using a computer is being connected to the internet. This internet connection which can be used for a variety of purposes will sometimes open unwanted doors. These will be in the form of numerous dangers which can hurt your computer’s working abilities. Spyware protection can help to provide the answer.

These protection programs are known under many names. Some of these software programs are more popular than others. These are programs which you can get to detect the presence of spyware and other harmful intruders into your computer environment. While some of these programs are limited in use there are others that you can use in place of these.

You will have the opportunity of downloading these spyware detection programs if you want them. You can also see the demo versions to see if they are worth your time and effort. When you are downloading one of these spyware detection programs make sure that you have chosen the correct version as there are different programs with different specifications that you can choose from.

You will be able to use many different popular spyware protection programs to find and remove or destroy spyware programs. As these are software programs are well known and popular, you have probably heard of their capabilities and features. You will find demo versions to see what can be accomplished with their help.

To see more details about these programs you will need to hunt around for information. The internet is one such option which will allow you to see the different brands of spyware protection programs that you can use for your computer.

When you are thinking about installing any of these spyware protection programs make sure that have the latest version on hand. The latest version which is installed on your computer you will provide you with some of the latest advantages to be found in these programs.

When you look at either downloading or buying any of these spyware protection programs always make sure that you have understood the instructions exactly. This will help in the easier installation of the program. By using these spyware detection programs which have been created to stop spyware invasions you will be able to set your computers system settings to intercept these intruder programs. Spyware protection hits these unwanted programs before they have a chance to get activated from within your computer when you access the internet.

Source : http://spyware removal tips

Read More......

Tuesday, September 25, 2007

Backdoor.IRC.Bot

Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


When Backdoor.IRC.Bot is executed, it may create a copy of itself in the %Windir% or the %System% folders.

Note:

* %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
* %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).


In most cases, this Trojan uses one or more of the common loading points to ensure that it runs when you start Windows. For information about common loading points, read one of these documents:

* Common loading points of threats in Windows NT/2000/XP
* Common loading points of threats in Windows 95/98/Me



Some of the actions that Backdoor.IRC.Bot can perform include:

* Listening on an IRC channel for commands from a remote attacker, allowing them to control a compromised computer.
* Connecting through TCP port 6667 or 18067 to an IRC server.
* Viewing system information, such as running processes, software installed, and other items.
* Terminating processes.
* Flooding the IRC channels.
* Flooding mailboxes (mailbombing) .
* Executing programs and scripts on the compromised computer.
* Uploading or downloading the files to the compromised computer.
* Updating the version of the Trojan.
* Participating in a Distributed Denial of Service (DDoS) attack on a remote host.
* Searching files on the compromised computer.
* Executing commands on command.com.
* Scanning for computers with the LSASS vulnerability (described in Microsoft Security Bulletin MS04-011)
* Uninstalling the Trojan.



Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

* Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
* If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
* Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
* Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
* Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
* Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
* Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

Writeup By: Tony Lee


Source : http://www.symantec.com

Read More......