Showing posts with label knowledge. Show all posts
Showing posts with label knowledge. Show all posts

Ten emerging malware trends for 2007

The bad guys have cranked up their malware-generating machine in the past couple of years, honing their methods to create powerful malicious code. And, the small trickles of advanced malware that we have seen in recent months are indicative of a tumultuous future. Here are 10 trends to keep an eye on from the malware front:


10) Spyware protected by rootkits
Spyware authors primarily make money when their software injects advertisements into a user's surfing experience, sends spam from a user's machine or performs keystroke logging to snag account numbers from a victim. The longer spyware is installed on a system, the more money an attacker can make. Enter rootkits, which alter operating system software so an attacker can hide code while maintaining control of the system. Today's sophisticated rootkits can hide attackers' files, processes and network usage from unsuspecting users and system administrators. This powerful combination, which sticks spyware to the victim machine using rootkit techniques, makes detecting and eradicating malware very difficult indeed. To fend off such attacks, keep antivirus and antispyware tools up-to-date, and utilize free rootkit-detection tools, like Microsoft's Rootkit Revealer, F-Secure Corp's Blacklight, Sophos' Anti-Rootkit, McAfee Inc.'s Rootkit Detective and Trend Micro Inc.'s RootKitBuster.

9) Totally smashing trust with evil certs
When a browser is installed, it contains certain digital certificates of certificate authority companies that your browser vendor believes are trustworthy. These companies can generate certificates for other organizations, such as banks, ecommerce companies and software vendors. Unfortunately, some savvy hackers have started to install alternative, evil certificates into the browsers of infected machines, meaning even after a victim discovers and removes an attacker's spyware, a phony certificate would tell the previously infected machine's browser to trust malicious Web sites, making reinfection easier. To mitigate this threat, I recommend periodically checking the trusted certificate authorities that are configured in your browser, and verify that those companies can be trusted. Internet Explorer users can check these certs by going to Tools then Internet Options then Content then Certificates. Once in the Certificate tab look under Intermediate Certificate Authorities then Trusted Root Certification Authorities then Trusted Publishers.

8) Editing network configurations and disabling antimalware tools in multiple ways
For years, some malware samples have attempted to foil antivirus and antispyware updates by altering a local hosts file to point the domain names of the various antimalware vendors to 127.0.0.1. That way, when the antimalware tool tries to receive its update, it resolves the vendor's domain name to localhost, where, unfortunately, there isn't a server waiting to deliver signature updates. Look for hackers to bring this technique to new levels this year. While altering a host file is pretty blatant, attackers have started using more subtle tactics, like attempting to change personal firewall settings to block access to antimalware sites or running scripts that turn off various antivirus and antispyware tools. Hackers are deploying malware that renders the antimalware tool blind, a tactic that's harder for users to spot. To defend against such attacks, pay attention to the update status of your antivirus tool; verify that it can download new signatures. It is also wise to periodically check your antivirus tool. I recommend using the EIcertificate authorityR's free antivirus test file. If an antimalware tool cannot detect EIcertificate authorityR, in all likelihood, it has been disabled.

7) Self-updating malware and metamorphic code
In an effort to stay ahead of antimalware signature updates and to deploy new functionality to extend the capabilities of their botnets, attackers are increasingly deploying self-updating malware. Such tools poll attacker-controlled Web sites for the latest updates, which bad guys can effortlessly install on hundreds of thousands of machines in just minutes. In effect, the attackers are implementing distributed software distribution, not unlike their own private Windows Server Update Services (WSUS). To stay ahead of this trend, update antivirus and antispyware tools once a day, and use tools like Microsoft Sysinternals' TCPView to look for unusual connection activity going to or from the system.

6) Peer-to-peer botnets
Historically, botnets have been controlled using Internet Relay Chat (IRC). Each bot logs into the same IRC channel as its creator. The attacker issues commands, which all of the bots read and then perform. But, there's a problem with this for the bad guys – there is a single point of failure. If investigators shut down the IRC server or remove the channel, the botnet cannot accept commands, preventing the attacker from communicating with his minions of infected machines. To avoid this, attackers are starting to use peer-to-peer (P2P) protocols to direct botnets without a central point of control. Some cutting-edge criminals are also looking for ways to control botnets using the Waste and Skype protocols used for Internet-based phone calls. These two techniques indicate the attackers are, in effect, creating highly distributed systems and are devising clever mechanisms for managing their distributed empires. To prevent this information security threat, use a tool like TCPView or the netstat command to look for unusual communications streams going to or from the system.

5). Script-based worms for Web 2.0 site
Recently, we've seen attackers exploiting Web services, which often allow one user to post information that thousands of other users can read. These so-called "Web 2.0" services include MySpace, Facebook, Gmail and countless others. Some are vulnerable to cross-site scripting attacks, in which malicious hackers post a script to their page in the service, and trick users into viewing the page via a browser. Once the victim reads the page, his or her browser runs the attacker's script. This script then uses the victim's account to add the script to the victim's own profile. If anyone else were to read this victim's profile, their account will become infected. The contagion then spreads, account to account, using victim's browser as the vehicle to run scripts from other users' profiles. To help defend against Web 2.0 attacks log out of any accounts and browsers when not in use.

4) Client-side exploits
As Microsoft has worked to eliminate server-side exploits, attackers are increasingly hunting for exploitable vulnerabilities in client-side software, including browsers, file viewers and music applications. In 2006, we saw several zero-day attacks in software like Internet Explorer, Microsoft Word, Microsoft PowerPoint and others. After creating an evil file that exploits the given client software, attackers then spew it out in spam or load it onto Web sites around the world, exploiting users who read the email attachment or simply surf to the wrong site. Look for many, many more of these in the future. To defend against them, diligently patch computers and ensure that antimalware software is current; if an enterprise system is vulnerable, detecting and removing malicious code is easier. Finally, consider using host-based intrusion prevention systems (HIPS), such as McAfee's Entercept and Cisco Systems Inc.'s Security Agent. HIPSes can defend against many attacks that haven't been seen by preventing the actions exploitable applications may take.

3) Privilege escalation attacks
With the release of Windows Vista, Microsoft has worked hard to create an operating system that more carefully divides user privileges. With Vista, it should be easier to deploy users in roles that let them get work done, without granting them local administrator privileges. This is certainly a good advance if the Microsoft promises are accurate. Too many organizations today let users surf the Web and read email from admin-based accounts. But if Windows Vista succeeds and eases the deployment of users without admin rights, attackers will most certainly need to develop new techniques. They'll still be able to break in with a client-side exploit, but, because clients have limited privileges, they won't have complete control of victims' machines. Therefore, look for attackers to focus heavily on finding local privilege-escalation attacks that will jack up their non-admin accounts to local system privileges, the most powerful local rights on a Windows machine you can have. To defend against what may be an avalanche of these exploits in 2007, keep Windows patched and deploy antivirus and antispyware tools.

2) Really big botnets (RBBs)
It almost seems quaint to think of the botnets of a decade ago, with one to three hundred systems under control of one malicious hacker. Today, such numbers represent a baby botnet. Hackers have extended their empires so that botnets of 60,000 infected machines are run of the mill. Look for bigger botnets in the future, with several examples tipping the scale over a million systems. With economies of scope at that magnitude, the attackers wield immense computing power. They can direct a flood and knock systems off of the network, crack crypto keys and passwords at rates that used to only be available to highly funded government agencies. To deal with this trend, those responsible for the security of an organization's network should have the emergency number for their ISPs, so if there is a massive attack against an organization, key personnel are notified.

1) Move to non-computer platforms
The vast majority of malware to date has affected PCs. But as more and more processing power is added to non-computer platforms, more generalized operating systems will be able to store sensitive data. In 2007, watch for attacks against cell phones, PDAs and (dare I say it?) even the iPod. As such devices proliferate and are connected to the Internet wirelessly, a whole new malicious code vector will surface. While there aren't a lot of defenses available now, antivirus vendors will realize the need for such tools in this new environment and release products specialized for this realm.

About the author:
Ed Skoudis is a founder and senior security consultant with Intelguardians, a Washington, DC-based information security consulting firm. His expertise includes hacker attacks and defenses, the information security industry and computer privacy issues. In addition to Counter Hack Reloaded, Ed is also the author of Malware: Fighting Malicious Code. He was also awarded 2004, 2005 and 2006 Microsoft MVP awards for Windows Server Security, and is an alumnus of the Honeynet Project. As an expert on SearchSecurity.com, Ed answers your questions relating to information security threats.

from: here

Active FTP vs. Passive FTP

Somethings need to understand in terms of FTP ==> PORT mode, PASV mode.
Read this help file from Microsoft.

Here also has a very useful article explaining the difference between Active FTP and Passive FTP.

The following chart should help admins remember how each FTP mode works:

Active FTP :
command : client >1023 -> server 21
data : client >1023 <- server 20

Passive FTP :
command : client >1023 -> server 21
data : client >1023 -> server >1023
A quick summary of the pros and cons of active vs. passive FTP is also in order:

Active FTP is beneficial to the FTP server admin, but detrimental to the client side admin. The FTP server attempts to make connections to random high ports on the client, which would almost certainly be blocked by a firewall on the client side. Passive FTP is beneficial to the client, but detrimental to the FTP server admin. The client will make both connections to the server, but one of them will be to a random high port, which would almost certainly be blocked by a firewall on the server side.

Luckily, there is somewhat of a compromise. Since admins running FTP servers will need to make their servers accessible to the greatest number of clients, they will almost certainly need to support passive FTP. The exposure of high level ports on the server can be minimized by specifying a limited port range for the FTP server to use. Thus, everything except for this range of ports can be firewalled on the server side. While this doesn't eliminate all risk to the server, it decreases it tremendously. See Appendix 1 for more information.

for details, please go to the website.

Yahoo 知识堂的回复


问题

如何获得更多的中文垃圾邮件?

课题研究的原因,我需要大量的中文垃圾邮件,现在我每天可以收到大概十几二十封垃圾邮件,但是还远远不够。哪位能够告诉我,除去那些基本的方法(网站注册,订阅杂志等等),还有什么更有效的方法能获得更多的垃圾邮件?多谢!
另外欢迎转发你的中文垃圾邮件给我!请转发到:rui.yahoo@anquan11.cn, 多谢!

在各家论坛上留下邮箱。尤其要在阿里巴巴上注册一下。哈哈。什么购物网站也不能忘掉。而且在各种征婚网站,色情网站也注册一下。
楼上的问题还真是奇怪!!!

连接




Yahoo 知识堂!

Yahoo出了.cn结尾的域名: yahoo.cn
并且,Yahoo也有知识堂:ks.cn.yahoo.com/
和这两个差不多:百度知道,新浪知识人

robtex