Pages

Showing posts with label spyware. Show all posts
Showing posts with label spyware. Show all posts

Wednesday, July 22, 2009

Spyware (Part - 3)

Let us see what are the medium through which a spyware infects computer. A spyware in a computer do not try to infect other computers like virus or worms or trojans. It just collects the user details and send to a particular person or firm via internet. Spywares usually get installed in the computer without the knowledge of the user. The spyware usually comes with a useful software. When the user installs the software without knowing that the software contains spyware, the spyware gets installed in to the computer and sends the details about the user stored in the computer. This is against the privacy in using internet. The manufacturer usually presents the spyware as a useful software. The common categories of the software include themes, games, internet utilities such as download accelerators, web boosters etc. Many Internet users were introduced to spyware in 1999, when a popular freeware game called "Elf Bowling" came bundled with tracking software. The cookie is a well-known mechanism for storing information about an internet user on their own computer. If a website stores information about you in a cookie that you don't know about, the cookie can be considered a form of spyware.
Another way of installing is by using the vulnerabilities in the security software provided to block this spyware. This is by making the user to click on a link that is disguised as a pop up asking any thing that makes the user click on the pop-up. that triggers the installing of the spyware. In a few cases, a worm or virus has delivered a spyware payload. Some attackers used the Spybot worm to install spyware that put pornographic pop-ups on the infected system's screen.By directing traffic to ads set up to channel funds to the spyware authors, they profit personally.



Add to Technorati Favorites Bookmark and Share





Monday, July 20, 2009

Spyware (Part - 2)

Now let us look in to a small history of the Spyware. I have searched several sites for getting the history of Spyware. The Wikipedia provides good and clear information on the history of the Spyware. I have extracted some part of the history of the Spyware here just for you. The first known use of the word Spyware was in October 16, 1995 and it was against Microsoft Business Model. Spyware was first considered as a hardware meant for the espionage purposes. In the early 2000, the founder of the Zone labs, Gregor Freund, used the term spyware during the release of the ZoneAlarm Firewall. Since then the term is used in its present sense. As of 2006, spyware has become one of the prominent security threats to computers using Microsoft Windows operating systems. Computers using Internet Explorer (IE) is the primary browser are particularly vulnerable to such attacks. It not only because IE is the most widely-used browser, but because its tight integration with Windows allows spyware access to crucial parts of the operating system.
Before Internet Explorer 7 was released, the browser would display a message showing that activex must be installed to view a particular section of the website or the whole website. But in most cases the spyware will be in disguised as activex. The combination of user naiveté towards malware and the assumption by Internet Explorer that all ActiveX components are benign, led, in part, to the massive spread of spyware. Many spyware components would also make use of exploits in Javascript, Internet Explorer and Windows to install without user knowledge or permission. After installtion, sometimes windows pop-up warning messages about the presence of the Spyware in the Computer.

The Windows Registry contains multiple sections that by modifying keys values allows software to be executed automatically when the operating system boots. Spyware can exploit this design to circumvent attempts at removal. The spyware typically will link itself from each location in the registry that allows execution. Once running, the spyware will periodically check if any of these links are removed. If so, they will be automatically restored. This ensures that the spyware will execute when the operating system is booted even if some (or most) of the registry links are removed.



Add to Technorati Favorites Bookmark and Share





Friday, June 26, 2009

Spyware (Part - 1)

A Spyware is any technology or software that gathers personal information of a person or the confidential information of a organization. A Spyware is a malicious application that is installed in the computer with or without the knowledge of the user. The Spyware, as its name suggest perform the function of a spy. It collects several information from the computer and send the information to the attacker. Some spywares allows the user to configure the victim's computer to his needs. The spyeare may be installed in to the computer without the knowledge of the user through the drive by download or by clicking the link on the pop-up window. But there are spywares available in the market which help the parents to track the sites visited by their children. As you may know that the browser stores the information about the sites you visited in the cookies. If the personal information about you are stored in the cookie, then cookie can be considered as a spyware. In the beginning stage the function of the spyware is just monitering the user. But as the time passes, more powerful spyware were introduced. There functions are not just limited to the simple monitering the user. It can not only collect the browsing habts of the user but can also install the software that will interfere with the normal operation of the computer. You may someetimes noticed that you cannot access the internet, but the data transfer occurs between your computer and the internet without your permission. That may be because of the spyware. Some people asks through the sites like yahoo answers, ibibo.com etc about the problem of the spyware redirecting the website. Even if they entered the correct website address, they are redirected to another site. This shows that your browser has compremissed with the spyware installed. As you may know, any personal information that is collected without the knowledge of the user by any means is a crime. Similarly the creaton and uasge of spyware that collects the personal information about the other people or organization is a crime. Many countries have made strict laws to prevent the spyware. Yet there are people creating the spyware, challenging the laws of their own nation.



Add to Technorati Favorites Bookmark and Share





Tuesday, May 5, 2009

Cyber Spying


Cyber Spying is the practice of stealing data or information from a computer without the knowledge of the owner. The Cyber Spying targets competitors, government,enemies, economists, politicians etc. Cyber Spying may be done on a computer located at far away from the attacker. Cyber Spying can be done with the help of several malicious softwares including virus, trojan, spyware etc. The Cyber Spying is done at work place by a computer professional or at home by a trained professional hacker. Cyber Spying is done by infiltrating in to the computer network in the illegal way. There were strong laws to prevent Cyber Spying.

You will get a detailed information from :

http://www.rainbowskill.com/internet-fundas/all-about-chinese-cyber-spying.php

Monday, January 5, 2009

Other Malicious Softwares

In the olden days of computing the only thing the viruses spread through is the infected floppies. The booting from infected floppies causes the viruses to spread in to the host machine. With the advancement of the technology the medium of spreading also widened. The medium of spreading became internet, pen drives etc. The internet service has resulted in the formation of several malicious softwares. There are several such softwares available in the internet.


  • Trojans

The most important difference between the Trojans and viruses is that Trojans cannot spread themselves whereas the viruses spread themselves. The Trojans disguise themselves as useful softwares and the user will download and install it thinking that it is a useful software. He only recognizes the harmful effect of Trojans only after it has started its job.

The Trojan has two parts: a server and a client. The server is the part that is installed in the attacker's system. It is the client that disguised themselves as a useful software and get installed in the victims machine. The client is present in the peer to peer networks and unofficial download sites. Once the Trojans enter in to the victims site, it has vast capability of destruction. The Trojans are highly sophisticated that they can be used according to the wish of the attacker. The attacker can decide the degree of harmness that can be caused by the Trojans. There are different types of Trojans. Some of them are listed below. A Trojan could have any or one of the combination of the below mentioned functionalities.



  • Remote Access Trojans

These Trojans give full control of the victim's machine to the attacker. The attacker can gather several information from the victim's machine including confidential thins like passwords, credit card number etc stored in the victim's machine.


  • Password Sending Trojans

These type of Trojans possesses great threats even today. The purpose of these Trojans is to send the password stored in the cached memory. They can also steal the passwords as you enter the passwords. They then send it to the specified e-mail without the users knowledge. Passwords of the restricted sites, e-mail, messaging services and FTP services come under the threat of these Trojans.


  • Keyloggers

These Trojans log victim's keystroke end send the log files to the attacker. They can be active in two modes: one in online mode and the other in the offline mode. The attacker can get several information including the passwords. The logs are send in the daily basis.


  • Destructive

The only function of these Trojans is to destroy all files in the core system. They performs the destructive work according to the will of the programmer or can be programmed to work as a logic bomb which can be activated in a special date or time.



  • Denial of Service (DoS) Attack Trojans

The main aim of this kind of Trojans is to reduce the bandwidth of the victims machine by increasing the net traffic. This makes the internet connection too overloaded to let the user to visit a website or download anything. One of the variation of this type of Trojans is the mail-bomb Trojan, whose main aim aim is to infect maximum systems as possible and simultaneously attack a specific e-mail address with random subjects and content that cannot be filtered. However today the e-mail service providers use advanced filters to filter out these malicious softwares upto an extend.



  • Proxy/Wingate Trojans

These Trojans turn the victim's system into a Proxy/Wingate server. Thus the victim's machine will be opened to many other systems connected to the network. The attacker can easily use this victim's system to anonymously browse in to the restricted sites and access various risky internet services. The attacker can register domains or access pornographic sites with stolen credit card number or can perform several similar illegal activities.



  • FTP Trojans

These Trojans are commonly very simple. But most of them does not exist today. It does nothing but opens the port for the FTP transfer that is port 21. So everyone connected to the network can access files from the victim's machine. Today the systems are password protected so that only attacker can connect to the computer.


  • Software Detection Killers

The main aim of these Trojans is to kill the softwares or firewalls that protect your computer from malicious softwares. This will reduces your computer's defense to the malicious softwares and becomes easily vulnerable to attacks. These Trojans exists even today. Some anti-virus asks the displays a confirmation message when they are to be uninstalled.



  • Worms

Computer worms are programs that reproduce themselves and run independently. They can travel across the network connections They are platform independent, so they can attack system running on any operating system. The difference between a worm and a virus is the method in which they reproduce and spread. A virus is dependent on a host file or a boot sector, and transfer of files between the machines to spread, while a worm can run completely independent and spread of its own through the network connections.

The security threat of worm is same as that of the viruses. Worms are capable of doing wide range of damages such as destroying essential files in the victim's computer, slowing it down to the maximum extend and even causes some of the essential programs to crash. Two famous worms are MS-Blaster and Sasser worms.


  • Spyware

Spyware is also an Adware (advertising-supported software). Advertising in shareware products is a way for shareware authors to make money, other than by selling it to the user. There are several large companies that offer to place banner ads in their products in exchange for a portion of the revenue from banner sales. If the user finds the banner annoying, there is usually an opinion to get rid of it by paying the license fee.

Unfortunately, the advertising companies often also install additional tracking software in your system that is continuously using your internet connection to send the statistical data back to the advertisers. Although the companies claims that they did not collect any personal information from the user so that he will be anonymous, the fact is that there is a server running in your computer that will send the information about you and your surfing habits to a remote location using the bandwidth of your internet connection.


Spyware slows down the speed of your internet connection. They also reduces the processing power of your computer. Sometimes unwanted pop ups will irritate the user. It also changes the settings of your browser like changing the home page or default search engines. Many people does not consider it as illegal. But unfortunately there is no way to get rid of such nuisance.