|
Home / Computers / Software
Trojan Horse Delivered In Automatic Update
By:Darren Miller
Trojan Horse - One Mans “Worse Case Scenario” Prediction
----------------------------
This is a fictional article about a Trojan Horse Virus, or you could say it is one mans prediction of a “worse case scenario”. Because of the field I’m in, I maintain a personal list of my top 10 “worse case scenarios”. Every time I perform a security assessment I run into something new or identify a situation that is ripe for a potential vulnerability. I think we could all agree that no respectable or ethical company would intentionally deliver a malicious piece of code as part of a helpful update solution. However, the reality is that human beings are behind technology and human beings are unpredictable and fallible.
Many major operating system vendors have automatic update services. Many hardware vendors and other software packages have followed this trend, incorporating automated update services into their products. In some cases, the services for automatic updates run as the local “system” account. This account has the ability to access and modify most of the operating system and application environment. When automatic updates were relative new, many people would perform the updates manually, however, as time has progressed, many now trust these services and allow the updates to proceed in a truly automated fashion.
The Final Step Before The Hammer Falls
--------------------------
So let’s expand upon our “worse case scenario”. A new service pack is just about ready for release. The last step prior to public release is quality control / validation. The team of people performing this task includes a significantly disgruntled employee (Or may he/she is going through a horrible life crisis and has not much to lose). When people are in pain or distress it is not uncommon for them to project this same feeling onto others in any way they can. So, instead of performing their job in the normal fashion, they decide to incorporate a malicious payload into the forthcoming update.
The First Step For The Trojan Horse: Evasion
--------------------------------------------------
This payload has some unique characteristic, three to be precise. First, it is constructed in such as way to not appear as something malicious. The anti-virus and anti-spyware programs currently on the market won’t be able to detect it through anomalous detection techniques.
The Second Step For The Trojan Horse: Information Collection
----------------------------
Secondly, it has been instructed to wait 12 hours to activate to start searching your computer an network for important files that may contain financial, healthcare, and other confidential information such as user accounts and passwords. It then sends this information to anonymous systems on the Internet. Because this “Trojan horse” has been incorporated into an automated update by someone with reasonable skills, it is instructed to only perform the collection of data for 12 hours. Given the number of global systems that allow automated updates, 12 hours should be more than enough. The person behind this realizes that someone will quickly identify that something malicious is going on and start to roll-out a defense solution to halt the process.
The Final Step: Incapacitate
-------------------------------
Finally, the Trojan Horse will cease it’s data collection and deliver it’s final blow. Because of the level of system privilege it is running at, it modifies the communication protocols and services on the system to prevent any type of external communication to its local peers and external (Internet) hosts. It does this in such as way that the only immediate method to recover from this is a system roll-back, system repair, or restore from near-line media, such as tape or disk. And as far as system recovery is concerned, I can tell you that many people even in corporate entities do not perform the most basic steps to be prepared for a quick system disaster recovery. In some cases, some of the most important recovery services have been disabled because of lack of system resources or disk space (which is amazing given how inexpensive this is anymore).
What Could Be The Impact Of This “Trusted” Trojan Horse
----------------------------------------
Just about every time you install a new application or piece of software you increase the time it takes to boot your PC and in some cases decrease its performance. On thing that drives me crazy is printing software. For the life of me I cannot understand how or why printer support software could total 400MB in size, but they sometimes do. Not only that, they tend to load all kinds of unnecessary real-time running applets. HP printers are notorious for this. Be very aware of what it is you are loading and only load those components that you need. Even some off-the-shelf software packages load adware and other not so helpful applets. Also, when you uninstall software, not all the software gets uninstalled in many cases. One thing I suggest is to purchase a registry cleaner. This can dramatically decrease boot times and in many cases increase the overall performance of your PC.
People are already concerned about identity theft, or at least they should be. I recently spoke with a business associate that told me that even with everything he does to keep his identity secure he has been the victim of identity theft not once, but twice. If your user id’s, online accounts, passwords, financials, or other confidential information winds up on the Internet for any anonymous person to see, you can bet it will be used in a way to cause you problems. Even if only 10% of the global systems fell victim to this Trojan Horse, the cut off of communications could cost businesses billions of dollars and potentially impact their reputation as “secure” institutions.
Conclusion
----------
If we don’t think that this “worse case scenario” can happen, then we’re kidding ourselves. Recently, one of the market leaders in the perimeter defense business had to recall a service pack because it contained a significant “bug” that could result in a security breach; a service pack that can be delivered through and intelligent update service. Obviously there has to be a certain level of trust between us, the consumer, and the vendors of hardware / software we rely on. I’m not entirely sure what “fail-proof” solution can be put in place to prevent something like this from happening. Although I’m sure there are quite a few checks and balances in place already. The bottom line is, if you or I can image a scenario like this, there is always a chance of it happening. In my case, I usually wait for several days to apply new service packs and hot-fixes. Hopefully someone else will find the problem, correct it, and then I’ll apply it.
You may reprint or publish this article free of charge as long as the bylines are included.
Original URL (The Web version of the article)
------------
http://www.defendingthenet.com/newsletters/TrojanHorseDeliveredInAutomaticUpdate.htm
About The Author
----------------
Darren Miller is an Information Security Consultant with over seventeen years experience. He has written many technology & security articles, some of which have been published in nationally circulated magazines & periodicals. If you would like to contact Darren you can e-mail him at Darren.Miller@defendingthenet.com. If you would like to know more about computer security please visit us at http://www.defendingthenet.com.
Digg
del.icio.us
Blink
Stumble
Spurl
Reddit
Netscape
Furl
Article keywords: trojan horse, trojan horse virus, delete trojan horse, remove trojan horse, trojan horse picture, trojan horse removal, new trojan horse
Article Source: http://www.articles2k.com
|
|
| Top Software Articles |
- 1). Track Your MySpace Profile Visitors By : PaulG
I know that everyone who is on MySpace has had the same burning questions that I’ve had. How can I see who has viewed my MySpace profile? Where can I find a MySpace Tracker? Since MySpace has become so popular, so have the MySpace profile stalkers. Could be your friends, neighbors, ex-boyfriends or ex-girlfriends, or even someone you don’t even know.
|
- 2). 13 Comparisons of Vista vs Tiger By : paul wilson1
Competitive and fast are two terms that are applicable to the world of computers. Constantly changing and evolving computer systems bring many advantages to the users and techies alike. The race for supremacy between the yet to be launched Vista (scheduled for 2006) and Mac OSX Tiger began in 2003 with Microsoft’s announcements of plans for an integrated desktop search functionality in Windows Vista.
|
|
|
- 4). The Top Five Spyware Issues Dealing With Internet Security By : Greg Lietz
One of the main ways to compromise internet security on your PC is via a program called a Trojan Horse. A Trojan Horse is a program that quietly runs in the background, inviting the user to run it, while spreading its malicious code. This code can do any number of things. It can start right away or it may simply install a program that won't start for sometime.
|
- 5). The Benefits of Open Source By : Matthew C. Keegan
If you are a building a website or a forum, chances are you are using a web editor or paying for message board services. The costs of using these "out of the box" products can add up, especially if you are trying to grow your business. Let's look at some good "open source" options for you to consider. You may be surprised at how much money open source can save you.
|
- 6). Virus Strains By : J Square Humboldt
What we need is the Dewey Decimal System to go digital ...
Specifically, someone needs to coax their keepers into putting some logical order into how computer viruses are sorted.
Recently, warnings abounded about the Kama Sutra virus quickly proliferating cyberspace, joining the Grew.A and Nyxem.E as serious threats to computer file security. However, only those who took a closer look at these strains were able to discover that they all had something in common.
|
- 7). How To Install And Setup Noah's Classifieds By : Bedrich Omacka
In this article I will explain the basic Noah's Classifieds features, show you how to install this script and how to setup it to run properly. First of all let's mention that Noah's Classifieds script is written in PHP can be used for free. Noah's Classifieds is one of the most popular classified ads tool on the Internet. Using this great script you can create unlimited categories and subcategories, upload images for the categories and the advertisements, define variable fields for the advertisements per categories etc.
|
- 8). Trojan Horse Delivered In Automatic Update By : Darren Miller
Trojan Horse - One Mans “Worse Case Scenario” Prediction
----------------------------
This is a fictional article about a Trojan Horse Virus, or you could say it is one mans prediction of a “worse case scenario”. Because of the field I’m in, I maintain a personal list of my top 10 “worse case scenarios”. Every time I perform a security assessment I run into something new or identify a situation that is ripe for a potential vulnerability.
|
- 9). New to gaming, all you need to know about Flash gaming sites By : paul wilson1
Whew! According to Computer Gaming World, there are 80 gazillion free Flash games sites in the cyber world.
Popular sites are:
• www.games.yahoo.com -- this has card games, word games, arcade games, as well as puzzles. The number of violent games is limited so the site appeals to the “old-young” –those who are young at heart.
• www.shockwave.com -- a popular site with original games as well as PopCap ones.
|
- 10). Improve PC Performance - 6 Tips You Must Know By : Michael Braid
Are you frustrated with your PC?
Is it feeling sluggish or crawling at a snail's pace?
Are programs running slower than they used to?
Are you just plain fed up with frequent slowdowns, freezes or crashes?
Then it's time to stop what you're doing and optimize your system to improve PC performance!
Follow these 6 simple sure-fire tips to help improve PC performance and you'll be surprised by the results! Each comes with an indication of how often you should do it.
|
| New Software Articles |
|
|
|
|
- 3). Business Intelligence guide By : mansi gupta
Business intelligence can be defined as a set of business processes designed to garner and analyze business information. It is a vast category of application of programs that includes providing access to data to help an entrepreneur in his business decisions, task of query and reporting, online analytical processing (OLAP), statistical analysis, forecasting and data mining.
|
- 4). PsP Software Downloads – Review of Software Sites By : pjs1965
PsP handhelds are one of the newest and most fun ways to play games, watch movies and listen to music. PsP software downloads are just some things that you can do to improve your psp. PsP software downloads are fun and easy.
There are many places on the net were one can find psp software downloads. Some sites have you pay per download and sometimes charge up to a couple dollars for each download.
|
- 5). PsP Software – Review of Software Download Sites By : pjs1965
PsP handhelds are one of the newest and most fun ways to play games, watch movies and listen to music. PsP software downloads are just some things that you can do to improve your psp. PsP software downloads are fun and easy.
There are many places on the net were one can find psp software downloads. Some sites have you pay per download and sometimes charge up to a couple dollars for each download.
|
- 6). Microsoft Has Stunted Innovation By : Chris Young
Creativity is what spurred the growth of the computer industry and technology. Challenges were met and new frontiers conquered through sharp-edged innovations and competition. Sadly, over the years small companies like Microsoft grew into giants and then lost their thirst for adventure. They deliberately hid their proprietary source code and this stunted innovation.
|
- 7). Download Music, Movies and Games for Free - A Hot Issue By : Harry Rackers
The Internet is used by a lot of people to download music, movies, games and various other soft wares for free. The legality of this practise is, and will be for a long time, a hot issue. Some countries want to totally stop the downloading of copy wright protected materials, like the U.S.A. Other countries, like France, want to allow this type of downloading, but only for personal use.
|
- 8). Expressing Love With Ecards - Is It Effective? By : CD Mohatta
Can love be effectively expressed with ecards? With many mediums available today, which medium should be our medium of choice in expressing our feelings. We have choice of sending a voice mail, sending an email, a printed card, and ecards. Of course the first choice always remains - our own talk. How are ecards better than other mediums to express love? Let us look at that.
|
- 9). Learn Management With Desktop Wallpapers By : CD Mohatta
Learning over the ages has undergone many changes. In recent years many rapid changes have taken place, from classroom teaching to online education. Could you ever think that management could be taught with the help of Desktop wallpapers? Here is how it is being done now days.
Learning - Let us look at learning. How do we learn? By reading, reflecting and thinking and then remembering what we have been taught.
|
- 10). Adware is a Pain but you Can Deal with Fast By : Carol Hansonly
Adware is one of those things that many people simply do not worry about until the ghastly stuff actually does some damage. Yes it can cause damage and sometimes this is too late to fix. The plain facts are that adware or spyware can number one effect your computers functionality and two this can lead to system failure and ultimately data loss.
Now without putting the fear of god into you the data loss scenario is certainly a possibility but in the most extreme of cases.
|
|
|