Showing posts with label General. Show all posts
Showing posts with label General. Show all posts

Tuesday, June 29, 2010

Malware and its Classification

Malware

Malicious Software (Malware) is a software designed to damage or do other unwanted actions on a computer system. The term 'Mal' refers to Bad and hence its a bad software. Previously Malwares were just pranks, but these days they are completely "Profit Oriented".

The types of malwares can be broadly classified into, 
  1. Infectious malware (viruses and worms)
  2. Concealment malware (Trojan horses, backdoors, and rootkits)
  3. Profit Oriented malware (adware & spyware and botnets)
  4. Exploits
VIRUS
Virus is a program designed to spread its code to all system files. Virus may have payload which performs malicious activities.

Examples : 
  • Virus.Win32.Sality
  • Virus.Win32.Virut
WORM
Worm is a self-propagating malicious code which transmits itself over a network to infect other computers. Unlike virus worms do not infect a file or program, but rather stand on their own. Worm too may have payload which performs malicious activities. Worm can be again classified into :
  • Email Worms - It spreads via E-Mail messages. It can be a link or an attachment in an E-Mail Message
  • Instant Messaging Worms - It spreads via Instant Messagin messages.
  • Internet Worms - It will scan all the network resources of the local machine to attack and gain full access through internet.
  • IRC Worms - It spreads via chat channels.
  • Networks Worms - It copies itself to all shared folders in the network.
Examples : 
  • Net-Worm.Win32.Allaple
  • Worm.Win32.AutoRun
  • IM-Worm.Win32.Sumom
TROJAN HORSE
This is the most dangerous malware. By the name, It hides its malicious code inside a software which appears as an useful or harmless software like the astute Greeks in their attack on Troy. Trojan horses can be again classified into :

  •  Trojan Clicker - It silently runs in the background and connects to a predetermined website to increase the vote counter.
  • Trojan Downloader - It connects a remote server in order to download additional malware onto a users computer without their knowledge.
  • Trojan Dropper - It drops malicious file and run it on the compromised computer.
  • Trojan IM - It relies on instant messenger client application to do Malicious activity.
  • Trojan Notifier - It is capable to notify remote client with the details of its installation on the current system.
  • Trojan Proxy - It sets the local computer as a proxy server, allowing others to connect to the computer.
  • Trojan PSW - It Steals passwords, login details and other information.
  • Trojan Spy - It attempts to monitor keyboard stroke activities made by users of the affected system in hopes to gain essential personal information.
  • Trojan Dialer - It used to dial a high-cost international phone number using a modem without the users permission or knowledge.
Examples : 
  • Trojan-Clicker.Win32.Stixo
  • Trojan-Dropper.Win32.Drooptroop
  • Trojan-Downloader.Win32.Mufanom
Backdoor
Backdoor by name is a method of opening backdoors for unauthorised attackers to get complete access of the system.This method bypasses usual authentication for remote access to victim PC.

Examples : 
  • Backdoor.Win32.IRCBot
  • Backdoor.Win32.Rbot
  • Backdoor.Win32.Hupigon
Rootkits
It is the hardest of all malwares to detect and remove. It camouflage itself in a system's core processes so as to go undetected. Rootkits are basically meant to help hackers. It hides resources such as processes, files, registry keys, and open ports that are being used by the malicious purpose.

Examples :
  • Rootkit.Win32.TDSS
  • Rootkit.win32.bubnix
Adware & Spyware
Its a software which automatically displays, plays or download Advertisements to the computer where it is installed. Spyware are also type of adwares which collects bits of information without their knowledge. Spyware such as keyloggers are also used by corporates in order to secretly monitor other users.

Examples :
  • AdWare.Win32.Mirar
  • Adware.Win32.Ardamax
Botnets
Botnets are becoming a major tool for cybercrimeDOS attack. Botnets, or “Bot Networks,” are made up of vast numbers of compromised computers (Zombies) that have been infected with malicious code, and can be remotely-controlled through commands sent via the Internet. Then the spammer purchases this service of the botnet and provide spam messages to Zombies. In some cases botnets are used for DDOS attack.

Examples :
  • Conficker
  • Kraken
Exploits
Exploit is a piece of software or commands that take advantage of a bug or vulnerability to perform malicious activity. These exploits are due to Buffer Overflows.

Buffer Overflows - If a programmer wants to put ten bytes of data into a buffer that had only been allocated eight bytes of space, that type of action is allowed, even though it will most likely cause the program to crash. This is known as a buffer overrun or buffer overflow.

Examples :

  • Exploit.Win32.MS04-028
  • Exploit.Win32.Pidief


    Monday, June 28, 2010

    Windows Startup - A Weapon for Malwares

    Hey guys have you ever thought that why “Msn Messenger” or “Yahoo Messenger” or any other software open as your Windows starts?????
    This is due to “Windows Startups”

    Even malwares uses this facility to run every time Windows starts.It's a good practice to frequently inspect the startup entries for security.Now lets see how it works......

    Startup using Windows Registry
    Before saying about “Windows Startups” will give you a brief introduction to “Windows Registry”

    Every OS needs place to store settings and options. Windows Registry is a database where Windows OS stores all configuration settings and user preferences. It contains information and settings for all the hardware, software, users, and preferences of the PC. It stores different kinds of data in a hierarchical manner. You cannot edit this database directly, you must use "Registry Editor" to make any changes.


    To open "Registry Editor" type “regedit” in Run command.



    You will notice five subtrees(HIVE), which appear as follows:
    • HKEY_LOCAL_MACHINE
    • HKEY_CURRENT_USER
    • HKEY_CURRENT_CONFIG
    • HKEY_USERS
    • HKEY_CLASSES_ROOT
    Following registry entry are used for Windows Startup  :

    HKCU - HKEY_CURRENT_USER
    HKLM - HKEY_LOCAL_MACHINE
    • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    • HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    • HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
    • HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    • HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
    • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows :"Load" [VALUE]

    • HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
    • HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    • HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    • HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

    • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

    • HKLM\Software\Microsoft\Active Setup\Installed Components
    • HKCU\Software\Microsoft\Internet Explorer\Main, Start Page [VALUE]
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    • HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
    • HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs [VALUE]
    • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, UserInit [VALUE]
    • HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, BootExecute [VALUE]
    Here is an example for "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"
          1. Type “regedit” in Run command.

         2. Click [+]HKEY_CURRENT_USER

          3. Click [+]Software then [+]Microsoft then [+]Windows then [+]CurrentVersion

         4. Finally Click on Run.

    Malwares can use such facility and start next time windows reboot...There are third party softwares available which shows all startups entries and ease your work.One of them is"Autoruns for Windows v10.01"

    This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them.

    Caution:
    Do NOT delete or disable the entry named Userinit. Doing so will result in your inability to logon to any user account in the system.

    Sunday, June 27, 2010

    Common Security Tips

    Common Security Tips to Keep You Safe :-)

    Use an Anti-virus software
    Be sure to keep your anti-virus software up-to-date. Many anti-virus packages support automatic updates of virus definitions. We recommend the use of these automatic updates when available.

    Use a firewall
    I strongly recommend the use of some type of firewall product, such as a network appliance or a personal firewall software package. Intruders are constantly scanning home user systems for known vulnerabilities. Network firewalls (whether software or hardware-based) can provide some degree of protection against these attacks. However, no firewall can detect or stop all attacks, so it’s not sufficient to install a firewall and then ignore all other security measures.

    Avoid phishing
    Always trust only yourself. It’s not too hard to type the address of online banking site on the address bar. Please DO NOT access online banking site via the link in your email or some untrusted sources.

    Unknown email attachments
    Before opening any email attachments, be sure you know the source of the attachment & also scan the file using your anti virus software.For additional protection, you can disconnect your computer's network connection before opening the file.


    Unknown programs
    Never run a program unless you know it to be authored by a person or company that you trust. Also, don't send programs of unknown origin to your friends or coworkers simply because they are amusing -- they might contain a Trojan horse program.


    Disable hidden file name extensions
    Windows operating systems contain an option to "Hide file extensions for known file types". The option is enabled by default, but you can disable this option in order to have file extensions displayed by Windows.
    To disable hidden file name extensions follow these steps:
    1. Click Start > Control Panel.
    2. Double-click Folder Options.
    3. Select the View tab.
    4. Scroll down in the list and uncheck "Hide Protected operating system files" and check "show hidden files and folder".
    5. Click OK.
    Password tips
    DO NOT use the same password in ALL your online accounts. If you do and one of your accounts got hacked, hacker will be able to access all your other accounts.
    Try to avoid using dictionary words like “prettygirl”, “imagination” etc or any other stuff that’s easy to guess (like your birth date, your car plate number)
    Password is case sensitive, choosing passwords that are composed by different case will add more strength to the security (for example, StRonG_pAss).
    DO NOT disclose your password to anyone, even if the person claimed he/she is working for the bank or is the site admin.

    Beware of Social Media Sites
    Do not click on links in social media sites such as Twitter, Facebook or MySpace that don't look right.
    Patch all applications, including your operating system
    Keeping your OS updated is very important in keeping it secured from exploitation, and so should never be overlooked.Vendors will usually release patches for their software when a vulnerability has been discovered. Most product documentation offers a method to get updates and patches. You should be able to obtain updates from the vendor's web site.

    Disable Simple File Sharing
    Simple File Sharing allows users to share folders without a password and may allow malicious attackers to read or write files from your shared folders.Windows XP allows you to disable Simple File Sharing and require a user id and password for shared folder access.
    To disable Simple File Sharing follow these steps:
    1. Click Start > Control Panel.
    2. Double-click Folder Options.
    3. Select the View tab.
    4. Scroll down in the list and uncheck "Use simple file sharing".
    5. Click OK.
    Secure Your Accounts and Passwords
    You must establish effective passwords for all active accounts. Existing accounts with weak or nonexistent passwords are an invitation for malicious attackers to compromise your system.To disable any unused accounts such as "Guest" and to verify that an effective password is set for the Administrator account, follow these steps:

    1. Click Start > Control Panel.
    2. Double-click User Accounts.The User Accounts dialog box appears.
    3. Select the User Account you want to set a password for (e.g., Administrator).
    4. Click Change the password and enter your old and new password.
    5. To disable a Guest account, select it in the dialog box and click Turn off the guest account.

    Welcome to My Blog!!!!

    Hey buddies, I have started this blog to spread my knowledge regarding computer security...I would like to share knowledge about following stuffs....
    • Security Tips
    • Types and Purpose of Malwares
    • New and Latest Malwares
    • Reverse Engineering (Static and Dynamic analysis)
    • File Packers (Eg: Upx, Aspack, PeCompact....)
    • File Crypters and Protectors
    • Malwares Removal Techniques
    • Analyst Tools
    This is all I have in my mind...It wont End here...If u feel i have missed something let me know by comments...Lets be doctors of computers and remove all virus and malwares our self...