Showing posts with label browser. Show all posts
Showing posts with label browser. Show all posts

Saturday, 31 March 2012

How Windows pc and Mac systems get infected

Why Windows malware is not posing a threat to Linux system

In this post I will make an attempt to create a synopsis of usual ways malware makes its way into Windows or Mac system. I am referring specifically to Win/Mac because the vast majority of viruses and other malware is created for these two aforementioned Operating Systems, MS Windows being particular favourite of malware writers due to its large share of OS market (that is, if we are not talking mobile phones at this point).
Malware that has been created for Windows pc, is designed for Registry based OS, and neither Linux or Unix is one, therefore, cannot become affected by it (that is one of the few reasons why I absolutely love Linux). Even though malware can affect only OS it has been designed for, there are couple of things often shared by all three most popular computer Operating Systems (as well as those found in majority of mobile smartphones): Adobe Flash and Sun Java. (In case of Linux the use of Adobe product is less common though.) Even though HTML5+DOM coding in website development is expected to eventually make the use of Flash obsolete, currently that is not the case.

Top weaknesses that can cause infection

1. Unpatched security holes.

Operating system, software and its components are always a subject to exploitation because nothing is ever 100% perfect. If latest updates are not installed, the coding and design vulnerabilities in software applications and operating system are posing a risk of being abused by malware writers. Internet browsers, Adobe products, Sun Java, Windows Media Player, Apple Quicktime all have to be updated on regular basis.
Adobe products. Adobe Reader is usually installed with Speed launcher. This feature is loaded during Windows start-up thus prolonging the OS loading and storing the associated .exe file in Applications' folder where it may simply be another useless file which may be exploited during malware attack on the system. By reading this short article you can decide whether you really need this feature. More on Adobe Acrobat Reader related security issues here.
Adobe Flash is another subject to exploitation if not kept updated. Hackers are known to exploit Flash vulnerabilities which can lead to malware infection. When visiting a website that hosts a HTML page which requires a Flash script, users may encounter a malicious Flash redirector, or malicious script written to exploit vulnerability in the Flash Interpreter which causes it to execute automatically in order to infect the computer. Flash vulnerabilities are directly related to Web application and casual online gaming security. More extensive overview on this subject can be found here.
Java, if not kept updated, is the most common way of infecting computer with trojans while browser is rendering a HTML code at some dodgy adult or software cracking tools' website. It must be noted that most exploited vulnerability on such an occasion is previous Java version that has not been uninstalled after the new, updated one has been downloaded and installed. You can check whether you have two Java versions in your Windows pc by going to Control Panel and opening Add/Remove Programs. If you do have two Java updates listed, it is recommended that you uninstall the older one. You can check your system's Java status here.

2. Javascript enabled for all sites.

Regardless of the Web browser you are using, a Javascript can make your system less secure if enabled to run on all sites. The safe way of using Javascript is to enable it exclusively for trusted sites. Javascript is often the cause of malicious redirects to a site with either a malicious content or an intent to boost the incoming traffic.

3. Online game servers.

Because of the design of the online game architecture, firewalls and anti-malware software sometimes can't detect intrusions. That provides an opportunity for hackers to abuse the victim's machine by using online bots and rootkit-like techniques. More info on data and computer security threats related to online gaming can be found here.

4. Torrent, P2P (Peer-to-Peer) networks, File Sharing programs.

Connection to these networks is making the system susceptible to remote attacks and probability of downloading infected, malicious files. That in turn can lead to identity thefts. Malicious worms, backdoor Trojans, IRCBots and rootkits spread across P2P file sharing networks, gaming, dodgy adult and underground sites.

5. Infected files on USB and other storage media.

An Autorun.inf file can cause much trouble. More about this threat and how to avoid it you can read here.

6. Clicking unsolicited links in e-mail and Instant Messenger chats.

For more info as to why such links are being sent and what consequences such actions can have please see my previous posts here and here.

7. Rogue antivirus / antimalware software.

This includes clicking on pop-ups or banners that claim your computer is infected. All about rogues you can read in one of my previous posts here.

8. Backing up infected files.

A logical cause of re-infection.

9. Assuming that antivirus and/or firewall are not needed, or that they are providing 100% protection.

Two extreme assumptions that both can result in computer not being protected against cyber threats. On the first occasion, it is most likely that such a computer's owner won't even get that far as to visit this website to read this article, therefore, I am going to address the second assumption by saying that even protected machines get infected. Otherwise malware writers wouldn't waste their time on doing what they do. Here is an excerpt from Ivizsecurity.com blog:
Security products like anti-virus, firewalls, IDS/IPS and VPN have become of paramount importance to provide highest degree of confidentiality, availability and Integrity (CIA) to individuals and organizations. However, it is foolish to assume that security products are free from any vulnerability (security flaws). Security Products can also be of target of attacks from the attackers.
  By assuming that Anti-virus and Firewall will do the trick of fully protecting the machine, we risk to return to the beginning of this list, e.g. unpatched security holes.

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Thursday, 1 March 2012

Few basic online safety tips for everyone

Yesterday, while going through all the new information on the Internet, I found a useful pdf file that basically covers few things everyone should learn before going on the Internet.
The file has been developed by Citizens Advice Bureau in UK together with Google. It's called Good to Know: How to be safer on the Internet and manage the information you share online. It provides tips on the following:
  • How and why you should create strong passwords for accessing your online accounts;
  • Why you would want to properly log out and shut down your Internet Browser when you've finished with your Internet session;
  • How you can tell a website is safe;
  • What is and how to spot phishing;
  • How to keep your email accounts safe (Click here for a quick guide on how to send an email);
  • How to keep kids safe online;
  • What is IP address and why you should know that;
  • How searching the web works.
You can view and download the file by clicking here.
Here's a suggested watching: few YouTube videos covering basic online safety tips, including but not limited to password creating advice and what things and why you would want to keep private:



Also, you might want to check out one of my other posts here which deals with common ways a Windows/Mac computer gets infected.
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Friday, 10 February 2012

How a banking trojan can steal your data and money

A quick look at Zbot

There are many ways hackers can try to steal personal data from computers. We will take a look at what is known as Zeus to give you the idea of how your banking information can be stolen, so that you know what to be aware of, and how to avoid of becoming a victim.

There is an in-depth analysis of ZeuS Banking trojan to be found at SecureWorks website by authors Kevin Stevens and Don Jackson, Security Researchers from SecureWorks Counter Threat Unit SM (CTU). While it is suggested that you read the whole article, I will post some excerpts here:
ZeuS is a well-known banking Trojan horse program, also known as crimeware. This trojan steals data from infected computers via web browsers and protected storage. Once infected, the computer sends the stolen data to a bot command and control (C&C) server, where the data is stored. ZeuS has evolved over time and includes a full arsenal of information stealing capabilities:
  • Steals data submitted in HTTP forms
  • Steals account credentials stored in the Windows Protected Storage
  • Steals client-side X.509 public key infrastructure (PKI) certificates
  • Steals FTP and POP account credentials
  • Steals/deletes HTTP and Flash cookies
  • Modifies the HTML pages of target websites for information stealing purposes
  • Redirects victims from target web pages to attacker controlled ones
  • Takes screenshots and scrapes HTML from target sites
  • Searches for and uploads files from the infected computer
  • Modifies the local hosts file (%systemroot%\system32\drivers\etc\hosts)
  • Downloads and executes arbitrary programs
  • Deletes crucial registry keys, rendering the computer unable to boot into Windows
  •  
How to detect the ZeuS Banking Trojan on your computer
Computers infected with this version of ZeuS will have the following files and folders installed. The location depends on whether the victim has Administrator rights. The files will most likely have the HIDDEN attribute set to hide them from casual inspection.
With Administrator rights: 
%systemroot%\system32\sdra64.exe (malware)%systemroot%\system32\lowsec%systemroot%\system32\lowsec\user.ds (encrypted stolen data file) %systemroot%\system32\lowsec\user.ds.lll (temporary file for stolen data) %systemroot%\system32\lowsec\local.ds (encrypted configuration file)
Without Administrator rights: 
%appdata%\sdra64.exe%appdata%\lowsec%appdata%\lowsec\user.ds%appdata%\lowsec\user.ds.lll%appdata%\lowsec\local.ds 
ZeuS also makes registry changes to ensure that it starts up with Administrator privileges:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinlogonFrom:"Userinit" = "C:\WINDOWS\system32\userinit.exe"To:"Userinit" = "C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe"
Without Administrator rights:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunAdd:"Userinit" = "C:\Documents and Settings\<user>\Application Data\sdra64.exe" 
The sdra64.exe program uses process injection to hide its presence in the list of running processes. Upon startup, it will inject code into winlogon.exe (if Administrator rights available) or explorer.exe (for non-Administrators) and exit. The injected code infects other processes to perform its data theft capabilities.

How your system can get infected

There is a list of ways your system can get infected to be found in one of my other posts here. Things you really should watch out for, and avoid, are emails supposedly sent from your bank where you are asked to follow a certain link in order to update your security details, or to download a file attached to the e-mail message. Here are few samples of such e-mail messages:

Dear Customer,
We detected irregular activity on your
Internet banking account.
For your protection, you must verify this
activity before you can continue using your
account.
Please download the document attached to this
email to review your account activity.
We will review the activity on your account
with you and upon verification, we will remove any restrictions placed on
your account.
If you choose to ignore our request, you leave us no choice
but to temporary suspend your account.
We ask that you allow at least 72 hours for the case to be
investigated and we strongly recommend to verify your
account in that time.
© Copyright Barclays Bank Holdings plc 2012 - All rights reserved


and

Dear Valued Customer,
Your account is suspended due to the number of incorrect login attempts.
For your protection, we've suspended your account .
To reactivate your account please download the document attached to this
e-mail and review your account activity.
If not completed until February 09, we will be forced to close your account .
Note: If you received these e-mail in your BULK/SPAM section please
add to your address book [e-mail address withdrawn]

Thank you,

Customer Support Service.

Copyright © NatWest Bank Plc. Limited. All rights reserved.


On both occasions senders obviously have made an opportunistic attempt to get me into downloading their malicious HTML files attached to messages without knowing that I'm not a customer of either of aforementioned banks.
So, what would have happened if I'd downloaded the attached file? I would most likely have infected my machine with a trojan bot spyware that would be capable of sending data from my computer to a remote server on the Internet, controlled by a cyber criminal, and basically making my machine a part of a botnet.
Or, if there would have been a link to follow, then, by clicking it, I would most likely have ended up on some bogus website designed by a cyber criminal for malicious purposes such as pharming (URL redirections with purpose of information stealing) or spreading malware infections. Example of a phishing message:

Dear Valued Customer,
our security filter noticed a malicious activity in your online account.
We were able to trace it to an unknown link thereby, placing
your online banking on suspension till this is resolved.
We implore you to go over your account details so
as to continue with your online transactions.
Click here to resolve the problem.
[Link withdrawn]

Thank you for helping us to render you a maximum protection.

Security Department.

Alliance-leicester online banking.


Things to keep in mind

Regardless of the content of the message, remember: banks will not ask you for any security details or security updates via e-mail. Don't just click on links in emails you receive from someone. Make sure the sender is trusted and genuine, and the link does not look dodgy. (The same applies to Instant Messenger chats.) If you receive a suspicious email supposedly sent from your bank, and you are asked to proceed with giving away any of your personal or financial details, or to download an attachment, don't. Instead, forward the email message to the bank. Almost on all occasions you can find e-mail address for forwarding phishing emails to at the bank's official website. For more detailed information on types of scams related to Online banking, and to get a genuine advice, please visit Bank Safe Online, a website developed by UK Payments Administration Ltd.

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Wednesday, 8 February 2012

Speed up and secure your Web Browser

One excellent way to make your Windows (or Mac or Linux) computer more safe for the Internet browsing is to manage what is called the Hosts file. That does not mean that you would have to understand programming or anything like that. It's actually pretty simple: on your computer you just go to where your Windows Hosts file is, and either, copy+paste new content into it, or replace the file with a new one. It is easy to do yet also requires careful attention while performing the process of changing the file: Hosts file is not something you want carelessly play around with.

Before we proceed to actual way of dealing with Hosts file, I will explain what is the point of changing it, so you can figure out yourself if you actually want to do that.
You most definitely want to update your Hosts file if you:
  • don't like dozens of advertisements displayed on pages you are browsing. If that is the case then updating your Hosts file the way I am about to advise will let you get rid of majority of annoying ads on Internet pages by simply not loading those ads.
  • want to keep the number of malicious websites (those containing malware and browser hijackers) you risk to open to a minimum.
  • don't want to be secretly tracked by some Internet ad providers who try to follow visitors' actions and see what other sites they are visiting.
Changing your Hosts file will block your computer's connection to any of the sites that are correctly listed in this file.
For instructions and more details visit this site: http://winhelp2002.mvps.org/hosts.htm The procedure is harmless and doesn't require any additional software. Speaking in terms of TV adverts: Ever since I have discovered this method, my computers' (both, Windows and Linux) Hosts file is always up to date with the content provided by Winhelp2002 website. No more forever loading ads, no more strange, slow loading pages, no more strange behaviour by my Web Browsers.

Download and test these products for free for 30 days:

Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall