0% found this document useful (0 votes)
5 views13 pages

Cyber Security Module 3 Notes

The document discusses keyloggers, spyware, viruses, and worms in the context of cybersecurity. Keyloggers can be software or hardware-based, capturing keystrokes covertly, while spyware collects user information without consent. Additionally, it explains the nature of viruses and worms, their modes of spreading, and the classification of malware, including Trojan horses and backdoors.

Uploaded by

nandansshetty456
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views13 pages

Cyber Security Module 3 Notes

The document discusses keyloggers, spyware, viruses, and worms in the context of cybersecurity. Keyloggers can be software or hardware-based, capturing keystrokes covertly, while spyware collects user information without consent. Additionally, it explains the nature of viruses and worms, their modes of spreading, and the classification of malware, including Trojan horses and backdoors.

Uploaded by

nandansshetty456
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Cyber security unit 3

3.5 Key Loggers and Spy wares

• Keystroke logging, often called keylogging, is the practice of noting (or logging) the
keys struck on a keyboard, typically in a covert manner so that the person using
the keyboard is unaware that such actions are being monitored.
• Keystroke logger or keylogger is quicker and easier way of capturing the passwords
and monitoring the Victims IT savvy behavior.
• It can be classified as Software keylogger and Hardware keylogger

• 3.5.1 Software Keylogger


• Software keyloggers are software programs installed on the computer systems which
usually are located between the OS and the keyboard hardware, and every
keystroke is recorded.
• Software keyloggers are installed on a computer system by Trojans or viruses without
the knowledge of the user.
• Cybercriminals always install such tools on the insecure computer systems available
in public places (i.e., cybercafes, library) and can obtain the required information
about the victim very easily.
• A keylogger usually consists of two files that get installed in the same directory: a
dynamic link library (DLL) file and an EXEcutable (EXE) file that installs the DLL
file and triggers it to work. DLL does all the recording of keystrokes

Some important Keylogger as follows


All in one Stealth Perfect KGB spy Spy Buddy
Keylogger Keylogger Keylogger

Elite Keylogger Cyberspy Powered XPC Spy Spytech


Keylogger spyagent
stealth

3.5.2 Hardware Keyloggers

• To install these keyloggers, physical access to the computer system is required.


Hardware keyloggers are small hardware devices.

• These are connected to the PC and/or to the keyboard and save every keystroke into
a file or in the memory of the hardware device.
• Cybercriminals install such devices on ATM machines to capture ATM Cards PINs. •
Each keypress on the keyboard of the ATM gets registered by these keyloggers • These
keyloggers look like an integrated part of such systems; hence, bank customers are
unaware of their presence.
• Listed are few websites where more information about hardware keyloggers can
be found:
• [Link]
• [Link]
• [Link]
• [Link]
Prepared by:Suraj B S
Cyber security unit 3

3.5.3 Antikeylogger

• Antikeylogger is a tool that can detect the keylogger installed on the computer system
and also can remove the tool.
• Advantages of using antikeylogger are as follows:

1. Firewalls cannot detect the installations of keyloggers on the systems; hence,


antikeylogger can detect installations of keylogger.
2. This software does not require regular updates of signature bases to work effectively
such as other antivirus and antispy programs; if not updated, it does not serve the
purpose, which makes the users at risk.
3. Prevents Internet banking frauds. Passwords can be easily gained with the help of
installing keyloggers
4. It prevents ID theft
5. It secures E-Mail and instant messaging/chatting Note: Visit [Link]
[Link] for more information)

3.5.4 Spywares

• Spyware is a type of malware that is installed on computers which collects


information about users without their knowledge.
• The presence of Spyware is typically hidden from the user;
• It is secretly installed on the user's personal computer. Sometimes, however,
Spywares such as keyloggers are installed by the owner of a shared, corporate or
public computer on purpose to secretly monitor other users.
• Spyware is secretly monitoring the user. Spywares programs collect personal
information about the victim, such as Internet surfing habits/ patterns and
websites visited.
• These program changes the internet settings then the user start complaining about
the speed issues to ISP. Various Spywares are available in the market.
• Anti Spyware software's are available in the market. These have become a common
element now days from computer security practices perspective.

Spywares examples

007 Spy Spector Pro eBlaster

Remotespy: Stealth Recorder Pro Stealth Website Logger

Flexispy Wiretap Professional PC PhoneHome

SpyArsenal Print
Monitor Pro:

3.6 Virus and Worms


• Computer Virus is a program that can “infect” legitimate programs by modifying them
to include a possibly “evolved” copy of itself.
• Viruses spread themselves, without the knowledge or permission of users
• Virus contains malicious instructions that may cause damage or annoyance; the
combination of possibly malicious code with the ability to spread is what that makes
viruses a considerable concern.

Prepared by:Suraj B S
Cyber security unit 3

• A computer virus passes from computer to computer in a similar manner as a


biological virus passes from person to person.
• A virus can start on event driven effects (e.g., triggered after a specific number of
executions), time driven effects (e.g., triggered on a specific date, such as Friday the
13th), or can occur random.

Viruses can take some typical actions:

1. Displays a message to prompt an action which may set of the virus


2. Delete files inside the system into which Viruses enter
3. Scramble data on hard disk
4. Cause erratic screen behaviour
5. Halt the system (PC)
6. Replicate themselves to propagate further harm

Computer virus has the ability to copy itself and infect the system. The term virus is also
commonly but erroneously used to refer to other types of malwares, adware and spyware
programs that do not have reproductive ability.

A true virus can only spread from one system to another (in some form of executable code).
When its host is taken to the target computer, for instance, when a user sent it over the
internet or a network, or carried it on a removable media such as CD, DVD or USB drives.

Malware includes viruses, worms, Trojans, most Rootkits, Spyware, dishonest Adware,
Crimeware and other malicious and unwanted software as well as true viruses.

difference between Virus and Worms

SL Facet Virus Worm


.
No

1 Different Stealth virus, self-modified E-Mail worms, instant


types virus, encryption with messaging worms, Internet
variable key virus, worms, IRC worms, file
sharing, networks worms

polymorphic code virus,


metamorphic code virus

2 Spread Needs a host program to Self-spreading, without


mode spread user intervention

Prepared by:Suraj B S
Cyber security unit 3

3 What is it? Computer virus is a A computer worm is a


software program software program self
that can copy itself and replicating in nature,
infect the data or which spreads through a
information, without the network.
users' knowledge. However,
to spread to another It can send copies through
computer, it needs a host the network with or
program that carries the without user intervention
virus.

4 Inception The creeper virus was The name worm originated


considered as the first from Inception. The
known virus. It was spread Shockwave Rider, a
through ARPANET in the science fiction novel
early 1970s. published in 1975 by
John Brunner.

5 Prevalence Prevalence for virus is very Moderate prevalence for a


high. worm.

3.6.1 Types of Viruses:

Categorized based on attacks on various elements of the system

1. Boot sector viruses: It Infects the storage media on which OS is stored and which
is used to start the computer system. Spread to other systems when shared infected
disks and pirated software's are used.
2. Program viruses: These viruses becom Active when the programs files (usually with
extension .bin, .com, .exe,. ovl, .drv) is executed. Makes copy of itself.
3. Multipartite viruses: It is hybrid of a boot sector and program viruses. It infects
program files along with the record when the infected program is active.
4. Stealth viruses: It camouflages and/or Masks (hides) itself so detecting this virus is
difficult. It can hide itself such a way that anti-virus software also cannot detect it.
Memory to remind in the system and detected. Example of stealth virus is Brain
virus.
5. Polymorphic viruses: It acts like a "Chameleon" that changes its virus signature
(I,e., binary pattern) every time it spread through the system (i.e., multiplies and
infects a new file). Polymorphic generators are routines (small programs) that can be
linked with the existing viruses.

Generators are not viruses but purpose to hide actual viruses under the cloak of
polymorphism. It is difficult to detect polymorphic virus with the help of an
antivirus [Link] Polymorphic generator was the Mutation Engine (MtE).
Other Polymorphic generators are Dark Angel’s Multiple Encryptor (DAME),
Darwinian Genetic Mutation Engine (DGME), Dark Slayer Mutation Engine (DSME),
MutaGen, Guns’nRoses Polymorphic Engine (GPE), and Dark Slayer Confusion
Engine (DSME)

6. Macro viruses: Many applications, such as Microsoft word and Microsoft Excel,
support MACROs (i.e., macrolanguages). These macros are programmed as a macro
Prepared by:Suraj B S
Cyber security unit 3

embedded in a document. Once macro virus gets onto a victim's computer then
every document he/she produces will become Infected.
7. Active X Java control: All the web browsers have settings about Active X and Java
Commands. Little awareness is needed about managing and controlling these
settings of a web browser to prohibit and allow certain functions to work.
8. Which invites the threats for the computer system being targeted by unwanted
software

Examples of The World’s Virus attacks !!!


Conficker INF/AutoRun Win32 Win32/Agent (Trojan)
PSW.
OnLineGa
m es

Win32/FlyStu Win32/Pacex Win32/ [Link]


d io (Trojan .G en Co dec
with Qhost
characteristic
of backdoor)

Worms:

• It is self-replicating malware computer program.


• It uses a computer network to send copies of itself to other nodes and it can transmit
without any intervention
• This is due to security shortcomings on the target computer
• Unlike Virus, it does not need to attach itself to an existing program
• It will almost always cause at least some harm to the network, if only by consuming
bandwidth, whereas viruses almost always corrupt or modify files on a targeted
computer.
• See table 3.3 to know more on World’s worst worm attacks.
• The world's worst virus and worm attacks!
Morris Worm ILOVEYOU Nimda Code Red Melissa

MSBlast Sobig Storm Worm Michelangelo Jerusalemn

Everyday new virus albums are created day be coming you trade to netizens. In spite of
different platforms OS and or applications a typical definition of computer virus or warm
white have the various aspects such as

• A virus attacks specific file types (or files).


• Virus manipulates a program to execute tasks and unintentionally.
• An infected program produces more viruses.
• An infected program may Run without error for a long time

Viruses can modify themselves and may possibly escape detection this way

***************************************

Prepared by:Suraj B S
Cyber security unit 3

Malware and its classification

Malware

• Malware, Short for malicious software, is a software designed to infiltrate a computer


system without the owner’s informed consent.
• The represents a variety of forms of hostile, intrusive or annoying software or program
code.
• It can be classified as follows
• 1. Viruses and worms
• 2. Trojan Horses
• 3. Rootkits
• [Link]
• 5. Spyware
• [Link]
• Keystroke loggers
• Viruses and worms: These are known as infectious malware. They spread from one
computer system to another with a particular behavior
• 2. Trojan Horses: A Trojan Horse, Trojan for short, is a term used to describe
malware that appears, t the User, to perform a desirable function but, in fact,
facilitates unauthorized access to the user's computer system
• 3. Rootkits: Rootkits is a software system that consists of one or more programs
designed to obscure the fact that a system has been compromised.
• [Link]: Backdoor in a computer system (or cryptosystem or algorithm) is a
method of bypassing normal authentication, securing remote access to a computer,
obtaining access for plain text and so on while attempting to remain undetected

• 5. Spyware: Spyware is a type of malware that is installed on computers which


collects information about users without their knowledge.
• The presence of Spyware is typically hidden from the user;
• It is secretly installed on the user's personal computer. Sometimes, however,
Spywares such as keyloggers are installed by the owner of a shared, corporate or
public computer on purpose to secretly monitor other users.

• [Link]: These refers to network of hijacked internet connected devices that are
installed with malicious code known s malware. The infected devices are called as
bots. Hackers remotely controls the

• 7. Keystroke loggers: Keystroke logging, often called keylogging, is the practice of


noting (or logging) the keys struck on a keyboard, typically in a covert manner so
that the person using the keyboard is unaware that such actions are being
monitored.
• Keystroke logger or keylogger is quicker and easier way of capturing the passwords
and monitoring the Victims IT savvy behavior.
• It can be classified as Software keylogger and Hardware keylogger

Prepared by:Suraj B S
Cyber security unit 3

Explain the concept of Computer hoax.


It is a message warning the recipient of a non-existent computer virus threat. The
message is usually a chain E-Mail that tells the recipient to forward it to everyone they
know. They often include announcements claimed to be from reputable organizations
such as Microsoft, IBM or news sources such as CNN and include emotive language
and encouragement to forward the message. These sources are quoted to add
credibility to the hoax. The list of virus hoax can be found at
[Link]

3.7 Trojan Horses and Backdoors

• Trojan Horse is a program in which malicious or harmful code is contained inside


apparently harmless programming or data in such a way that it can get control and
cause harm.
• Get into system from number of ways, including web browser, via E-mail, or with
software download from the Internet.
• Trojan do not replicate themselves but they can be equally destructive
• Examples of threats by Trojans
• Erase, overwrite or corrupt data on computer
• Help to spread other malware
• Deactivate or interface with antivirus and firewall
• Allow to remote access to your computer
• Upload and download files without user knowledge
• Gather E-Mail address and use them for spam
• Slow down, restart or shutdown the system
• Reinstall themselves after being disable
• Disable task manager or control panel
• Copy fake links to false websites, display porno sites, play sounds/videos and
display images
• Log keystrokes to steal info such as password or credit card number.

3.7.1 Backdoors

• It means of access to a computer program that bypass security mechanisms •


Programmer use it for troubleshooting
• Attackers often use backdoors that they detect or install themselves as part of an
exploit
• Works in background and hides from user
• Most dangerous parasite, as it allows a malicious person to perform any possible
action

• Programmer sometimes leave such backdoor in their software for diagnostic and
troubleshooting purpose. Attacker discover these undocumented features and use
them.

What a backdoor does?

1. It allows an attacker to create, delete, rename, copy or edit any file; change any
Prepared by:Suraj B S
Cyber security unit 3

system setting, alter window registry; run control and terminate application; instal
arbitrary software
2. The control computer hardware devices, modify related setting, shutdown or restart
a computer without asking for user permission
3. Steals sensitive personal information, logs user activity, tracks web browsing habits
4. Record Keystrokes that a user types on a computer’s keyboard and captures
screenshots
5. Sends all gathered data to predefined E-Mail address
6. It infects files, corrupts installed app and damage entire system
7. It distributes infected files to remote computers and perform attack against hacker
defined remote hosts.
8. It installed hidden FTP server that can be used by malicious person
9. It degrades Internet connection speed and overall system performance
[Link] provides uninstall features and hides processes, files and other objects to
complicate its removal as much as possible.

Examples of Backdoor Trojans

1. Back office: Enable user to control a computer running the Microsoft windows OS
from remote location
2. Bifrost: Infect Windows 95 through Vista
3. SAP backdoors: SAP is an Enterprise Resource Planning (ERP) system and
nowadays ERP is the heart of the business technological platform.

These systems handle the key business processes of the organization, such as
procurement, invoicing, human resources management, billing, stock management and
financial planning.

1. Onapsis Bizploit: It is the open-source ERP penetration testing framework


developed by the Onapsis Research Labs. Bizploit assists security professionals in
the discovery, exploration, vulnerability assessment and exploitation phases of
specialized ERP penetration tests.

3.7.2 How to protect from Trojan Horses and Backdoors

1. Stay away from suspect websites/web links:

Avoid downloading free/pirated softwares that often Ca by Trojans, worms, viruses


and other things.

2. Surf on the web cautiously:

Avoid connecting with and/or downloading any information from peer (P2P) networks,
which are most dangerous networks to spread Trojan Horses and other threats. P2P
networks create files packed with malicious software, and then rename them to files
with the criteria of common search that are used while surfing the information on the
web.
3. Install antivirus/Trojan remover Software
Nowadays antivirus software(s) have built-in features for protecting the system not
only from viruses and worms but also from malware such as Trojan hoses. Free
Trojan remover programs.
Prepared by:Suraj B S
Cyber security unit 3

3.9. DoS and DDOS Attacks

3.9.1 DoS Attack


• In this type of criminal act, the attacker floods the bandwidth of the victim's network
or fills his E-Maill box with spam mail depriving him of the services he if entitled to
access or provide.
• The attacker typically sites or services hosted on high profile web servers such as
bank credit card payment gateways mobile phone networks and even root name
servers.
• Buffer overflow techniques is employed to commit such kind of criminal attack

• Attacker spoofs the IP address and floods the network of victim with repeated request

• As the IP address is fake, the victim machine keeps waiting for response from the
attacker’s machine for each request
• This consumes the bandwidth of the network which then fails to server the legitimate
responses and ultimately breaks down.

Symptoms of DoS attack

• US Computer Emergency Response Team defines symptoms of DoS attack:

1. Unusually slow network performance (Opening file or accessing websites)


2. Unavailability of a particular website
3. Inability to access any website
4. Dramatic increase in the number of spam E-Mails received [E-mail Bomb].

What DoS attack does?

• Goal of DoS is not to gain unauthorized access to systems or data, but to prevents
intended users of a service from using it. The DoS attack do the following

1. Flood a network with traffic, thereby preventing legitimate network traffic


2. Disrupt connection between 2 systems, thereby preventing access to a service.
3. Prevent a particular individual from accessing a service
4. Disrupt service to a specific system of person

3.9.2 Classification of DoS attacks

• 1. Bandwidth attacks: Loading any websites takes certain time. Loading means

Prepared by:Suraj B S
Cyber security unit 3

complete webage appearing on the screen and system is awaiting user's input.
Loading consumes some amount of memory.
• Every site given with a particular amount of bandwidth for its hosting, say 50GB.
Now if visitor consumes all 50GB bandwidth then hosting of the site can ban
this site.
• The does the same- he/she opens 100 pages of a site and keeps on refreshing and
consumes all the bandwidth, the site becomes out of service.
• 2. Logic attack: These kinds of attacks can exploit vulnerabilities in network
software such as web server or TCP/IP stack.

• 3. Protocol attacks: Protocols are rules that are to be followed to send data over
network. These kinds of attacks exploit specific feature or implementation bug of
some protocol installed at victim’s system to consume excess amount of its
resources
• 4. Unintentional DoS attacks: This is a scenario where a website ends up denied
not due to a deliberate attack by a single individual or group of individuals, but
simply due to a sudden enormous spike in popularity.

3.9.3. Types or levels of DoS attacks

1. Flood attack (Ping flood)

• This is the warliest form of DoS attack and is also known as ping flood. Attacker
sending number of ping packets, using ping command, which result into more
traffic than victim can handle.
• This requires the attacker to have faster network connection than the victim •
It is very simple to launch, but Prevention is difficult

2. Ping of death attack

• The ping death attack sends oversized ICMP (Internet Control Message Control)
packets, and it is core protocol of IP Suite.
• It is mainly used by networked computers OS's to send error messages indicating
datagrams to the victim.
• The maximum packet size allowed is of 65,536 octets. Some system upon
receiving the oversized packet, will crash, freeze or reboot system resulting DoS.

3. SYN attack (TCP SYN flooding)

• In this Transmission control protocol handshaking of network connections is


done with SYN and ACK messages. An attacker initiates a TCP connection to the
server with an SYN (using a legitimate or spoofed source address).

Prepared by:Suraj B S
Cyber security unit 3

• The server replies with an SYN-ACK. The client then does not send back an ACK,
causing the server (i.e., target system) to allocate memory for the pending
connection and wait.
• This fills up the buffer space for SYN messages on the target system, preventing
other systems on the network from communicating with the target system.
Figure 3.5 explains how the DoS attack takes place

4. Teardrop attack

• Teardrop attack is an attack where fragmented packets are forged to overlap


each other when the receiving host tires to reassemble them.
• IP’s packet fragmentation also is used to send corrupted packets to confuse
the victim and may hang the system. This attack can crash various Oss due
to a bug in their TCP/IP fragmentation reassembly code.
• Windows 3.1x, 95 and NT, Linux versions 2.0.32 and 2.1.63 are vulnerable to
this attack

5. Smurf attack

• Generating significant computer network traffic on victim network using foods via
spoofed broadcast ping message
• Attack consists of a host sending ICMP echo request to network broadcast ping
address
• Every host receive this packet and send back ICMP echo response

• Internet relay chat (IRC) servers are primarily victim of smurf attack

6. Nuke:

• An old DoS attack against computer network is consisting of fragmented or


otherwise invalid ICMP packets sent to target.
• Achieved by using a modified ping utility to repeatedly send this corrupt data,
thus slowing down the affected computer until comes to complete stop
• Eg. WinNuke which is exploited the vulnerability in the NetBIOS handler in
windows 95. A string of out of band data was sent to TCP port 139 of victim’s
machine, causing it to lock up and display Blue Screen of Death (BSOD)

3.9.4 Tools used to launch DoS attack

Jolt2: attack against window based machine consume 100% of CPU time on processing
of illegal packets

Nemesy: generates random packets of spoofed source IP


Targa: used to run 8 different DoS attack

Crazy Pinger: send large packets of ICMP


Prepared by:Suraj B S
Cyber security unit 3

SomeTrouble: Remote flooder and bomber developed in Delhi

Blended Threat: It is more sophisticated attack that bundles some of the worst aspects
of viruses, worms, Trojan Horses and Malicious code into one single threat

Use server & Internet vulnerabilities to initiate, transmit and thereafter spread

attack Characteristics:

• Cause harm to the infected system or network

• Propagate using multiple methods as attack may come from multiple point •
Exploit vulnerability

• Server multiple attacks in one payload to use multiple mode of transport rather
than a specific attack on predetermined “.exe” files, it could do multiple
malicious acts, such as modify your “.exe” files, HTML files and registry keys

Permanent DoS attack

• Damages a system so badly that it require replacement or reinstallation of hardware.


• Pure hardware sabotage,
• PhlashDance is a tool created by Rich Smith who detected and demonstrated PDoS.

3.9.5 DDOS Attacks

• In a DDoS attack, an attacker uses your computer to attack another computer • By


taking advantage of security vulnerabilities or weaknesses, an attacker could tack
control of your computer, then force your computer to send huge amounts of data to a
website or send spam to particular E-Mail addresses.
• The attack is distributed because the attacker is using multiple computers to
launch the DoS attack
• Large number of zombie systems are synchronised to attack a particular system.
• Zombie systems are called secondary victims and main target is called primary
victim.

3.9.6 How to Protect from DoS/DDoS Attack

1. Implement router filter, it lessens your exposure to certain attacks.


2. If such filters are available in your system, install patches to guard against TCP SYN
flooding.
3. Disable any unused or inessential network service. This can limit the ability of an
attacker to take advantage of these services to execute a DoS attack.
4. Enable quota systems on your OS if they are available.
5. Observe your system performance and establish baselines for ordinary activity.

6. Routinely examine your physical security with regard to your current needs. 7. Use
tools (eg. Tripware) to detect changes in configuration information or other files 8.
Invest and maintain "hot spares" – Machine that can be placed into service quickly if a
similar machine is disabled.
9. Invest in redundant and fault-tolerant network configuration
Prepared by:Suraj B S
Cyber security unit 3

[Link] and maintain regular backup schedules and policies, fr important


configuration information.
[Link] and maintain appropriate password policies, especially access to highly
privileged accounts such as Unix root or Microsoft Windows NT Administrator.

Prepared by:Suraj B S

You might also like