IPB

ISO Image Creator | Cheap EQ2 gold - Buy EQ2 gold, EVE ISK, EQ Plat and more!

Welcome Guest ( Log In | Register )

2 Pages V   1 2 >  
Reply to this topicStart new topic
> Security Focus: Rootkits, Spyware is not bad enough
bfarber
post Apr 20 2005, 05:45 AM
Post #1


Administrator
Group Icon

Group: Admin
Posts: 10,302
Joined: 9-February 03
From: Jacksonville, FL
Member No.: 1
 United States


Just when you thought you had seen it all...

A recent article I read in PC Magazine prompted me to research this a bit online, and well, frankly it's scary.  There is a tool that up until recently was more commonly seen in the Unix community, called rootkits.  These malicious tools are not generally harmful by themselves, but are coupled with Trojans to do some devastion to systems and you would  never even know, regardless of how many umpteen tools you run a day.  Read on...

Applications run on your computer by making calls to certain API's to do some common functions.  For example, a directory listing.  It's just not feasible to have developers run low-level system calls to get a directory listing, when they can just hook into an API the system provides.  It's used by all programmers, as it's just required to properly code.

A rootkit is a utility that when installed on a system (usually without your permission and knowledge), it will essentially intercept those API calls, manipulate the data (for example, to remove it's name from a directory listing, and to modify the number of files in the directory afterwards), and then return the data to the requesting party.  While this isn't harmful in itself, and they don't hurt resources, one common usage of rootkits is to couple them with Trojans so that you never know the Trojan is there.  The worst thing...A/V and Malware/Spyware scanners do not pick up rootkits, and when properly implemented, cannot pick up on files that the rookit is hiding.

Scary, huh?
Here are some reference points I found, links to programs that CAN detect rootkits, and sites that have more information on the subject in general.  Please note that we have no control over the content of these sites and are providing links as an educational experience only.  Also please note that most of the utilities that you can download to detect and remove rootkits are completely free (at this time):

  • http://www.rootkit.com/index.php  <-- You can download rootkits here
  • Go to the top of the page
     
    +Quote Post
    Widescreen
    post Apr 20 2005, 05:57 AM
    Post #2


    God of the Forums
    Group Icon

    Group: Members
    Posts: 4,237
    Joined: 15-February 03
    From: Leicester, England.
    Member No.: 7
     United Kingdom


    unsure.gif
    Go to the top of the page
     
    +Quote Post
    horai
    post Apr 20 2005, 05:02 PM
    Post #3


    Advanced Member
    Group Icon

    Group: Advanced Members
    Posts: 632
    Joined: 8-August 03
    From: Derbyshire, England
    Member No.: 2,272
     United Kingdom


    That's just plain scary.  I'm really beginning to hate some people.
    Go to the top of the page
     
    +Quote Post
    bfarber
    post Apr 21 2005, 08:26 AM
    Post #4


    Administrator
    Group Icon

    Group: Admin
    Posts: 10,302
    Joined: 9-February 03
    From: Jacksonville, FL
    Member No.: 1
     United States


    Quite amazing huh. Oddly enough, even though I work in the IT industry (server tech support), I'd never heard of these before.

    Neither had the guy I worked with who has A+, Net+, AND Security+

    blink.gif
    Go to the top of the page
     
    +Quote Post
    azn_gangsta
    post Apr 24 2005, 05:37 PM
    Post #5


    Newbie
    Group Icon

    Group: Members
    Posts: 5
    Joined: 18-August 04
    From: Grand Rapids, MI
    Member No.: 18,375
     United States


    My old host got rootkitted. Lost my whole site. Thank god I installed an automatic backup script.
    Go to the top of the page
     
    +Quote Post
    phatnanna
    post Aug 30 2005, 06:51 PM
    Post #6


    Newbie
    Group Icon

    Group: Members
    Posts: 2
    Joined: 28-March 05
    Member No.: 30,586
     United States


    Im not very computer savvy but this sounds scary and after reading some of this Im frozen with fear as to what to do to do anything about this problem or even to find out how i have it, im afraid to download any thing to even begin to fix it that may be a virus or something even crazier what is a computer dummy to do?
    Go to the top of the page
     
    +Quote Post
    mflintjer
    post Sep 1 2005, 12:29 AM
    Post #7


    Back; Down you Hooligans! :P
    Group Icon

    Group: Members
    Posts: 1,012
    Joined: 2-November 04
    From: Rochester, MN
    Member No.: 23,596
     United States


    Well, I do know one thing -- this ain't cool! It is quickly becoming a world without end of viruses, and endless amounts of cash coming out of our wallets/purses to buy anti-virus/spyware/malware -- now ROOTKIT!!

    Another thing I know, I work for Charter Communications -- Owned by one of the founding fathers of -- dare I say in horai's presence? -- MICROSOFT!! As a "benefit" of paying for our 3 or 5 Mb service, you get the "Charter High Speed Security Suite" for free. Now this suite is partnered with f-secure -- one of the sites that BF listed.

    Here's where it gets interesting -- My buddy owns a DELL -- sick.gif And his woman also works at Charter, and she SWEARS by this security suite!! In the past few weeks, I have run this anti-virus 5 times. Each time, it finds, ON AVERAGE, 6 viruses!!!!! They used to have MacAfee, and she used to SWEAR by that. Honestly, she doesn't know whether to shiot or go blind!! She is about as daft about computers as they come. The only thing with her is, she THINKS she knows alot about computers.

    I have used MacAfee on my system for more than a year now, and have never had an y viruses make it through. I should digress, I did have it happen once -- when I activated WinXP over the internet, BEFORE I installed MacAfee!!

    That in conjunction with "Zone Alarm Pro" -- I can honestly say that I have not had any problems.

    Now, back to the topic at hand -- F-Secure -- I'm not so sure their products are all what they are hyped up to be!! Yes, I work at this company (Charter), They push this product (made by F-Secure) -- You will NEVER catch me pushing this product on ANY customer wink.gif UNLESS, I have THOROUGHLY tested it, and re-tested it to assure its worthiness.

    Like BF stated, those products may or may not work. It's up to you to decide if you want to try them out and see. Thanks BF for those links, and I will do a little research on them from my end! thumbsup2.gif
    Go to the top of the page
     
    +Quote Post
    bfarber
    post Sep 8 2005, 07:26 AM
    Post #8


    Administrator
    Group Icon

    Group: Admin
    Posts: 10,302
    Joined: 9-February 03
    From: Jacksonville, FL
    Member No.: 1
     United States


    No problem.

    To add to the antivirus talk, I used Norton for the longest time, until my friend turned me onto avast for 2 very important reasons

    1) It's FREE (completely)
    2) In testing it uses a LOT less resources (don't have exact numbers, but Norton used up like 5% of my CPU at any given moment spread across it's processes....avast uses less than 1%...and the memory usage is drastically lower as well)

    I would recommend avast to anyone at this point. I tried (when I reinstalled XP) to reinstall a Key Logger on my pc (I like to always know what's going on with my pc) and I couldn't even do it. laugh.gif Could with Norton, no problem...not with avast though.
    Go to the top of the page
     
    +Quote Post
    NickTheGreek
    post Sep 8 2005, 07:15 PM
    Post #9


    Newbie
    Group Icon

    Group: Members
    Posts: 10
    Joined: 23-July 05
    Member No.: 36,710
     Greece


    ues, i have read it in PC MAG 2 months ago... but it is not so serious. i mean, it is a serious threat but not reallycompared to trojans and especially spyware & keyloggers...

    anyway, i use F-Secure Blacklight it is a perfect choice for rootkit detection
    Go to the top of the page
     
    +Quote Post
    mflintjer
    post Sep 9 2005, 12:19 AM
    Post #10


    Back; Down you Hooligans! :P
    Group Icon

    Group: Members
    Posts: 1,012
    Joined: 2-November 04
    From: Rochester, MN
    Member No.: 23,596
     United States


    thanks for the info BF -- found a nice (IMHO really nice) anti-spyware called "Ewido Security Suite 3.5". I did a scan with it, and it caught, literally, more than 300 spyware files that McAfee missed!! ohmy.gif hmm.gif

    I want to try out Avast -- any links to it BF!? thumbsup2.gif
    Go to the top of the page
     
    +Quote Post

    2 Pages V   1 2 >
    Reply to this topicStart new topic
    1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
    0 Members:

     

    Lo-Fi Version Time is now: 25th July 2008 - 11:01 AM

      Page top

    Webber Enhanced skin created by Im4eversmart of RuneHQ.

      Webmasters     Cool Sites     Money Network     Privacy Policy