Find White Papers
Home
About Us
List Your Papers
    
> Perimeter > The Book On Malicious Websites

The Book On Malicious Websites

White Paper Published By: Perimeter

Before Microsoft released Microsoft XP Service Pack 2 (SP2), most attackers would compromise a computer system by simply attacking it with known vulnerabilities or "bugs" that could allow the attacker to gain some level of control over the system. Newer attack methods were starting to be seen where the attacker would take advantage of vulnerabilities within the Internet browser itself.



Tags : 
virus, anti-virus, anti virus, spyware, windows xp, xp sp2, intrusion detection, ids

Perimeter
Published:  Jul 17, 2007
Type:  White Paper
Length:  5 pages





MALICIOUS WEBSITES Kevin Prince Chief Security Officer Perimeter eSecurity February 2007

Page 1 of 5 In August 2004, Microsoft released Microsoft XP Service Pack 2 (SP2). This marked a significant date in the network security world. The largest software provider in the world had released a version of their operating system (OS) that had built in security turned on by default. The next several weeks and months were interesting as many dependant software applications "broke" when the security features were tightened up. But all things said and done, it was a great milestone in security, and although it was a rough road, it was a long time in coming. Security enhancements included a major revision to the internal firewall which was renamed to Windows Firewall, advanced memory protection that takes advantage of the NX bit that is incorporated into newer processors to stop buffer overflow attacks, and removal of raw socket support (which supposedly limits the damage done by "zombie" machines: infected computers that can be used remotely to launch denial of service attacks). Additionally, security-related improvements were made to e-mail and web browsing. Windows XP Service Pack 2 includes the Windows Security Center, which provides a general overview of security on the system, including the state of anti-virus software, Windows Update, and the new Windows Firewall. Third-party anti-virus and firewall applications can interface with the new Security Center. These modifications to the worlds most popular OS shocked the hackers of the world. No longer would it be very easy to attack and compromise systems. No longer were there more open systems than they had time to compromise. Attackers would scour the Internet looking for open systems, and when found, would quickly close the holes so another attacker couldn't claim what they had rightfully stolen. Don't get me wrong, I said no longer was it "very" easy. Now it is just sort-of easy. Much of this is due to computer systems being brought online in other countries where there is a lot of pirated software, and other older OS's that don't have security features enabled. There are also a lot of older computer systems right here in the USA that are still using OS's older than XP SP2. Lastly, even with security turned on, there are other ways of having a system be vulnerable. But because most of the systems or information that had the highest value to
Page 2 of 5 hackers had become more secure, they were required to get creative in their attacks. In 2005 we saw the beginning of a movement towards an entirely new type of attack method. Until then, most attackers would compromise a computer system by simply attacking it with known vulnerabilities or "bugs" that could allow the attacker to gain some level of control over the system. These are commonly referred to as "inbound attacks". With personal firewalls loaded onto many systems, as well as other security features enabled, the "inbound attack" approach became increasingly less profitable. New attack methods started being seen where the attacker would take advantage of vulnerabilities within the Internet browser itself. These vulnerabilities would allow the attacker to download malicious code, Trojan horses, or other applications in the background simply by having the user look at a web page. Some of the new attack methods included luring unsuspecting users to malicious web sites via SPAM, instant messaging, or popular web sites. In one case, an attacker created a Katrina Relief web site. The site was good, giving up-to-date storm watch information, video's of survivors, even links to real donation sites. This web site was indexed by several search engines and quickly became one of the top links when typing "Katrina" into a search web site. Just by clicking the link, a malware program was installed onto the users PC. Malware programs can do things like: crash your system, keystroke (password) capture, screen shot capture, or give full remote control. What people don't realize is that the software makes an OUTBOUND connection to the Internet. Because the internal computer is making the request (connection) out to the Internet, it is assumed by the security systems to be "authorized" traffic. The PC's can make connections back to the attackers systems and they can do just about anything they want. This defeats a... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search