1. Attachments are working again! Check out this thread for more details and to report any other bugs.

RSA: Microsoft on 'rootkits': Be afraid, be very afraid

Discussion in 'Fred's House of Pancakes' started by Sufferin' Prius Envy, Feb 20, 2005.

  1. Sufferin' Prius Envy

    Sufferin' Prius Envy Platinum Member

    Joined:
    Jul 7, 2004
    3,998
    17
    0
    Location:
    USA
    Vehicle:
    Other Non-Hybrid
    FEBRUARY 17, 2005 (IDG NEWS SERVICE) - Microsoft Corp. security researchers are warning about a new generation of powerful system-monitoring programs, or "rootkits," that are almost impossible to detect using current security products and could pose a serious risk to corporations and individuals.
    http://www.computerworld.com/securitytopic...1,99843,00.html

    It may be time for people to start adding a sandbox security utility to their computer’s security schema. Firewall and Antivirus programs alone just don’t hack it any more.
    For over two years I have been using a program from Finjan Software called SurfinGuard Pro.
    http://www.finjan.com/products/HomeUsersSu...Pro/default.asp
    This software protects users even from unknown Internet threats by monitoring and containing the behavior of downloaded programs and active content (Active-X, Java, etc).

    Almost every time I use Internet Explorer I get warnings from SurfinGuard Pro. Of course, I am smart enough to limit my usage of IE to only those web sites in which are dumb enough to require IE. If a web site programmer is dumb enough to require you to only use IE, they really shouldn’t be trusted to protect you while visiting their site.

    I have yet to have SurfinGuard warn me while using Firefox. Speaking of Firefox . . . they just recently announced their 25 millionth download.
    http://www.mozilla.org/press/mozilla-2005-02-16.html
     
  2. Canuck

    Canuck Member

    Joined:
    Aug 16, 2004
    605
    2
    0
    Location:
    Vancouver Island,BC,Canada
    Vehicle:
    2011 Prius
    Model:
    Three
    Patrick, not to deminish your alert to us but I think eventually all computers and software will implode into a black hole and we will revive a quaint old system of communicating by quill and paper delivered by horseback. IMHO I think it would be a great world again where we could all slow down and talk to folks but, of course, we would still drive our Prii. :roll:
     
  3. TonyPSchaefer

    TonyPSchaefer Your Friendly Moderator
    Staff Member

    Joined:
    May 11, 2004
    14,816
    2,497
    66
    Location:
    Far-North Chicagoland
    Vehicle:
    2017 Prius Prime
    Model:
    Prime Advanced
    Geez. It's going to be difficult to make computers accessible and friendly to everyone when everyone will need to run a series of spam, antivirus, firewall, and cleanup utilities. Maybe it's time to support my local postal service a little more. At least with snail mail, the only virus I have to worry about is Anthrax.
     
  4. ammiels

    ammiels New Member

    Joined:
    Jan 5, 2004
    121
    0
    0
    Location:
    brewster, ny
    Sorry, bacterium.
     
  5. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    Nothing new about Rootkits, they have existed in one form or another for a *very* long time. With a RTOS, you're usually aware of what threads and processes are running so you can spot anything that doesn't belong.

    However, folks now expect a pretty GUI and a brainless way of interfacing with their computer. Once you turn a gadget like a computer into an appliance, all bets are off.

    For example with Windows XP Pro, click on Start, All Programs, Accessories, System Tools, and System Information. Expand Software Environment and click on Running Tasks.

    With my machine, I see that 43 processes are running. I know what most of them are for, though several are a mystery as I cannot find them at MSDN.

    The Rootkit can effectively hide any process you want to hide from the above procedure, and more cleaver Rootkit processes can even encrypt their processes.

    You could very effectively hide a keystroke logger into this hidden Rootkit to gather credit card numbers or other personal information. So if folks wonder why I'm paranoid about Identity Theft, it's because I know just how easy it is to pull off.
     
  6. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    Never mind Rootkit, Let's not forget if you have a High Speed Internet connection, you can use something like Etherpeek or Snort to snoop out all the users on your domain and/or subnet.
     
  7. mikepaul

    mikepaul Senior Member

    Joined:
    Dec 2, 2003
    1,763
    6
    0
    Location:
    Columbia, SC
    Vehicle:
    2004 Prius
    I make it a point to never use tools that probe outside my firewall. Any day now, RoadRunner will probably announce that as a reason to cancel service. Or worse, forget to announce but cancel anyway...
     
  8. DaveinOlyWA

    DaveinOlyWA 3rd Time was Solariffic!!

    Joined:
    Apr 13, 2004
    15,140
    611
    0
    Location:
    South Puget Sound, WA
    Vehicle:
    2013 Nissan LEAF
    Model:
    Persona
    Tony, u might want to consider the 250,000 pieces of mail that the post office loses EVERY DAY. there is also mail theft which has gained huge popularity around here.

    a few things that help... always drop mail directly into a secured mailbox. never send mail from your home.

    obtw... that does seem like a lot of mail lost, but realize that it still amounts to better than a 99.9% delivery rate... not bad
     
  9. TonyPSchaefer

    TonyPSchaefer Your Friendly Moderator
    Staff Member

    Joined:
    May 11, 2004
    14,816
    2,497
    66
    Location:
    Far-North Chicagoland
    Vehicle:
    2017 Prius Prime
    Model:
    Prime Advanced
    touche
     
  10. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    :lol:

    Geez I missed that the first time through.

    You the man Tony!
     
  11. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    Good point. Here in Canada, Shaw Cable does in fact state it is their policy to immediately suspend your cable internet service *if* they catch you running any snoopware.

    That's a big *if*

    An easy way around that is to use your favorite airsnort to find an unsecured WiFi and then use *that* connection to run snort or etherpeek. Another way around that is to make a point of *not* trying to resolve the DNS numbers you snort up.
     
  12. Sufferin' Prius Envy

    Sufferin' Prius Envy Platinum Member

    Joined:
    Jul 7, 2004
    3,998
    17
    0
    Location:
    USA
    Vehicle:
    Other Non-Hybrid
  13. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    Well, I tried the Revealer. It claimed there was a Data Mismatch with my American Power Conversion UPS monitor. Then the UPS gave a beep and powered down.

    I think I'll wait for a better written Rootkit snooper.
     
  14. DaveinOlyWA

    DaveinOlyWA 3rd Time was Solariffic!!

    Joined:
    Apr 13, 2004
    15,140
    611
    0
    Location:
    South Puget Sound, WA
    Vehicle:
    2013 Nissan LEAF
    Model:
    Persona
    well that leaves me out. i live in an older apartment complex and there is no way i'll run my computer without my UPS
     
  15. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    David:

    Tell me about it. I'm sure you're well aware of what happens when Windows XP has the power yanked. Takes awhile for the tools to clean up the resultant mess. I'm glad I didn't have anything important running when I did that little science experiment.
     
  16. DaveG

    DaveG Member

    Joined:
    Jan 20, 2004
    806
    6
    0
    Location:
    Vancouver, BC
    Vehicle:
    2004 Prius
    Just a quick note that the fine folks at sysinternals have released a free Windows rootkit scanning program:

    Rootkit Revealer

    It's a fairly ingenious scanner that combines a high-level scan (what windows "sees"), with a very low-level scan (that bypasses APIs that are hooked by rootkits), and shows any differences. It will display a few things that are hidden by default in windows to protect users and such, but it's pretty handy to check for other things that try and worm their way in.

    A rather cunning program from some very smart programmers.

    Dave
     
  17. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    <div class='quotetop'>QUOTE(DaveG\";p=\"67203)</div>
    Just too bad it didn't work when I tried it. See my post above. It thought my American Power Conversion UPS monitor was bad, then the UPS powered down, leaving a mess for me when I booted everything back up.
     
  18. Sufferin' Prius Envy

    Sufferin' Prius Envy Platinum Member

    Joined:
    Jul 7, 2004
    3,998
    17
    0
    Location:
    USA
    Vehicle:
    Other Non-Hybrid
    <div class='quotetop'>QUOTE(jayman\";p=\"67021)</div>
    Int'resting! Didn't cause any problems with my PowerChute program.

    No way would I be able to survive without a UPS . . . I have third world power with overhead wires and lots of tall trees in the area which mess with the wires on a regular basis.

    I do have one warning about APC UPSs. Last month I had a Back-UPS Pro 650 fry itself without warning, but not before taking out the power supply on my computer. The only warning was after the fact with a burnt electrical smell, the case was hot to the touch, and the battery was so warped it would not come out. I hate to think what would have happened if I weren’t home! Keep a close eye on yours!
     
  19. jayman

    jayman Senior Member

    Joined:
    Oct 21, 2004
    13,439
    639
    0
    Location:
    Winnipeg Manitoba
    Vehicle:
    2004 Prius
    I only use APC Smart UPS XR's. One is for my security system at the condo and another is for the same duty at the hobby farm. I have a reconditioned Matrix at the hobby farm for my home theater. Lastly, another Smart UPS for the computer.

    I'm running PowerChute Business Edition for Windows XP.
     
  20. DaveinOlyWA

    DaveinOlyWA 3rd Time was Solariffic!!

    Joined:
    Apr 13, 2004
    15,140
    611
    0
    Location:
    South Puget Sound, WA
    Vehicle:
    2013 Nissan LEAF
    Model:
    Persona
    i cant really emphasize how important having a UPS is. power problems are the root of many many seemingly weird computer issues.

    for nearly everyone, its one of the best investments one can make.