Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Anti Spyware Malware » Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits

Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits

Category: Anti Spyware Malware
Published: 04/02/2007, 21:24  
Editor: Remus Zoica
 
Print article
Send to a friend
Search in reviews
    Itelligent Business Research Services analyst James Turner said rootkits will be increasingly used in highly targeted attacks as they become more sophisticated and form a critical part of hacker arsenals. Turner stated: "We are going to see rootkits used in highly targeted attacks where hackers will source, for example, a CFO's operating system and the typical applications they use, and then find a specific vulnerability based on these which allows a rootkit to be inserted."

    A rootkit is a set of software tools intended to conceal running processes, files or system data from the operating system. Rootkits have their origin in relatively benign applications, but in recent years have been used increasingly by malware to help intruders maintain access to systems while avoiding detection. Rootkits exist for a variety of operating systems, such as Linux, Solaris and versions of Microsoft Windows. Rootkits often modify parts of the operating system or install themselves as drivers or kernel modules. Rootkits can be classified as; kernel-mode, which intercept kernel interface calls and alter OS kernel data to conceal rootkits from process lists; persistent, which use the system registry to execute on boot; user-mode, which can use keyloggers and infect or masquerade as OS commands; and memory-based, which rely on manual user execution to operate.

    The security infrastructure is heating up through increased education and simulations of information security warfare. The biggest problem remains: how to get people who have been hacked to warn the public about it. Chris Gatford, senior security analyst at penetration testing firm Pure Hacking, sais that the most critical exploits can be found in unpatched in common applications.
Gatford said: "Microsoft Word has an unspecific exploit that has been unpatched for 47 days; if I were a hacker I would certainly target these kinds of exploits because the scope is so wide. Hackers are using the same spyware model but are distributing them with the next-level of rootkits."

In addition, Markets-Alert director Jeff McGeorge, said: "Rootkits are being dynamically inserted on-the-fly which means they can sit invisibly in a Web page's source code using a Windows cloaking function, and download on to your machine without raising any attention because they disable download warnings and spyware applications from flagging them. A TPM takes an initial encrypted sumcheck of a hard drive and crosschecks the result against the TPM chipset on each boot, which detects additions to the kernel. However TPMs don't work against dynamically inserted rootkits because you can't do a sumcheck against the TPM when you are on the Internet and surfing around which is where the rootkits install, infect and uninstall. There will never be a universal rootkit detector however the most powerful alternatives will be online-offline comparison scanners that integrate with anti-virus programs."

Bookmark to:
Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Del.icio.us Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to digg Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to FURL Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to reddit Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Technorati Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Yahoo My Web Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Stumble Upon Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Google Bookmarks Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to RawSugar Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Squidoo Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Spurl Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Netvouz Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Rojo Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Bloglines Add 'Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Trojan, Spam and Malware Protection Software Cannot Prevent System Compromise by Sophisticated Rootkits
 

SPAMfighter - community spam filter
 SPAMfighter Now 2 Million Strong and Still Growing. Now with over two million users,SPAMfighter is at it's strongest against the war on spam.
Read More >
01/09/2007, 10:05
 

Webroot Software Expands the Distribution of Webroot® Spy Sweeper® Enterprise and Webroot SME Security to Canada
 This new parthnership demonstrates Webroot’s commitment to expand the accessibility of its award-winning products on a global basis.
Read More >
06/12/2007, 22:12
 

Microsoft becomes a victim to hidden 'scareware'
 Microsoft said it moved quickly to remove a banner advertisement that was appearing on its instant-messaging program for a software application that falsely agitates security threats on a user's operating system.
Read More >
02/24/2007, 02:19
 

PC World's '101 Fantastic Freebies' List Names SPAMfighter
 SPAMfighter was honored in the May 2008 issue of PC World as one of the “101 Fantastic Freebies.” The article, which features the editors’ top 101 picks of online services and downloadable software in various categories ranging from Security to Video and Photo, and provides information to help keep you secure, productive, and entertained, is live at http://www.pcworld.com and will be available on newsstands April 15.
Read More >
04/02/2008, 10:37
 

The difference between spyware and a virus
 I have done all the seven steps that you provided, but my computer is still "infected"!
Read More >
12/08/2006, 11:01

Sponsored