On TV.com: KIM KARDASHIAN is hot hot hot

Search:
Go!




Click Here
Security Watch : Don't get burned by viruses and hackers
Targeted Web attacks
By Robert Vamosi 
Senior editor, CNET Reviews
July 1, 2005

Forget the notion of a lone script kiddie sitting at a computer, launching wide-scale attacks on random computers around the world. Now that there's good money to be made in criminal hacking, security experts are warning that highly organized groups of attackers are doing their research online before carefully selecting their targets. The goal is to obtain intellectual property that only an insider would have access to, then offer it for sale or demand a ransom. Armed with an arsenal of custom Trojan horses, these organized criminals are going after secrets within high-profile companies and even within government agencies. Often, the victim is unaware that it's happening.

Warning from the United Kingdom
According to a June 16, 2005, briefing by the NISCC (National Infrastructure Security Co-ordination Centre, in the United Kingdom), targeted e-mail Trojan horse attacks have increased in sophistication within the last few months. The basic concept is not new. I first wrote about a similar concept two years ago.

Similar to phishing attacks or to e-mail-borne viruses, the criminal hackers (a.k.a. crackers) target a specific company or government agency, then create a fake e-mail that appears to be an internally sent document. Crackers are literally Googling their quarry, gaining valuable background information regarding the organizational structure of the target system first, then shaping the social engineering part of their e-mail attacks for maximum impact. For example, a subject line might read Re: Project Bluebird, where bluebird is an internal mandate.

Déjà vu
By looking up legitimate e-mail addresses within a particular government agency, then spoofing an e-mail broadcast back to as many recipients of that domain as possible, an attacker can penetrate fairly deeply within an otherwise protected network. According to NISCC, the documents used in these new targeted Trojan horse attacks are often publicly available and usually sent to e-mail distribution lists. The attackers simply modify the original document to include their custom-built Trojan horse.

The irony is that the thieves themselves don't have to know much about programming. Individuals are available on IRC chats and on the Web who will custom-design a Trojan horse to fit specific needs. Because the attacks are so specific, antivirus and security companies may not identify the exact Trojans used to carry out the attack until much later.

Smash and grab
Using known vulnerabilities in Windows, Outlook, and Internet Explorer, a targeted Trojan horse can be installed on an insider's computer, often without his or her knowledge. Once in place, these Trojans can record keystrokes, gain access to other parts of the internal network, or expose an internal network to a remote attacker. The Trojans can reside on desktops and networks for days or weeks before they are detected. This allows crackers to "smash and grab" files located deep within a company or government agency before conventional antivirus and security systems recognize there's a problem. I'm speculating that the recent theft of the information on 40 million credit cards from a CardSystems Solutions' database in Arizona might have been accomplished in this stealth manner.

Prevention
Since these attacks rely mostly upon vulnerabilities in software, you should patch your PC regularly. The Windows Update service from Microsoft can be set to run automatically within Windows XP. If you're running older versions, you should check the site manually at least once a month. In addition, good antivirus, personal firewall, and antispyware apps provide layers of security, making it harder for intruders to gain access to your individual PC or private network.

Are criminal hackers getting bold, or is this a logical evolution in the game of cat and mouse? Talk back to me.




Security Center
Top antivirus apps
From CNET Reviews
Top antispyware apps
From CNET Reviews
Virus and security alert forums
From CNET Message Boards


More commentary
Buzz Report
Molly Wood
Taking a bite out of hype.
Security Watch
Robert Vamosi
Don't get burned by viruses and hackers.
Fully Equipped
David Carnoy
The electronics you lust for.
On Call
Kent German
Solutions for your wireless woes.
Driving It
Wayne Cunningham
What's hot and what's not in car tech.

TalkBack
13 messages

Article discussion: Targeted Web attacks


Latest post:

"Still can't shake the trojan!"
by gladtdgs (See profile) - July 11, 2005 1:28 PM PDT
Thanks for the article Robert, but I already have 3 spyware detectors running plus an anti-virus, plus the microsoft "fire wall". They still can't rid my machine of this vicious t... (Read more).
Sort by: Title |
Date
| Most helpful

let's question some assumptions

1. Hackers are programmers - good and bad
2. If they are criminals then their... (Read more)
by holymole (See profile) - July 6, 2005 5:20 PM PDT

IP address is HARD to get

Internet is too anonymous. No where else in society can you "hide" your ture ide... (Read more)
by jschutzm (See profile) - July 6, 2005 12:10 PM PDT

Anonymity of email

The Whole E-mail system is too insecure. Spoofing of the header information is t... (Read more)
by jschutzm (See profile) - July 6, 2005 12:04 PM PDT

Trojans & spyware

I find it STUPID that CharterPipeline advised my daughter to get rid of her Zone... (Read more)
by garyccb (See profile) - July 6, 2005 9:03 AM PDT

Bank Robbers...

Q: Why do Bank Robbers rob banks
A: Because the need to...

Same/Same f... (Read more)
by Aardasp (See profile) - July 6, 2005 8:33 AM PDT

Everyone is missing the boat.

The way you end this nonsense is by getting law enforcement officials to start k... (Read more)
by jmarinis (See profile) - July 6, 2005 7:13 AM PDT

Start by not running windows as administrator!

Start by not running windows as administrator!

The default configuration ... (Read more)
by hadaso (See profile) - July 6, 2005 3:53 AM PDT


© 2008 CNET Networks, Inc., a CBS Company. All rights reserved. | Privacy Policy | Terms of Use