So now that you have an idea of what is botnet, are you part of it?
Botnet computer are computer infected with Trojan or malicious code design to allow remote control of the infected computer. Many still have the traditional thinking that botnet are controlled using Internet Relay Chat (IRC) which is a dying trend. But the actual fact is that botnet are very much alive as hackers are using a mixture of protocol and stealth technique to infect and control infected machines. According to researched, as many as 1.5 million botnet have been found and the number are growing.
Botnet computer are not immune from detection. There will be signs and trails of infection and prevention can be practiced. Simple task will be looking out for unusual running of services, process and going through the log files. If you suspect that your computer had been infected, do the following;
1) Update your operating system and internet application to prevent as much vulnerabilities as possible
2) Install a different anti-virus on your operating system and do a full updated scan. Your existing anti-virus are most likely to be compromised and by updating it and doing a full scan won’t help most of the time.
3) Install and run a updated malware/spyware application. There are lots of freeware in the Internet. “Spybot – Search & Destroy” is one of my favourite.
4) Go through the services and spot unusual services.
Once you have done the above and you are pretty sure that you are free from being a botnet, install a personal firewall. Firewall wall normally closed all unnecessary ports and this make your computer a difficult for the hacker.
All these actions won’t guarantee that you won’t be part of a botnet someday. But no prevention is 100% and by making your computer a difficult target, chances of you being part of the botnet network is being narrow down by a great margin!
As the saying goes. “The only way not to make mistake is not to do anything. But in today’s world, that would probably be the biggest mistake” - Sun Tze
Monday, April 14, 2008
Sunday, April 6, 2008
Magnet, Nets, MegaNet or Botnet??? Part 1 of 2
Do you know that your computer would be compromised and be part of a group of computer used to sent out spam mail or carry out attack on others computer without your knowing?
Which of the terms below represent a group of compromised system used for malicious activities??
1) MegaNet
2) Botnet
3) Nets
4) Magnet
Read on if you are clueless about this. I will be explaining Botnet and how to prevent your computer from being part of it.
Basically botnet are a group of compromised system normally infected by Worms or Trojans control by hackers to carry out malicious operation such as Spamming, Distributed Denial of Services attack, etc The common questions on Botnet are such as I have anti virus do I still get infected?, I am behind a firewall, so I should be safe right? And how do I know if I am part of a botnet?
Anti Virus software would normally do a pretty good job in keeping out the viruses, worms, Trojan, etc. But between the time when a new malicious code was found flooding the internet and the virus definition file was release by the vendors, there would be a window period that your system could be compromised. Unlike virus, worms are autonomous. They have their own transport and mechanism and are independence and could self replicate themselves to other system in the network. Often when a PC has been compromised, a install or update of virus definition files would also not detect the worms as it would return a false call to the scan from the anti virus software. This explain why often you heard of people saying why their latest anti virus software are not detecting the virus.
Trojan often come in disguised, remember the “Trojan Horse” event? Trojan often come in the form of a useful software that the user could use and is lured into downloading it from the internet. I am sure many of you have experiences a pop up from your anti virus detecting a Trojan after downloading a program from the Internet. But what happen if it is not detected? The answer is your system is probably a member of an xzy botnet.
Ask yourself, can your firewall detect what you sent from your email? Traditionally, your firewall can’t do so. Firewall act as a gate between your system/network and the Internet. It only work on ports. And this gateway doesn’t work for email ports, else if it does, no mail can be sent out of the network. This also explain the reason why companies need separate anti spam appliance or Unified threat Machine (UTM) for their SMTP port. So can your firewall wall protect you from being a botnet spammer? I guess the answer is obvious.
End Part 1 of 2
Which of the terms below represent a group of compromised system used for malicious activities??
1) MegaNet
2) Botnet
3) Nets
4) Magnet
Read on if you are clueless about this. I will be explaining Botnet and how to prevent your computer from being part of it.
Basically botnet are a group of compromised system normally infected by Worms or Trojans control by hackers to carry out malicious operation such as Spamming, Distributed Denial of Services attack, etc The common questions on Botnet are such as I have anti virus do I still get infected?, I am behind a firewall, so I should be safe right? And how do I know if I am part of a botnet?
Anti Virus software would normally do a pretty good job in keeping out the viruses, worms, Trojan, etc. But between the time when a new malicious code was found flooding the internet and the virus definition file was release by the vendors, there would be a window period that your system could be compromised. Unlike virus, worms are autonomous. They have their own transport and mechanism and are independence and could self replicate themselves to other system in the network. Often when a PC has been compromised, a install or update of virus definition files would also not detect the worms as it would return a false call to the scan from the anti virus software. This explain why often you heard of people saying why their latest anti virus software are not detecting the virus.
Trojan often come in disguised, remember the “Trojan Horse” event? Trojan often come in the form of a useful software that the user could use and is lured into downloading it from the internet. I am sure many of you have experiences a pop up from your anti virus detecting a Trojan after downloading a program from the Internet. But what happen if it is not detected? The answer is your system is probably a member of an xzy botnet.
Ask yourself, can your firewall detect what you sent from your email? Traditionally, your firewall can’t do so. Firewall act as a gate between your system/network and the Internet. It only work on ports. And this gateway doesn’t work for email ports, else if it does, no mail can be sent out of the network. This also explain the reason why companies need separate anti spam appliance or Unified threat Machine (UTM) for their SMTP port. So can your firewall wall protect you from being a botnet spammer? I guess the answer is obvious.
End Part 1 of 2
Friday, April 4, 2008
SPAM BUSTER! Part 4 of 4
Crytography – “zpv dbou tff nf!”
The most commonly use form of crytography used in Anti spam would probably be DomainKeys Indentify Mails (DKIM). Similary to SPF, DKIM is interested in indentifying the sender. But on top of that, DKIM also help in protecting the integrity of the mail content. DKIM does it by using a set of keys and by providing positive identification of the signer’s identity along with an encrypted “hash” of the message content allowing messages to be checked to verify that they are from purported senders (authentication) and have arrived unaltered (message integrity).
There are 3 main important keys in DKIM.
1) Digital Signature
2) Definittion of the field over which the digital signature was calculate
3) Sending Domain
The public key was published to the public Domain Name Server (DNS). When the receiver received the mail, it checked the DKIM signature against the sender’s public key through the DNS. If the incoming message cannot be verified then the receiving server knows it contains a spoofed address or has been tampered with or changed. A failed message can then be rejected, or it can be accepted but have it tagged according with “certainly spam”, “probably spam”, etc.
Email is an important form of communication in our lives and because of the heavy usage of email, spam are here to stay. Spam evolved quickily making it very difficult to stop them forever. Therefore we need different combination of anti spam technologies to put up an effective fight against spam. Hope this set of blogs would give you a better insight of anti spam technologies.
End of Part 4
The most commonly use form of crytography used in Anti spam would probably be DomainKeys Indentify Mails (DKIM). Similary to SPF, DKIM is interested in indentifying the sender. But on top of that, DKIM also help in protecting the integrity of the mail content. DKIM does it by using a set of keys and by providing positive identification of the signer’s identity along with an encrypted “hash” of the message content allowing messages to be checked to verify that they are from purported senders (authentication) and have arrived unaltered (message integrity).
There are 3 main important keys in DKIM.
1) Digital Signature
2) Definittion of the field over which the digital signature was calculate
3) Sending Domain
The public key was published to the public Domain Name Server (DNS). When the receiver received the mail, it checked the DKIM signature against the sender’s public key through the DNS. If the incoming message cannot be verified then the receiving server knows it contains a spoofed address or has been tampered with or changed. A failed message can then be rejected, or it can be accepted but have it tagged according with “certainly spam”, “probably spam”, etc.
Email is an important form of communication in our lives and because of the heavy usage of email, spam are here to stay. Spam evolved quickily making it very difficult to stop them forever. Therefore we need different combination of anti spam technologies to put up an effective fight against spam. Hope this set of blogs would give you a better insight of anti spam technologies.
End of Part 4
Subscribe to:
Posts (Atom)