<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: reroute]]></title>
    <link>http://securityratty.com/tag/reroute</link>
    <description></description>
    <pubDate>Wed, 07 Mar 2007 04:11:45 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Use of Rogue DNS Servers on Rise]]></title>
      <link>http://securityratty.com/article/0c734d36befa64d2b6075e3f3999488a</link>
      <guid>http://securityratty.com/article/0c734d36befa64d2b6075e3f3999488a</guid>
      <description><![CDATA[They're called &quot;servers that lie.&quot; Mendacious machines controlled by hackers that reroute Internet traffic from infected computers to fraudulent Web sites are increasingly being used to launch...]]></description>
      <content:encoded><![CDATA[They're called "servers that lie." Mendacious machines controlled by hackers that reroute Internet traffic from infected computers to fraudulent Web sites are increasingly being used to launch attacks, according to a paper published this week by researchers with the Georgia Institute of Technology and Google Inc.]]></content:encoded>
      <pubDate>Thu, 14 Feb 2008 23:20:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reroute internet traffic">reroute internet traffic</category>
      <category domain="http://securityratty.com/tag/fraudulent web sites">fraudulent web sites</category>
      <category domain="http://securityratty.com/tag/launch attacks">launch attacks</category>
      <category domain="http://securityratty.com/tag/georgia institute">georgia institute</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <category domain="http://securityratty.com/tag/mendacious machines">mendacious machines</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <source url="http://digg.com/security/Use_of_Rogue_DNS_Servers_on_Rise">Use of Rogue DNS Servers on Rise</source>
    </item>
    <item>
      <title><![CDATA[Grayware?]]></title>
      <link>http://securityratty.com/article/0488224eb743882e8c799c5fb4404dd5</link>
      <guid>http://securityratty.com/article/0488224eb743882e8c799c5fb4404dd5</guid>
      <description><![CDATA[Very interesting definitions that I found on www.dqchannels.com which I would like to highlight
Grayware' is a term that regularly appears on IT and security professionals' radar screens today. An...]]></description>
      <content:encoded><![CDATA[<P><FONT face="Times New Roman,Times,serif" size=1>Very interesting definitions that I found on </FONT><A href="http://www.dqchannels.com/"><FONT face="Times New Roman,Times,serif" size=1>www.dqchannels.com</FONT></A><FONT face="Times New Roman,Times,serif" size=1> which I would like to highlight:</FONT></P>
<P><FONT face="Times New Roman,Times,serif" size=1><STRONG>'Grayware' </STRONG>is a term that regularly appears on IT and security professionals' radar screens today. An umbrella term applied to a wide range of applications that are installed on a user's computer to track and/or report certain information back to some external source, these applications are usually installed and run without the permission of the user.</FONT></P>
<P class=boxheadmttf style="MARGIN-LEFT: 0in"><STRONG><FONT face="Times New Roman,Times,serif" color=#019277 size=1>Grayware categories</FONT></STRONG></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Adware:</STRONG> Adware is usually embedded in freeware applications that users can download and install at no cost. Adware programs are used to load pop-up browser windows to deliver advertisements when the application is open or run.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Dialers:</STRONG> Dialers are grayware applications that are used to control the PC's modem. These applications are generally used to make long distance calls or call premium 900 numbers to create revenue for the thief.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Gaming:</STRONG> Gaming grayware applications are usually installed to provide jokes or nuisance games.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Joke:</STRONG> Joke grayware are applications that are used to change system settings, but do no damage to the system. Examples include changing the system cursor or Windows' background image.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Peer-to-Peer:</STRONG> P2P grayware are applications that are installed to perform file exchanges. (P2P) While P2P is a legitimate protocol that can be used for business purposes, the grayware applications are often used to illegally swap music, movies, and other files.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 2.9pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Spyware:</STRONG> Spyware applications are usually included with freeware. Spyware is designed to track and analyze a user's activity, such a user's web browsing habits. The tracked information is sent back to the originator's Web site where it may be recorded and analyzed. Spyware can be responsible for performance related issues on the user's PC.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in; LINE-HEIGHT: 10.9pt">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Key logger:</STRONG> Key loggers are perhaps one of the most dangerous grayware applications. These programs are installed to capture the keystrokes made on a keyboard. These applications can be designed to capture user and password information, credit card numbers, email, chat, instant messages, and more.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Hijacker: </STRONG>Hijackers are grayware applications that manipulate the Web browser or other settings to change the user's favorite or bookmarked sites, start pages, or menu options. Some hijackers have the ability to manipulate DNS settings to reroute DNS requests to a malicious DNS server.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Plugins:</STRONG> Plugin grayware applications are designed to add additional programs or features to an existing application in an attempt to control, record, and send browsing preferences or other information back to an external destination.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Network management:</STRONG> Network management tools are grayware applications that are designed to be installed to for malicious purposes. These applications are used to change Tools network settings, disrupt network security, or cause other forms of network disruption.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Remote administration tools: </STRONG>These tools are grayware applications that allow an external user to remotely gain access, change, or monitor a computer on a network.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>BHO:</STRONG> BHO grayware applications are DLL files that are often installed as part of a software application to allow the program to control the behavior of Internet Explorer. Not all BHOs are malicious, but the potential exists to track surfing habits and gather other information stored on the host.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Toolbar:</STRONG> Toolbar grayware applications are installed to modify the computer's existing toolbar features. These programs can be used to monitor web habits, send information back to the developer, or change the functionality of the host.</FONT></FONT></P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in">&nbsp;</P>
<P class=boxtextmttf style="MARGIN: 0in 0in 3pt; TEXT-INDENT: 0in"><FONT face="Times New Roman,Times,serif"><FONT size=1><STRONG>Download: </STRONG>Downloaders are grayware applications that are installed to allow other software to be downloaded and installed without the user's knowledge. These applications are usually run during the startup process and can be used to install advertising, dial software, or other malicious code.</FONT></FONT></P>]]></content:encoded>
      <pubDate>Wed, 07 Mar 2007 04:11:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/grayware">grayware</category>
      <category domain="http://securityratty.com/tag/dangerous grayware applications">dangerous grayware applications</category>
      <category domain="http://securityratty.com/tag/joke">joke</category>
      <category domain="http://securityratty.com/tag/joke grayware">joke grayware</category>
      <category domain="http://securityratty.com/tag/p2p grayware">p2p grayware</category>
      <category domain="http://securityratty.com/tag/toolbar grayware applications">toolbar grayware applications</category>
      <category domain="http://securityratty.com/tag/bho grayware applications">bho grayware applications</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/toolbar">toolbar</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2007/3/7/2787949.html">Grayware?</source>
    </item>
  </channel>
</rss>
