Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
When Spyware Crosses the Line
Kelly Martin, 2004-06-23

"Spyware" isn't harmless software when it starts hijacking your browser, downloading updates, and displaying adult porn images to small children.

Comments Mode:
When Spyware Crosses the Line 2004-06-24
Laga Mahesa
When Spyware Crosses the Line 2004-06-24
Steve Poirot
another good tool 2004-06-24
Anonymous (1 replies)
another good tool 2004-06-28
Anonymous
When Spyware Crosses the Line 2004-06-24
Anonymous (1 replies)
When Spyware Crosses the Line 2004-06-28
Anonymous
When Spyware Crosses the Line 2004-06-24
raggi (1 replies)
I found your article very interesting, I have a couple of comments which may be useful to you and or others.

Firstly, with the removal of 0dayz exploit, while using safe mode alone used to be the solution. Now hoevever, due to the level of shell integration seen in some of these spyware programs, it is no longer safe to load explorer.exe. Instead boot to safe mode with command prompt, load ad-aware from there. Even with old definitions by comparison to the newer exploit (in the case of spyware that is known but has auto-updated itself), ad-aware can often still remove the file so long as it is not in use (thus no explorer.exe).

Secondly, protecting against future infection. I was also impressed at the bold statement to move away from internet explorer, however there are some features I find in IE which just cannot be delivered elsewhere. Speed is one such feature (I have had my head near bitten clean off for saying that, but it is true, internet explorer loads fast and processes pages more progressively than most browsers (yes it cheats as half of it is loaded already)). Feature argument or not, some people just dont want to move away from the MS browser, and in this case we need to theorise how to lock it down. My first suggestion is to pay careful attention to the settings in tools->advanced. I have seen many administrators laugh and chuckle when this is suggested, and the only suitable answer is REREAD! Install on Demand can be switched off, and this is highly recommended if you want a more secure system. As usual with removing a feature, you need to remedy other side effects, so go and get flash, shockwave, svg and maybe full java so that your users can still see these formats. You could turn off third party browser extensions, that will stop any spyware from hijacking the browser, however, you loose third party browser extensions. ActiveX settings, well... It is true to say that there exists sites which use activex productively, but this is not enough to solve our problem. What can be done? Group Policy - thats right. ActiveX has the ability to be signed and should be, settings should be customised to cull unsigned ActiveX and still be dubious of even signed ActiveX. If install on demand is switched off, this combination is effective against most of the spyware installers to date. On several desktops I have default security settings, a version of Norton with Adaware scanning regularly. Install on Demand is off, and third party extensions are On due to the use of the google toolbar (which has popup blocking, just make sure you disable script debugging also). Famous last words of a security guy, "it's been hard as nails so far". This system is not impervious -but that having been said its pretty good. We have tested it against several of the recent hijacking trojans too, and it stood up to the test. If combined with a deep inspection firewall this can be very strong.

Stronger still - what? It can be done, although its not graceful. What about running your internet browsing off the desktop? A server running internet browsing can be quite a productive strategy, and can help maintain the solidarity of your desktop environments. This is costly however, especially in large corporations. An alternative to using a server is to use a guest account to run all copies of internet explorer. This is a nasty idea though, as where do file dialogs start when saving? under a different use context, thats right. Well this can all be solved with a little bit of scripting and some reghacks, but its not ideal. All recommendations point to simply using antoher browser, but hopefully this is some food for thought on the possibility of not doing so.

Enjoyed your article,

Thanks,

raggi.
Mantissa 51.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/250/26968#26968
When Spyware Crosses the Line 2004-06-24
Mac Man
Lude and lascivious act? 2004-06-24
Brad
When Spyware Crosses the Line 2004-06-24
Glauber Ribeiro (1 replies)
When Spyware Crosses the Line 2004-06-24
Anonymous
When Spyware Crosses the Line 2004-06-24
Anonymous (4 replies)
When Spyware Crosses the Line 2004-06-24
Anonymous
When Spyware Crosses the Line 2004-06-25
Anonymous
When Spyware Crosses the Line 2004-06-26
Anonymous
When Spyware Crosses the Line 2004-06-30
blacklight
When Spyware Crosses the Line 2004-06-24
Anonymous (1 replies)
When Spyware Crosses the Line 2004-06-24
TechSupport (1 replies)
When Spyware Crosses the Line 2004-06-24
same thing
When Spyware Crosses the Line 2004-06-24
Anonymous (1 replies)
Spyware? This should be re-classified 2004-06-25
TheHornedReaper (1 replies)
When Spyware Crosses the Line 2004-06-25
Anonymous
Same thing happened to me 2004-06-25
Anonymous
What about going after the TRUE source? 2004-06-25
nosebreaker.com
When Spyware Crosses the Line 2004-06-25
Mark S Panko
Two things worth noting 2004-06-25
Anders Bengtsson (1 replies)
When Spyware Crosses the Line 2004-06-25
Anonymous
When Spyware Crosses the Line 2004-06-25
sandalle
When Spyware Crosses the Line 2004-06-25
Anonymous
Why even run IE ? 2004-06-26
thomassoares AT hotmail DOT com
I always wondered how it is legal. 2004-06-26
Call the cops.
When Spyware Crosses the Line 2004-06-26
A French User
When Spyware Crosses the Line 2004-06-26
England1215
When Spyware Crosses the Line 2004-06-27
Devin McGrane
When Spyware Crosses the Line 2004-06-27
Cleber S. Leite
Who Profits 2004-06-27
Chris Woodruffe
When Spyware Crosses the Line 2004-06-28
Anonymous
When Spyware Crosses the Line 2004-06-28
Anon-e-mouse
When Spyware Crosses the Line 2004-06-28
Martin, Sweden
When Spyware Crosses the Line 2004-06-28
kerberos_daemon
When Spyware Crosses the Line 2004-06-28
Anonymous
It's parents fault !!!!!!!!!! 2004-06-28
Anonymous (3 replies)
It's parents fault !!!!!!!!!! - Not! 2004-06-29
An InfoSec Engineer (1 replies)
Parents fault 2004-06-30
Aenox
It's parents fault !!!!!!!!!! 2004-06-30
Anonymous
When Spyware Crosses the Line 2004-06-28
Anonymous
When Spyware Crosses the Line 2004-06-28
estrinyefim@yahoo.com
Don't use internet Explorer! 2004-06-29
Anonymous
When Spyware Crosses the Line 2004-06-29
VTofHHH
Never gotten spyware 2004-06-29
Jason S. (1 replies)
Never gotten spyware 2004-07-01
Erya
When Spyware Crosses the Line 2004-06-30
Richard Chirgwin
When Spyware Crosses the Line 2004-06-30
Anonymous
When Spyware Crosses the Line 2004-06-30
Anonymous
When Spyware Crosses the Line 2004-06-30
Anonymous
When Spyware Crosses the Line 2004-06-30
Anonymous
No sympathy 2004-07-01
Anonymous
Spyware in the Consumer and Corporate Desktop: A Security Engineer's Reply 2004-07-02
Mary B. Winfield, Platinum Precision Software Inc.
No need to remove spyware. 2004-07-05
Anonymous
When Spyware Crosses the Line 2004-07-05
Anonymous
When Spyware Crosses the Line 2004-07-06
Lambert, Ryan
When Spyware Crosses the Line 2005-08-02
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus