Re: Spyware going thru firewall

From: FromTheRafters (!0000@nomad.net)
Date: 06/30/02


From: "FromTheRafters" <!0000@nomad.net>
Date: Sat, 29 Jun 2002 21:20:22 -0400


"Art Kopp" <artnpeg@nowhere.com> wrote in message
news:3d1e5134.43488213@news.epix.net...

> Say for example you have given permission to IE to access the
> internet. That means the iexplore.exe program has permission. All a
> Trojan has to do is rename iexplore.exe to foo.exe and then name its
> "dirty worker" program iexplore.exe. Once "dirty worker" is finished,
> control is passed to foo.exe which makes you think everything is
> normal except perhaps IE may seem slower to load than usual. You see?
> Very simple :)

Another example is when the trojan name is iexp1ore.exe, iexpiore.exe,
iexplore .exe, or other visually similar spellings. When your firewall asks
if you want it to access the internet, you grant it permission, and never
notice the error. There are many ways to insinuate programs into the
startup axis, and to trick users into allowing access to the internet.



Relevant Pages

  • Re: Talents
    ... Denying permission to use what is freely available on Internet is just plain ... There are 2 types of HTML additions in the IGB ... Lets describe the talents improvement in detail. ...
    (rec.games.roguelike.adom)
  • How to re-enter something into Windows Task Manager "Processes"?
    ... notification that was asking for permission to grant something access to the ... internet using javaw.exe. ...
    (microsoft.public.windowsxp.help_and_support)
  • RE: New users cannot access some parts of internal website
    ... permission on the folders where the data is at and everyone has the same ... I understand that the new accounts cannot ... Uninstall Internet Explorer Enhanced Security by unchecking the same. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: ISS configuration after ip address change
    ... granted to the new subnet. ... I recommend you to change the permission manually. ... Make sure that the preferred DNS server is the internal NIC's IP ... >> How to configure Internet access in Windows Small Business Server 2003 ...
    (microsoft.public.windows.server.sbs)
  • RE: New users cannot access some parts of internal website
    ... I understand that the new accounts cannot ... Uninstall Internet Explorer Enhanced Security by unchecking the same. ... Microsoft CSS Online Newsgroup Support ... | don't have permission to access the internet). ...
    (microsoft.public.windows.server.sbs)