版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
1、1The next virusesWhat we could wait for?Fernando de la CuadraPanda Software International2Index Big attacks Summary of advantages and disadvantages What could we wait for? And then.3Big attacks Jerusalem Melissa Lovelettter Klez Sobig SQLSlammer Blaster4Jerusalem First big infection Payload: Deletes
2、 executables files Low damage according with nowadays figures Factors for success: Users misinformation Piracy Factors for being unsuccessful: Low number of computers in 1989 Date for payload: Friday, 13th Spreads without conditions: all EXE files5Melissa First mass-mailer worm for end users Payload
3、: Modifies Word 9.0 macro security Inserts some texts Forward itself to 50 addresses Factors for success: First mass mailer worm for Outlook Users misinformation Factors for being unsuccessful: Too many symptoms of being infected Excessive use of mail servers6Loveletter Another mass-mailer worm for
4、end users, with high media impact Payload: Overwrites certain files Steals personal information Factors for success: Forwards itself to all addresses Users misinformation Fast spreading Factors for being unsuccessful: Too many symptoms of being infected Excessive use of mail servers Big media impact
5、7Klez First big security hole exploit PayloadStops antivirusDeletes filesSpreads massively changing shape Factors for success:Users lack of upgradingVulnerability Factors for being unsuccessful:?8Sobig Combined threat PayloadSpreads massivelyDownloads a worm form Geocities Factors for success:Social
6、 engineeringUsers misinformation Factors for being unsuccessful:Use of mail serversMedia impact9SQLSlammer Non- PayloadDenial of Services in MS SQL Servers Factors for success:Fast spreadingLack of updating in servers Factors for being unsuccessful:Upgrading of serversCorrect firewall configuration1
7、0Blaster Using RPC vulnerability Payload Denial of Services to Installs Trivial Protocol server Factors for success: Fast spreading Lack of updating in computers Factors for being unsuccessful: Upgrading of computers Media impact11Summary SuccessSocial engineeringUsers misinformationFast spreadingLa
8、ck of updating in serversFast spreadingLack of updating in computers12Summary Factors for being unsuccessful:Excessive use of mail serversMedia impactUpgrading of serversCorrect firewall configurationUpgrading of computersMedia impact13What could we wait for? E-mail virus:Spreading through a non sus
9、picious e-mail address and sender “Postmaster” may be a good sender “Undeliverable” may be a good subjectIt cannot look like spamAbsolutely “aseptic” body and subject14What could we wait for? Slow actionNot more than 10 messages per dayNo administrator will detect this low traffic increasing15What c
10、ould we wait for? Propagation:Direct SMTP commandsE-mailing to addresses in different domains than the computerInside domains, direct spreading through open standard ports16What could we wait for? Avoid address book to read addressesLook for addresses in hard driveInternet temporal filesWord textsHT
11、ML files17What could we wait for? Very light PC damageComputers are its life support,Distributed attack to big Internet serversIf it cracks PC, it will become well knownFor non ADSL or networked PC, it should dial-up its own connection when screen saver pops up18What could we wait for? Avoiding antivirus detectionEncrypted attachmentRandom password inside the textWinZip may be a good tool!Better a new encryption system19And th
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025年哈爾濱銀行七臺(tái)河分行招聘外包員工5人備考題庫(kù)完整答案詳解
- 2025年中國(guó)航空工業(yè)集團(tuán)凱天崗位招聘?jìng)淇碱}庫(kù)及答案詳解參考
- 2025年龍巖市上杭縣人民法院招聘編外人員的備考題庫(kù)及1套完整答案詳解
- 2026年深空探測(cè)數(shù)據(jù)使用合同
- 2025年北京西城區(qū)高二(上)期末歷史試題和答案
- 監(jiān)管協(xié)管員面試題及答案解析(2025版)
- 有色金屬行業(yè)2025Q3總結(jié):Q3盈利同比繼續(xù)上行擁抱資源新周期
- 中國(guó)社會(huì)科學(xué)院世界經(jīng)濟(jì)與政治研究所2026年度公開招聘第一批專業(yè)技術(shù)人員6人備考題庫(kù)及答案詳解一套
- 來(lái)賓市公安局2025年第三次招聘輔警備考題庫(kù)及參考答案詳解一套
- 崇左憑祥市應(yīng)急管理局招聘考試真題2024
- 2025年淮北市相山區(qū)公開招考村(社區(qū))后備干部66名考試筆試模擬試題及答案解析
- 柔性引才合同協(xié)議
- 2025中原農(nóng)業(yè)保險(xiǎn)股份有限公司招聘67人筆試考試參考試題及答案解析
- 2025年戰(zhàn)略投資專員崗位招聘面試參考試題及參考答案
- 2025年小學(xué)教師素養(yǎng)大賽試題(含答案)
- 2025年國(guó)家開放大學(xué)《中國(guó)現(xiàn)代文學(xué)專題》形考任務(wù)試題與答案
- 軍事理論課指揮控制技術(shù)
- 2024年河北秦皇島市公安醫(yī)院招聘考試真題
- 事業(yè)單位會(huì)計(jì)面試熱點(diǎn)問題匯編
- 工程工程培訓(xùn)課件
- 學(xué)堂在線 雨課堂 學(xué)堂云 經(jīng)濟(jì)學(xué)原理(微觀部分) 章節(jié)測(cè)試答案
評(píng)論
0/150
提交評(píng)論