Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] Re: Microsoft AntiSpyware falling further behind |
|---|---|
| Date: | Fri, 28 Oct 2005 11:28:36 -0400 |
On Fri, 28 Oct 2005 17:56:32 +0300, Valdis Shkesters said: (Hmm.. usually when I reply to Valdis I'm talking to myself... ;)
As today I was preparing news for a portal on IT security, I am informed that Anti-Spyware Coalition is finalizing spyware definition. It is last moment to finalize with spyware, because at the horizon already has appeared ?crimeware?. Take a look at http://www.antiphishing.org/. I?m quoting: ?Technical subterfuge schemes plant crimeware onto PCs to steal credentials directly, often using Trojan keylogger spyware.? Maybe it would be better to call Trojan horses Trojan horses?
No, because they're different.
Trojan horses (a) get installed under pretense of being something wanted
or beneficial ("Hey, I'm a neat fun codec that lets you view these movies...")
and (b) once there, gives the attacker a "back door" into the system, to
do unspecified things (run commands, launch DDoS attacks, send spam, scan
for other vulnerable software, upload plugins to extend the Trojan's
functionality,
or whatever).
Spyware, on the other hand (a) *may* be installed via Trojan Horse means, but
may
also be forcibly inserted on a system via a software vulnerability, or added
in via the above-mentioned plugin method by an already-present Trojan, and (b)
is
software that monitors system activity (keystrokes, screen pixmaps, etc) in an
effort to acquire credentials or other sensitive information.
pgpppZWQPiR8K.pgp
Description: PGP signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ GLSA 200510-23 ] TikiWiki: XSS vulnerability, Thierry Carrez |
|---|---|
| Next by Date: | Re: [Full-disclosure] Brain dead SSH scans from Italy, Jeff MacDonald |
| Previous by Thread: | Re: [Full-disclosure] Re: Microsoft AntiSpyware falling further behind, Valdis Shkesters |
| Next by Thread: | Re: [Full-disclosure] Re: Microsoft AntiSpyware falling furtherbehind, Valdis Shkesters |
| Indexes: | [Date] [Thread] [Top] [All Lists] |