Bytestart - The online small business portal
Search over 1700 Articles!


Low-cost phone and broadband deals
Over 100,000 small businesses have already switched to XLN for cheap phone calls and broadband packages. We will never be beaten on price or service, so call us now on 0845 034 8802 or click here to find out more.


'Rootkits' - just when you thought viruses were a pain!

 print  e-mail 

A New Threat

Well, it could only be a matter of time before hackers and virus writers got round the latest security technologies to start messing with people's PCs again. Just when we thought we were safe with our anti spyware programs, virus scanners and firewalls, a new threat looms on the horizon, and what's worse is that the companies we rely on to keep us secure aren't really prepared for it. So, what is this new threat? It's something called "Rootkits"

"A root kit is a set of tools used by an intruder after cracking a computer system. These tools can help the attacker maintain his or her access to the system and use it for malicious purposes. Root kits exist for a variety of operating systems such as Linux, Solaris, and versions of Microsoft Windows." (Wikipedia)

 

In English then?

Basically a hacker finds a way into someone's PC in the normal way, through vulnerabilities in the operating system (ie: Windows, Linux, etc) or by taking advantage of lax security. Once inside, they install a set of applications, some of which are disguised as programs that the operating system needs to run. This in itself is quite common: many Windows-based viruses disguise themselves as important system processes which fools Windows itself, meaning you can't shut them down because Windows thinks they're Microsoft products. However, rootkits also include scripts (files containing computer code) which cover their tracks by removing any reference to their being there.

A couple of tools exist to help you monitor if and when your operating system files have changed. In the past, when a file was overwritten by a virus or other such program, the file's creation date would match the date at which the file was downloaded to that PC. Now, files installed by rootkits use the same creation date as the original files, making them almost undetectable. I say almost of course, and that brings me onto the tools you can use. One of these is Tripwire, which - among other things - examines your files for integrity and lets you know whether they pass or not. The problem with this is that it's for big-bucks business and so will be very expensive. Another of these tools is an open-source project called AIDE. Because it's open source it's free, but also it may be difficult to get comprehensive support, so be wary.

Rootkits exist in order to allow the hacker to return to the compromised machine at any time, without worrying about security or being detected. The programs they install can be controlled using a system called Telnet (the name may vary from system to system), which is a protocol for sending text commands from one machine to another. The command is sent as a standard string of text (it may be encrypted or compressed, but it's still just text), and interpreted and actioned by the receiving machine.

So What's the Fuss?

Once the hacker has gained access to your machine, you are almost completely vulnerable. Your files can be downloaded, viewed, edited and even deleted, your personal information can be ransacked and your operating system corrupted.

The problem as I stated at the beginning of this article is that software developers have been largely blind to this new technology for some time, and are now only starting to make movements towards finding a solution. The problem with Windows is that it is almost fundamentally insecure, and some people are using this to fuel the argument that Microsoft should start releasing the source code for Windows, so that developers outside of the software giant can fix the problem for themselves.

What Can I do?

I've not written this with a view to giving you comprehensive, step-by-step solutions to the problem. Instead I'm hoping this will raise your eyebrows and help you to be a little more wary about the security you have in place. If you'd like to discuss your security setup, why not raise it on the Uplink, our e-mail community, at uplink@msomedia.com.

There is some good news if you use Microsoft's fledgling AntiSpyware package: they're already researching ways to incorporate rootkit detection into their software. If you've got anti-virus software in place, visit their website to find out what they're doing about rootkits. Below are some possible points of interest for you:

I hope this has given you something to think about. But remember...don't have nightmares!

Article kindly provided by Mark Steadman - MSO Media - Web Solutions that Work

Posted October 4, 2005





Latest articles in Web Related
 
How to choose a Content Management System (CMS) for your website
[July 10, 2008] If you're running your own business website and need to update the contents on a regular basis, chances are you would benefit from having a CMS. This is a guide to content management systems, and choosing the right software for your small business.
 
Why do I need a small business website?
[July 1, 2008] With the continuing growth the Internet, more and more small businesses are going online. If you remain unconvinced, here are some compelling reasons why every small business should have a website
 
The security risks of your business website
[December 6, 2007] Having a business website isn’t just a simple matter of getting something set up and playing with the content every now and then. Because your website represents your business on the internet, that makes it a potential target for hackers.
 
Web Conferencing - How to engage an audience
[October 26, 2007] Communicating virtually offers cost savings as well as offering significant improvements in worker productivity and efficiency. Some tips to help ensure better engagement from your audience via web conferencing
 
Blogging - How to set up a blog for your small business
[July 2, 2007] You can get a business blog up and running in about 20 minutes. Here are the 7 simple steps you need to follow.
 
Building an online business from the ground up – Website Builder Tools
[April 25, 2007] Many startups with technical knowledge build their own websites, but this can mean that the money being saved on web development is now being lost in labour time. So what’s the alternative?
 
E-commerce and E-commerce Regulations for Small Businesses
[February 14, 2007] Overview of the basic legal requirements of the E-Commerce Regulations that businesses selling and advertising on line must be aware of and complied with - including what information you are obliged to include on your website.
 
New requirements for business website owners
[January 22, 2007] From 1 January 2007, if your website does not contain the company’s full name – including any trading names, its place of registration and registration number and registered office address, you are committing an offence.
 
Ecommerce in 2007 Is More Profitable & Less Expensive
[January 16, 2007] New research on the state of the UK SME retail market indicates that trading online has become more profitable and less costly to implement, but that few retailers are grasping the opportunity.
 
Guide to working securely with wireless
[January 4, 2007] Keeping vital information safe is critical for workers on the move, particularly on a wireless network. Here are some essential tips for ensuring all data on a wireless network is secure.
 
 Our Partners
Hiscox Office Insurance
Instant Online Quotation
Limited or Umbrella Co.?
Ask Danbro today
Bibby Financial Services
Funding your business
Click HereAccept Online Payments
PayPoint.net Solutions
2 Years FREE Banking
Alliance & Leicester
MORE THAN Business
10% off PI Insurance
Free Day-to-Day Banking
Abbey - 0800 085 3099
Public Liability Insurance
Get online cover now


 Key Services
Company Formation
Instant online setup!
£20 Free Postage
& 30 Day No Ties Trial
Cashflow Problems?
Try Invoice Financing
Phone and Broadband
Great deals for business
Compare Insurance Deals
Essential insurance cover
Virtual Office Service
For full details click here.


Start Up Guides

Click Here


 






















Free Bytestart News feeds