Trojan Horse Delivered In Automatic Update

Trojan Horse - One Mans "Worse Case Scenario"the communication protocols and services on the
Predictionsystem to prevent any type of external
---------------------communication to its local peers and external
This is a fictional article about a Trojan Horse(Internet) hosts. It does this in such as way that
Virus, or you could say it is one mans predictionthe only immediate method to recover from this
of a "worse case scenario". Because of the fieldis a system roll-back, system repair, or restore
I'm in, I maintain a personal list of my top 10from near-line media, such as tape or disk. And as
"worse case scenarios". Every time I perform afar as system recovery is concerned, I can tell
security assessment I run into something new oryou that many people even in corporate entities
identify a situation that is ripe for a potentialdo not perform the most basic steps to be
vulnerability. I think we could all agree that noprepared for a quick system disaster recovery. In
respectable or ethical company would intentionallysome cases, some of the most important
deliver a malicious piece of code as part of arecovery services have been disabled because of
helpful update solution. However, the reality is thatlack of system resources or disk space (which is
human beings are behind technology and humanamazing given how inexpensive this is
beings are unpredictable and fallible.Many majoranymore).What Could Be The Impact Of This
operating system vendors have automatic update"Trusted" Trojan Horse
services. Many hardware vendors and other---------------------
software packages have followed this trend,Just about every time you install a new
incorporating automated update services into theirapplication or piece of software you increase the
products. In some cases, the services fortime it takes to boot your PC and in some cases
automatic updates run as the local "system"decrease its performance. On thing that drives
account. This account has the ability to accessme crazy is printing software. For the life of me I
and modify most of the operating system andcannot understand how or why printer support
application environment. When automatic updatessoftware could total 400MB in size, but they
were relative new, many people would performsometimes do. Not only that, they tend to load all
the updates manually, however, as time haskinds of unnecessary real-time running applets. HP
progressed, many now trust these services andprinters are notorious for this. Be very aware of
allow the updates to proceed in a truly automatedwhat it is you are loading and only load those
fashion.The Final Step Before The Hammer Fallscomponents that you need. Even some
---------------------off-the-shelf software packages load adware and
So let's expand upon our "worse case scenario".other not so helpful applets. Also, when you
A new service pack is just about ready foruninstall software, not all the software gets
release. The last step prior to public release isuninstalled in many cases. One thing I suggest is
quality control / validation. The team of peopleto purchase a registry cleaner. This can
performing this task includes a significantlydramatically decrease boot times and in many
disgruntled employee (Or may he/she is goingcases increase the overall performance of your
through a horrible life crisis and has not much toPC.People are already concerned about identity
lose). When people are in pain or distress it is nottheft, or at least they should be. I recently spoke
uncommon for them to project this same feelingwith a business associate that told me that even
onto others in any way they can. So, instead ofwith everything he does to keep his identity
performing their job in the normal fashion, theysecure he has been the victim of identity theft
decide to incorporate a malicious payload into thenot once, but twice. If your user id's, online
forthcoming update.The First Step For The Trojanaccounts, passwords, financials, or other
Horse: Evasionconfidential information winds up on the Internet
---------------------for any anonymous person to see, you can bet it
This payload has some unique characteristic,will be used in a way to cause you problems.
three to be precise. First, it is constructed in suchEven if only 10% of the global systems fell victim
as way to not appear as something malicious. Theto this Trojan Horse, the cut off of
anti-virus and anti-spyware programs currently oncommunications could cost businesses billions of
the market won't be able to detect it throughdollars and potentially impact their reputation as
anomalous detection techniques.The Second Step"secure" institutions.Conclusion
For The Trojan Horse: Information Collection---------------------
---------------------If we don't think that this "worse case scenario"
Secondly, it has been instructed to wait 12 hourscan happen, then we're kidding ourselves.
to activate to start searching your computer anRecently, one of the market leaders in the
network for important files that may containperimeter defense business had to recall a service
financial, healthcare, and other confidentialpack because it contained a significant "bug" that
information such as user accounts and passwords.could result in a security breach; a service pack
It then sends this information to anonymousthat can be delivered through and intelligent
systems on the Internet. Because this "Trojanupdate service. Obviously there has to be a
horse" has been incorporated into an automatedcertain level of trust between us, the consumer,
update by someone with reasonable skills, it isand the vendors of hardware / software we rely
instructed to only perform the collection of dataon. I'm not entirely sure what "fail-proof" solution
for 12 hours. Given the number of global systemscan be put in place to prevent something like this
that allow automated updates, 12 hours should befrom happening. Although I'm sure there are quite
more than enough. The person behind this realizesa few checks and balances in place already. The
that someone will quickly identify that somethingbottom line is, if you or I can image a scenario like
malicious is going on and start to roll-out athis, there is always a chance of it happening. In
defense solution to halt the process.The Finalmy case, I usually wait for several days to apply
Step: Incapacitatenew service packs and hot-fixes. Hopefully
---------------------someone else will find the problem, correct it, and
Finally, the Trojan Horse will cease it's datathen I'll apply it.You may reprint or publish this
collection and deliver it's final blow. Because of thearticle free of charge as long as the bylines are
level of system privilege it is running at, it modifiesincluded.