HP products review


Trojan Horse Delivered In Automatic Update

Titledata collection and deliver it's final blow.
Because of the level of system privilege it
Trojan  Horse  Delivered  In Automatic Updateis running at, it modifies the communication
protocols and services on the system to
Trojan Horse - One Mans "Worse Case Scenario"prevent any type of external communication to
Predictionits local peers and external (Internet)
hosts. It does this in such as way that the
This is a fictional article about a Trojanonly immediate method to recover from this is
Horse Virus, or you could say it is one mansa system roll-back, system repair, or restore
prediction of a "worse case scenario".from near-line media, such as tape or disk.
Because of the field I'm in, I maintain aAnd as far as system recovery is concerned, I
personal list of my top 10 "worse casecan tell you that many people even in
scenarios". Every time I perform a securitycorporate entities do not perform the most
assessment I run into something new orbasic steps to be prepared for a quick system
identify a situation that is ripe for adisaster recovery. In some cases, some of
potential vulnerability. I think we could allthe most important recovery services have
agree that no respectable or ethical companybeen disabled because of lack of system
would intentionally deliver a malicious pieceresources or disk space (which is amazing
of code as part of a helpful update solution.given  how  inexpensive  this  is  anymore).
However, the reality is that human beings are
behind technology and human beings areWhat Could Be The Impact Of This "Trusted"
unpredictable  and  fallible.Trojan  Horse
Many major operating system vendors haveJust about every time you install a new
automatic update services. Many hardwareapplication or piece of software you increase
vendors and other software packages havethe time it takes to boot your PC and in some
followed this trend, incorporating automatedcases decrease its performance. On thing that
update services into their products. In somedrives me crazy is printing software. For the
cases, the services for automatic updates runlife of me I cannot understand how or why
as the local "system" account. This accountprinter support software could total 400MB in
has the ability to access and modify most ofsize, but they sometimes do. Not only that,
the operating system and applicationthey tend to load all kinds of unnecessary
environment. When automatic updates werereal-time running applets. HP printers are
relative new, many people would perform thenotorious for this. Be very aware of what it
updates manually, however, as time hasis you are loading and only load those
progressed, many now trust these services andcomponents that you need. Even some
allow the updates to proceed in a trulyoff-the-shelf software packages load adware
automated  fashion.and other not so helpful applets. Also, when
you uninstall software, not all the software
The  Final  Step  Before  The  Hammer  Fallsgets uninstalled in many cases. One thing I
suggest is to purchase a registry cleaner.
So let's expand upon our "worse caseThis can dramatically decrease boot times and
scenario". A new service pack is just aboutin many cases increase the overall
ready for release. The last step prior toperformance  of  your  PC.
public release is quality control /
validation. The team of people performingPeople are already concerned about identity
this task includes a significantlytheft, or at least they should be. I recently
disgruntled employee (Or may he/she is goingspoke with a business associate that told me
through a horrible life crisis and has notthat even with everything he does to keep his
much to lose). When people are in pain oridentity secure he has been the victim of
distress it is not uncommon for them toidentity theft not once, but twice. If your
project this same feeling onto others in anyuser id's, online accounts, passwords,
way they can. So, instead of performing theirfinancials, or other confidential information
job in the normal fashion, they decide towinds up on the Internet for any anonymous
incorporate a malicious payload into theperson to see, you can bet it will be used in
forthcoming  update.a way to cause you problems. Even if only 10%
of the global systems fell victim to this
The  First Step For The Trojan Horse: EvasionTrojan Horse, the cut off of communications
could cost businesses billions of dollars and
This payload has some unique characteristic,potentially impact their reputation as
three to be precise. First, it is constructed"secure"  institutions.
in such as way to not appear as something
malicious. The anti-virus and anti-spywareConclusion
programs currently on the market won't be
able to detect it through anomalous detectionIf we don't think that this "worse case
techniques.scenario" can happen, then we're kidding
ourselves. Recently, one of the market
The Second Step For The Trojan Horse:leaders in the perimeter defense business had
Information  Collectionto recall a service pack because it contained
a significant "bug" that could result in a
Secondly, it has been instructed to wait 12security breach; a service pack that can be
hours to activate to start searching yourdelivered through and intelligent update
computer an network for important files thatservice. Obviously there has to be a certain
may contain financial, healthcare, and otherlevel of trust between us, the consumer, and
confidential information such as userthe vendors of hardware / software we rely
accounts and passwords. It then sends thison. I'm not entirely sure what "fail-proof"
information to anonymous systems on thesolution can be put in place to prevent
Internet. Because this "Trojan horse" hassomething like this from happening. Although
been incorporated into an automated update byI'm sure there are quite a few checks and
someone with reasonable skills, it isbalances in place already. The bottom line
instructed to only perform the collection ofis, if you or I can image a scenario like
data for 12 hours. Given the number of globalthis, there is always a chance of it
systems that allow automated updates, 12happening. In my case, I usually wait for
hours should be more than enough. The personseveral days to apply new service packs and
behind this realizes that someone willhot-fixes. Hopefully someone else will find
quickly identify that something malicious isthe problem, correct it, and then I'll apply
going on and start to roll-out a defenseit.
solution  to  halt  the  process.
You may reprint or publish this article free
The  Final  Step:  Incapacitateof charge as long as the bylines are
included.
Finally, the Trojan Horse will cease it's



1 A B C D 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97