The Psy Bin

Before you read this (or any) blog, ride the Clue Train. If you know me, you will get it. If you don't, should I care........... **Get Yourself Committed**

Wednesday, January 14, 2009

Internet Explorer, Firefox and NoScript...Adware Writer Speaks

Before you read the section I found, know thatI am not saying that IE is more dangerous...I post this to say that the market share makes it less safe, and NoScript under FF stops everything cold, if you choose...

From the article:

S: Can you tell me more about your strategies for persistence?

M: Yes. I should probably first speak about how adware works. Most adware targets Internet Explorer (IE) users because obviously they’re the biggest share of the market. In addition, they tend to be the less-savvy chunk of the market. If you’re using IE, then either you don’t care or you don’t know about all the vulnerabilities that IE has.

IE has a mechanism called a Browser Helper Object (BHO) which is basically a gob of executable code that gets informed of web requests as they’re going. It runs in the actual browser process, which means it can do anything the browser can do– which means basically anything. We would have a Browser Helper Object that actually served the ads, and then we made it so that you had to kill all the instances of the browser to be able to delete the thing. That’s a little bit of persistence right there.

If you also have an installer, a little executable, you can make a Registry entry and every time this thing reboots, the installer will check to make sure the BHO is there. If it is, great. If it isn’t, then it will install it. That’s fine until somebody goes and deletes the executable.

0 Comments:

Post a Comment

<< Home