{"id":4402,"date":"2013-08-30T11:00:12","date_gmt":"2013-08-30T09:00:12","guid":{"rendered":"http:\/\/blogs.sun.ac.za\/it\/?p=4402"},"modified":"2013-08-30T12:17:53","modified_gmt":"2013-08-30T10:17:53","slug":"attack-of-the-trojans-bots-zombies","status":"publish","type":"post","link":"https:\/\/blogs.sun.ac.za\/it\/2013\/08\/attack-of-the-trojans-bots-zombies\/","title":{"rendered":"<!--:en-->Attack of the trojans, bots &#038; zombies<!--:--><!--:af-->Die trojane, bots &#038; zombies val in<!--:-->"},"content":{"rendered":"<p><!--:en--><\/p>\n<div>Once of the most common questions we are asked by users is: How do these spammers get my e-mail address? Previously we looked at <a href=\"http:\/\/blogs.sun.ac.za\/it\/2013\/08\/16\/how-do-spammers-get-your-e-mail-address-part-1-rumplestiltskin-attack\/\" target=\"_blank\">Rumpelstiltskin <\/a>attacks and this week we will focus on the second of the methods<strong> &#8211; \u00a0<\/strong>by using <em>Trojan Horses, Bots and Zombies<\/em>. Now, thet may sound like something from a movie, but they do pose quite a serious threat to you as e-mail user.<\/div>\n<div>\n<p>Let us use a familiar example.\u00a0You regularly exchange emails with your elderly mother who has a computer. Your mother uses Outlook or Thunderbird and has dozens of emails from you in her inbox. She even added you to her address book. She also has lots of emails from a distant family member \u2013 cousin<em>\u00a0<\/em>Johan from Australia. You haven\u2019t stayed in touch with Johan that closely over the years, but you definitely know who he is.<\/p>\n<p>Last year, just before the Christmas, Johan downloaded and installed this really pretty Christmas screensaver that showed tranquil tree and candle scenes when he wasn\u2019t using the computer. What he didn\u2019t know was that the screen saver had a sinister hidden payload. While the candles flickered peacefully on his screen, the software went to work combing through his emails and address book, his browser\u2019s cache of past webmail sessions and other files, storing every email address it would find in a separate list.<\/p>\n<p>Then it sent the entire list to a server in Russia, where a criminal combined it with other such submissions to build the ultimate monster spam list that can be sold and resold over and over again.<\/p>\n<p>But as if that wasn\u2019t enough, when the \u201cscreensaver\u201d sent the address list to Russia, it received some content in return \u2013 messages to be sent to all of Johan\u2019s contacts. Then, unbeknownst to John, his computer started creating hundreds of emails randomly using the harvested email addresses in the To: and From: field along with the content from the Russian server and sent them out using Johan\u2019s Internet connection. One of them used your mother\u2019s email address as sender and yours as recipient.<\/p>\n<p>Now you received some spam from your mother asking you to buy fake watches and you\u2019re ready to speak to her telling her to stop. Well, don\u2019t. Your mother has obviously nothing to do with the whole thing and you\u2019ll never find out that it was actually Johan\u2019s computer.<\/p>\n<p>You just had a look into the really nasty underworld of the Internet where\u00a0<strong>botmasters\u00a0<\/strong>(the guy in Russia) control\u00a0<strong>botnets<\/strong>\u00a0(infected computers that all report to the same server) of remote-controlled\u00a0<strong>zombies<\/strong>\u00a0(Johan\u2019s computer) that were compromised using\u00a0<strong>trojan horses<\/strong>\u00a0(the screensaver) or similar\u00a0<strong>malware<\/strong>.<\/p>\n<p>And it doesn\u2019t even end there. The botmaster typically doesn\u2019t spam for his own account but hires out his botnet to whoever pays the most. The equally shady factory in China wanting to sell more fake Rolexes can now hire the botmaster to blast their offers all over the internet. The guy in Russia doesn\u2019t even care if you open or click on that email from your mother, he gets paid either way. And when he\u2019s done with the watches, he\u2019ll inform his entire mailing list that they all won the lottery and can pick up the prize if only they pay a small \u201ctransfer fee\u201d up front. And after that, he\u2019ll mail a Paypal phish for yet another \u201cclient\u201d. And for good measure, he\u2019ll sell his entire email address database, incl. yours, to a friend who is in the same line of \u201cbusiness\u201d.<\/p>\n<p>In other words, once your email address got picked up by a\u00a0<strong>botnet<\/strong>, Pandora\u2019s Box is wide open. The whole scheme is particularly wicked because now you have to depend on others to keep your address safe. Unfortunately, there is little you can do:<\/p>\n<ul>\n<li>First of all, do your own share:\u00a0<strong>NEVER open email attachments<\/strong>\u00a0that you didn\u2019t ask for, even if they appear to come from good friends like Johan. If you\u2019re still curious, ask Johan or your mother first if they really sent it.<\/li>\n<li><strong>NEVER download anything<\/strong>\u00a0where you can\u2019t in\u00adde\u00adpend\u00adent\u00adly verify it\u2019s safe. With<em>\u201cindependently verify\u201d<\/em>\u00a0I mean you can read about it in forums, blogs, news sites, your local \u201ccomputer geek\u201d etc. Facebook fan pages, even with 1000s of \u201cfans\u201d, do NOT count, they are way too easy to manipulate and are usually full of misinformation!<\/li>\n<li><strong>NEVER get fooled by fake<\/strong>\u00a0<strong><em>\u201csecurity scans\u201d<\/em><\/strong>\u00a0<em>(they\u2019re quite the opposite!)<\/em>\u00a0or<em>\u201cvideo codec updates\u201d<\/em>\u00a0to see that funny kitten clip. If you think you need a new Flash player, type in flash.com by hand and update from there. If afterwards the site still says you need an<em>\u00a0\u201cupdate\u201d<\/em>\u00a0get out of there as fast as you can.<\/li>\n<li>Then\u00a0<strong>educate your friends and family<\/strong>\u00a0about the same. Explain how trojans work. Send them a link to this blog page!<\/li>\n<li>You can try having\u00a0<strong>multiple private email addresses<\/strong>. Keep a super-private one, only for family and very few of your closest friends.<em>\u00a0<\/em>\u00a0Use your university address for everyone you work with and don\u2019t use this for private mail \u2013 EVER! \u00a0Get a semi-private one for your wider social circle. The latter two do get some spam, although it\u2019s still manageable.\u00a0<em>GMail has a very good \u201cspam filter\u201d, and blacklisting spammers is very easy!<\/em><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p style=\"text-align: right;\">[ARTICLE BY DAVID WILES &amp; MATERIAL BY <a href=\"http:\/\/www.bustspammers.com\/still-get-spam-how-got-address.html\">BustSpammers.com<\/a>]<\/p>\n<\/div>\n<p><!--:--><!--:af--><\/p>\n<div>Een van die algemeenste navrae wat ons by gebruikers kry, is &#8211; &#8220;Hoe kry gemorsposversenders my e-posadres?!&#8221;. By `n vorige geleentheid het ons gekyk na\u00a0<a href=\"http:\/\/blogs.sun.ac.za\/it\/2013\/08\/16\/how-do-spammers-get-your-e-mail-address-part-1-rumplestiltskin-attack\/\" target=\"_blank\">Repelsteeltjie<\/a>-aanvalle en die keer kyk ons na `n tweede metode, die gebruik van <em>Trojaanse perde, robotte en zombies.<\/em> Dit klink nou wel soos iets uit `n fliek, maar ten spyte van hul belaglike name, hou al drie `n gevaar in vir jou as e-posgebruiker.<\/div>\n<div>\n<p>Kom ons gebruik `n bekende voorbeeld. Jy stuur gereeld e-posse aan jou ma wat onlangs `n rekenaar gekry het. Sy gebruik Outlook of Thunderbird en het dosyne e-posse van jou in haar posbus. Sy&#8217;t jou selfs bygevoeg as `n kontak in haar adresboek. Sy kry ook gereeld e-pos van `n verlangse familielid &#8211; neef Johan van Australi\u00eb. Jy en Johan het nie regtig kontak nie, maar jy weet definitief wie hy is.<\/p>\n<p>Verlede jaar, net voor Kersfees, het Johan &#8216;n baie oulike Kersfees skermskut (&#8220;screensaver&#8221;) afgelaai wat `n feestelike boom en flikkerende kersies wys as hy weg is van sy rekenaar. Wat Johan egter nie geweet het nie, is dat, terwyl die kersies vrolik geflikker het, die skermskut op die agtergrond besig was met ander aktiwiteite. Die sagteware wat Johan installeer het, het stelselmatig deur sy e-posse, adresboek, webblaaier se kasgeheue en ander le\u00ears gesoek en elke e-pos adres wat dit kon opspoor, geb\u00eare op `n lys.<\/p>\n<p>Die program het daarna die saamgestelde lys na `n bediener in Rusland versend waar `n kuberkrimineel dit kombineer het met soortgelyke lyste om `n super-lys saam te stel wat oor en oor verkoop kan word. Asof dit nie genoeg was nie, het die program ook boodskappe aan al Johan se kontakte gestuur. Sonder dat Johan bewus was, het sy rekenaar honderde e-posse geskep deur middel van die ge-oeste adresse, saam met die inhoud van die Russiese bediener en dit uitgestuur via Johan se adres en internetkonneksie. Een hiervan het jou ma se e-posadres as versender en joune as ontvanger gebruik.<\/p>\n<p>Ewe skielik kry jy nou e-pos van jou ma oor nagemaakte horlosies en verskeie ander gemorspos. Natuurlik het sy het niks daarmee te doen nie en jy sal waarskynlik nooit uitvind dat Johan se rekenaar eintlik die skuldige party is nie.<\/p>\n<p>Dit was `n kykie in die nare onderw\u00eareld van die Internet waar &#8220;<strong>botmasters&#8221;\u00a0<\/strong>(die ou in Rusland) &#8220;<strong>botnets&#8221;<\/strong>\u00a0(besmette rekenaars wat almal aan dieselfde rekenaar rapporteer) beheer of afstandbeheerde\u00a0<strong>zombies<\/strong>\u00a0(Johan se rekenaar) wat blootgestel is d.m.v.\u00a0<strong>trojaanse perde<\/strong>\u00a0(die skermskut) of soortgelyke &#8220;<strong>malware&#8221;<\/strong>.<\/p>\n<p>En daar hou dit nie op nie. Die &#8220;botmaster&#8221; huur gewoonlik net die &#8220;botnet&#8221; uit aan wie ookal die meeste betaal. Die ewe verdagte fabriek in China wat nog meer nagemaakte Rolex-horlosies wil verkoop kan dit, onder andere, huur om hul e-posse te versprei. Daarna verkoop hy die lys ten duurste aan ander suspisieuse besighede, jou adres ingesluit.\u00a0<\/p>\n<p>Met ander woorde, as jou adres opgetel word deur `n &#8220;<strong>botnet&#8221; <\/strong>is die deure wawyd oop. Ongelukkig is daar nie baie wat jy kan doen om dit te voorkom nie, maar jy kan op die volgende let:<\/p>\n<ul>\n<li>Moet nooit e-pos aanhangsels oopmaak waarvoor jy nie gevra het nie &#8211; selfs al is dit van iemand wat jy ken. As jy wel nuuskierig is, vra vir die persoon of hulle dit gestuur het. \u00a0<strong><br \/><\/strong><\/li>\n<li>Moet nooit iets aflaai as jy nie self kan verifieer dat dit veilig is nie. Lees eers op daaroor op\u00a0forums, blogs, webwerwe of vind uit by kenners.<\/li>\n<li>Moenie val vir sekuriteitswaarskuwings of video-opdaterings om daai oulike katprentjie te sien nie. As jy dink jy het `n Flash-speler nodig, laai dit af van die webwerf self.<em><br \/><\/em><\/li>\n<li>Deel hierdie inligting met jou vriende en familie.\u00a0<\/li>\n<li>Om veilig te speel kan jy meer as een e-posadres gebruik. Kry `n privaat adres vir jou naaste vriende, `n tweede een vir kennisse en gebruik jou sun-adres net vir jou kollegas, nie vir privaat aangeleenthede nie.\u00a0GMail het byvoorbeeld `n baie goeie gemorsposfilter en dis maklik om ontslae te raak van ongewenste e-posse.<em>\u00a0<\/em><\/li>\n<\/ul>\n<p style=\"text-align: right;\">[BRON:\u00a0<a href=\"http:\/\/www.bustspammers.com\/still-get-spam-how-got-address.html\">BustSpammers.com<\/a>\u00a0&amp; David Wiles]<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<p><!--:--><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Once of the most common questions we are asked by users is: How do these spammers get my e-mail address? Previously we looked at Rumpelstiltskin attacks and this week we will focus on the second of the methods &#8211; \u00a0by using Trojan Horses, Bots and Zombies. Now, thet may sound like something from a movie, [&hellip;]<\/p>\n","protected":false},"author":259,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20382,29187],"tags":[27588,29233,29170,29175,29232],"class_list":["post-4402","post","type-post","status-publish","format-standard","hentry","category-email","category-security-2","tag-bank-emails","tag-bots","tag-malware","tag-trojan","tag-zombies"],"publishpress_future_action":{"enabled":false,"date":"2026-07-30 09:40:36","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/4402","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/users\/259"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/comments?post=4402"}],"version-history":[{"count":10,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/4402\/revisions"}],"predecessor-version":[{"id":4461,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/4402\/revisions\/4461"}],"wp:attachment":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/media?parent=4402"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/categories?post=4402"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/tags?post=4402"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}