Examination,Drive-by-Download, computer Examination of a “Drive-by-Download” Many Security Professi


Gone are those times when the companies and the organisations didn't need a hi-tech system to handle them. Owing to the considerable increase in the business sector and thus, an enormous increase in the complexity of the organisational struc ----------------------------------------------------------Permission is granted for the below article to forward,reprint, distribute, use for ezine, newsletter, website,offer as free bonus or part of a product for sale as longas no changes a


Basic Definition:Drive-by downloads may happen when visiting a, viewing an e-mail message or by clicking on a deceptive pop-up window: by clicking on the window in the mistaken belief that, for instance, an error report from the computer' operating system itself is being acknowledged, or that an innocuous advertisement pop-up (pretending to be innocuous) is being dismissed. In such cases, the "supplier" may claim that the user "consented" to the download, although actually the user was unaware of having started an unwanted or malicious software download.Very Common Misconception:When I am interviewing candidates for security positions I always ask them the simple question of explaining what a drive-by-download is and 90% of the time they give me the wrong answer. The most common answer I receive is that it is when you are browsing a website a hacker has uploaded an executable or inserted an iframe with a download link to the file and when they visit the website a file is downloaded in the background without them authorizing it or even seeing it. They tell me it happens behind the scenes and executes.This is dead wrong, if it were that easy to get malware or adware onto a victims machine everyone and their mother would be hosting malware at an astronomical rate. Now this definition had a short time period where that was actually possible in some very early browsers or if a user changes their security settings to automatically download and run any file without question and answer any request it received, but the attacker would still have to rely on the victim willingly opening that file if those settings were not enabled. It's not 1995 anymore, browsers are smarter, people are still gullible and incompetent though.The individuals answering such a question with that type of an answer is a dead give away that they are not very knowledgeable in the field of cyber security. For a user to land on a website and have an executable download and run in the background without their knowledge would require them to be exploited. An exploit kit that has loaded exploits for 0day versions of Java or Flash for example may have injected an iframe into your favorite site and when you visit that site you will trigger the exploit kit process which must then exploit a vulnerable piece of software installed on your machine, once it successfully does that it can then request that an executable be downloaded (which will in fact happen behind the scenes) and be installed. You will at that time be hosting malware unless your AV has really good anomaly or behavioral based detection mechanisms as the signature portion will most likely fail as malware writers modify their malicious binaries daily and run them against AV to make sure they aren't detected. Once the malware becomes known and samples are obtained your AV provider will issue out a signature to prevent future occurrence.99% of drive-by-downloads result in the download of what is known as "adware" or "PUPs" (Possibly unwanted programs) not "malware" as most of their infrastructure is located in the United States and they seek to profit from your download without risking a lawsuit. Therefore, groups delivering drive-by-download software try to take measures to legalize their extremely shady practices. Most commonly you will see a site that will tell you your version of Java or Flash is out of date and you need to upgrade right now, they will inform you to click an install or download link which is packed with adware. They will typically have a very small disclaimer as well which if you read will explain vaguely what you are really downloading.Let's review a common example I see routinely of what a true drive-by-download looks like:I visit a bittorrent site and do a search for a file, a pop-under or new tab opens in my browser simultaneously for a site hosting a drive-by-download:[caption id="attachment_867" align="alignnone" width="1524"] drive-by-download landing page[/caption]If red flags are not going off in your head, something is wrong, check the URL, does it even make sense? Google the domain name, you'll get your answer right off the bat of what you have landed on or what has loaded. Legitimate software companies do not market software in this manner. You should be thinking why would google be advertising with pop-under windows with a domain secureopensoftware.com - do the math, think logically before proceeding.Next step of the drive-by-download:From the first page that I landed on I clicked the X box to close the window, and clicked "no" I don't want to update my software, but yet, here it comes anyway, if you spot the license agreement you will see that even that state that they are in know way affiliated with Google Chrome, yet they are using the copyrighted image on the download page.Example after closing the download window, you'll see another fraudulent statement "Manufacturer: Google" which most certainly is not.Clicking ok on the download or the install button will result in this:As you can see, they are ready to ship me an application to install, I edited the image slightly as there are some folders and directory mappings I would like to remain private. So, the site hosting the download really wants to make sure I run the program as soon as possible, look what happens after I download the file:Like I wouldn't know how to run a file I just downloaded, this type of drive-by-download is extremely successful when targeting young individuals who don't know any better and older users who don't understand how the internet works.The other type of drive-by-download you will rarely see these days is when you land on a page and it immediately prompts you for the download, they haven't even taken the time to craft a fake misleading website, they have simply created a link such as http://blah/blah.exe so when you hit that page a prompt will come up for download - this is less seen because legally speaking they have not afforded the user with any type of risk or acceptance to such a request and law enforcement would have a much easier time going after those hosting such files. In the above case, they have weak legal grounds to stand on because they can claim that you read the license agreement and willingly downloaded the file and installed it. DON'T BE A VICTIM - THESE GROUPS AND THESE TACTICS NEED TO STOP, YOU CAN HELP THAT FIGHT BY NOT BECOMING A STATISTIC.

Examination,Drive-by-Download,

computer

Equipment Rental Software – Features And Cost

Equipment rental management software is an essential thing these days for any equipment rental company.A well-developed equipment rental software provides you with a variety of features that can really help you maintain and organise your cus ...

computer

5 Big Reasons Why I Migrated From Angularjs To React

I have 5 main reasons for my angularjs to react migration. No, it's not a comparison on which is better. A comparison between apples and oranges would make no point. React is a library, and angular is a framework. Both can do stuff in their ...

computer

How to troubleshoot McAfee error 2318?

Security software means McAfee! For many computer users, McAfee antivirus is the only choice for security software as it provides all the features and tools which are necessary for device and data protection. This robust antivirus merely sho ...

computer

Manage Multiple Counter With AlignBooks Point of Sale

Fulfilling your businesss needs which can grow your firm is our aim. AlignBooks is better known for providing a strong pillar to newly started or midway businesss. Those companies who dont want to fall back with irregularity manage the inven ...

computer

How to Autoplay Embedded YouTube Videos

Source: How to Autoplay Embedded YouTube VideosEmbedding a video or audio enables the users to share their videos with any of their preferred sites or any social networking platforms. They can do so by copying the embedded link of the parti ...

computer

3 Major Mistakes to Avoid in Retail Business

Truth be told, nearly half of the retail businesses survive longer than four years and which can be something to ponder for a newbie before stepping into the industry. However, this being said, it is also true that you can excel in the indus ...

computer

Start Your Own Computer Repair Business

1. Know your street value. In the early 90's, running a PC repair business centered around selling parts and products, with service on the side. Today, it's about selling hours. If you run a business, you need to consider the X3 rule. That m ...

computer

How Establishments Show Up in Restaurant Searches

The revolutionary rise of technology has made things easy-peasy for consumers in the restaurant industry. Unlike the old days, the availability of innumerable platforms has made it possible for diners to choose from various searching options ...

computer

GuildWars 2 :

The last expansion pack for Guild Wars 2 was Path of Fire, which was released in 2017 and brings you a new enemy-Balthazar, the evil god of war. Although this doesn't sound like another expansion pack currently in production, some fans ma ...

computer

Customer Support at the time of COVID-19 Pandemic

COVID-19 is the worst crisis of our time as we observe social distancing protocols being imposed all around the world. While these measures are a step in effectively managing the COVID-19 pandemic, Hospitality and Retail businesses are confr ...

computer

How to Choose a Contract Management Solution (CLM)?

Contract life cycle management (CLM) systems can simplify and automate contract creation, negotiation, execution and storage. They are an intelligent alternative to the tedious hand tools formerly used for these tasks, which lacked visibili ...

computer

Contacting Google Live Person to Resolve Your Issues

Users are fond of all the Google supported products and look forward to the best services. Also, Google as a whole has never disappointed its users and helped them at every point with its commendable services. Also, being a customer-oriente ...

computer

how to uninstall discord

How to Uninstall Discord in Windows 10? has supported open source technologies, our tool is secure and safe to use. To uninstall a discord from your windows, you'll use this method which is given below.USING THIRD PARTY TOOLS1. Firstly, you ...