ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

Hack attacks on home PCs increase

Matt Loney ZDNet.co.uk

Published: 29 Aug 2001 17:22 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The last three months have seen a significant rise in so-called intruder attacks directed at home users, according to the latest quarterly report from the US-based CERT Coordination Centre.

Intruder attacks are defined as anything from packet sniffers, which capture data from plain text email and other information as they travel over the network, to email viruses -- not just hacking attacks.

PCs running Windows are particularly vulnerable. Unprotected Windows networking shares are singled out as one weakness often found in home PCs, allowing hackers to place tools on large numbers of Windows-based computers attached to the Internet. Windows is also singled out for its option to "Hide file extensions for known file types", which is enabled by default, making it difficult for many people to spot extensions such as .vbs on files. Many email viruses -- such as Love Letter -- arrive as Visual Basic files with .vbs extensions.

According to CERT, home users are particularly vulnerable to compromises of their PCs because "they do not keep them up to date with security patches and workarounds, do not run current anti-virus software, and do not exercise caution when handling email attachments."

"Intruders know this," said CERT in its advisory, "and we have seen a marked increase in intruders specifically targeting home users who have cable modems and DSL connections".

PCs connected to the Internet by cable modem or DSL are more vulnerable to hacker attacks than PCs connected by dial-up modem. Of these two broadband connections, says CERT, PCs connected by cable modems are the most vulnerable. This is because entire neighbourhoods of cable modem users are effectively part of the same LAN. A packet sniffer installed on any cable modem user computer in a neighbourhood may be able to capture data transmitted by any other cable modem in the same neighbourhood.

One former hacker known by the tag RaFa, who built up a notoriety for defacing Web sites when he was affiliated to a group called World of Hell (WoH), said home PCs are very much at risk from such attacks. Referring to the Network Address Translation method that is used to 'hide' home PCs from the Internet, RaFA told ZDNet: "A gateway device that controls the natting functions is typically the first system compromised (i.e. wingate, ipchains, etc) and than used as a launchpad to attack the internal machines it is natting for."

But CERT warns that while DSL access is not susceptible to packet sniffing and NAT attacks as cable modem access, many of the other security risks apply to both forms of access. And not even PCs on dial-up connections are immune from some of the most common security risks, such as email worms.

Other threats to home PCs include email spoofing, where an email that apparently originates from a reputable source tricks the user into releasing sensitive information. Weaknesses in chat clients are also cited, as are Trojan horse programs, which trick users into installing software that gives intruders easy access to a PC. On Windows computers, three tools commonly used by intruders to gain remote access to PCs are BackOrifice, Netbus and SubSeven.

RaFa, who is now senior research scientist at Fate Research Labs, said the diversity of files and information obtained from home systems range from credit card account numbers to online bill payment details, Word documents containing social security numbers from letters, and online brokerage accounts. "What home users need to understand is that security maintained with the Web site you use for business is not the weakest link in the chain. The weakest link will always be you and how strong your own security is on your machine."

For firewalls and other security downloads on ZDNet UK, click here.

See the Viruses and Hacking News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
22 out of 55 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Discussions

1000030281 1000030281

Facebook Bans Firefox 3

Sunday 20 July 2008, 2:33 AM

1 comment
roger andre roger andre

SP3 Under Suspicion Again

Saturday 19 July 2008, 9:29 PM

2 comments

Blog Posts

Avatar roger andre

Facebook Bans Firefox 3

Saturday 19 July 2008, 7:54 PM

1 comment
Avatar geek

Windows Vista

Friday 18 July 2008, 7:58 PM

0 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme