官术网_书友最值得收藏!

Exploits and compromised websites

Exploits are also categorized under malware. Exploits are crafted to compromise specific vulnerabilities of software or network services. These are usually in the form of binary data. Exploits take advantage of vulnerability, thereby causing the target software or service to behave in such a manner that the attacker intends it should behave. Usually, the attacker intends to gain control over the target system or simply take it down.

Once an attacker identifies vulnerabilities on its target, an exploit is crafted containing code that would download malware that can give the attacker more access. This concept was used to develop exploit kits. Exploit kits are a set of known vulnerability scanners and known exploits packaged as a toolkit.

The following diagram gives an example:

In a malware campaign, social engineering is used to lure users to visit links that are actually compromised. Usually, the compromised sites were manually hacked and have been injected with a hidden script that redirects to another website. The malicious links are spammed to email messages, instant messaging, and social networking sites. Visiting legitimate sites that are compromised with malicious advertisements also counts as bait. These sites include software or media piracy sites, the dark web, or even pornographic sites. Once the user clicks the link, typically, the site redirects to another compromised site, and to another, until it reaches the exploit kit landing gate page. From the user's internet browser, the exploit kit gate gathers information on the machine, such as software versions, and then determines whether or not the software is known to be vulnerable. It then delivers all exploits applicable to the vulnerable software. The exploits typically contain code that will download and execute malware. As a result, the unaware user gets a compromised system.

主站蜘蛛池模板: 隆回县| 屏边| 蓝山县| 绍兴县| 乌鲁木齐市| 新绛县| 克拉玛依市| 都兰县| 芮城县| 五台县| 鹿泉市| 泗阳县| 讷河市| 洪洞县| 元谋县| 连州市| 长沙市| 孝昌县| 绥棱县| 仁布县| 郑州市| 察隅县| 泰和县| 平原县| 庆安县| 刚察县| 全椒县| 竹山县| 麟游县| 杭锦后旗| 渭南市| 海盐县| 大渡口区| 隆尧县| 连江县| 泗阳县| 乐陵市| 衡东县| 卢湾区| 宁河县| 九寨沟县|