documento muy interesante, bof en poison ivy
Targeted attacks:
From being a victim to counter attacking
Andrzej Dereszowski
SIGNAL 11
deresz@signal11.eu
March 15, 2010
Abstract
This paper is an analysis of a common sort of targeted attack per-
formed nowadays against many organizations. As it turns out, publicly
available remote administration tools (which we usually call trojans)
are frequently used to maintain control over the victim after a success-
ful penetration. The paper does not focus on particular exploitation
techniques used in these attacks. Instead, it aims to get a closer look
at one of such trojans. First chapters describe a way to gure out
which trojan has been used. The following chapters describe in brief
the architecture, capabilities and techniques employed by developers
of the identied trojan, including mechanisms to hide its presence in
the system, and to cover its network trace. The paper presents all the
techniques used to perform the analysis. In the nal chapters, a quick
vulnerability analysis has been performed to show that such intruders
could also be an object of an attack. . .
pdf completo 28paginas
http://www.signal11.eu/en/research/articles/targeted_2010.pdf










Autor



En línea






