Watch Out!!! A felon is adumbrating there
Monday, December 19th, 2011 | Author:

A flawless and secured PC experience, isn’t it appears what you have dreamt of? But wait a minute. It’s a dangerous world out there. Click on www. and hey, welcome to the hacker’s Shangri-La. A moment spent on internet and that’s enough to get your PC packed like sardines. The only difference is that here sardines are viruses, spyware, adware, rootkits and many such odds and ends. Rootkits especially are proving to be the effective scimitars for hackers to gouge out a hole into your PC’s fortification and then sabotage your personal and financial data in a hush-hush way.

A Rooty Affair

With its etymology lying in word “root”, a name of UNIX administrator, rootkit is a very potent tool in hacker’s kitty that assists the same to take the driver’s seat of your PC. The hacker installs a rootkit on your PC the moment it gets its access by exploiting user-level access or administrator-level access. This can be done either by taking advantage of the known remote vulnerabilities or by using local exploit or cracking administrator password. Once this schemer (rootkit) is in, a slew of cascading effects just get kick started. Equipped with an armada of wicked programs, a rootkit assures that its looting spree can be carried out in an infallible manner. The most infamous among these programs is backdoor, which assists the hacker in gaining unauthorized access of an entire system. The next in the line is the Packet Sniffer, which monitors the data travelling over a network, TCP/IP or other network protocol. Finally, not to forget the log-wiping utilities that masks the lists of actions that have occurred, which assists the mugger to swab down the traces of its devilry.

What’s in the name?

Many versions but with a sole endeavour to ransack the confidential data, that’s what forms the part and parcel of the rootkit contraption. LRK, tOrn, Adore, NTROOT, NTKap, Nullsys and many, many more, the list of these iniquitous charms go on inexhaustible. But techheads pigeonhole the rootkits in two separate categories. The one labelled as conventional is termed as Application rootkit which replaces the useful application with the trojaned file for opening the entry doors for the hackers. As these conventional rootkits can be ensnared by security software, the caballers have come up with second generation of reprobates known as Kernel rootkits. These rootkits establish themselves in the most reliable kernel layer of the operating system to escape from detention. As these can circumvent conventional system integrity checker at application layer, kernel rootkits have came to be the toughest one to confiscate.

Rooting out!

Few simple steps and you will remain at a safe distance from the rootkit assault. Here are some of them:

  • Firewall all the networks.
  • Grant admittance to the concerned users that are needed to perform their jobs to avoid any kind of unauthorized access.
  • After a system is installed, take inventory of what is running.
  • Enable secure communications such as VPNs and Secure Shell.
  • Periodically monitor all log-files.
  • Install host and network based intrusion detection systems.