Trojan horse (computing)

From Wikipedia, the free encyclopedia
Jump to: navigation, search
Beast, a Windows-based backdoor Trojan horse

A Trojan horse, or Trojan, is software that is intended to perform, simultaneously, a desirable (expected) effect and a covert (unexpected) effect. Trojan horses can make copies of themselves, steal information, or harm the computer system.[1] The term is derived from the Trojan Horse story in Greek mythology. Some of the most popular trojan horses are Netbus, Subseven and Y3K RAT.

Contents

[edit] Purpose and uses

[edit] Malware

Malware is a destructive program that masquerades as a benign application. Unlike viruses, Trojan horses do not replicate themselves, but they can be just as destructive. One of the most insidious types of Trojan horse is a program that claims to get rid of viruses but instead introduces viruses onto the computer.

The term is adapted from its use in Greek mythology, specifically the Battle of Troy. The Greeks hid their army inside a hollowed, wooden horse and gave it to the City of Troy as a gift. Once inside city walls the Greek army exited and conquered Troy. In computer technology the term is used to hide code with one specific purpose, inside other code with a different purpose. A trojan is one of the three major types of malware (trojan horses, viruses and worms).

[edit] Security

Trojan may allow a hacker remote access to a target computer system. Once a Trojan has been installed on a target computer system, a hacker may have access to the computer remotely and perform various operations, limited by user privileges on the target computer system and the design of the Trojan.

Operations that could be performed by a hacker on a target computer system include:

Trojan horses in this way require interaction with a hacker to fulfill their purpose, though the hacker need not be the individual responsible for distributing the Trojan horse. It is possible for individual hackers to scan computers on a network using a port scanner in the hope of finding one with a malicious Trojan horse installed, which the hacker can then use to control the target computer.[2]

A recent innovation in Trojan horse code takes advantage of a security flaw in older versions of Internet Explorer and Google Chrome to use the host computer as an anonymizer proxy to effectively hide internet usage. The hacker is able to view internet sites while the tracking cookies, internet history, and any IP logging are maintained on the host computer. The host computer may or may not show the internet history of the sites viewed using the computer as a proxy. The first generation of anonymizer Trojan horses tended to leave their tracks in the page view histories of the host computer. Newer generations of the Trojan horse tend to "cover" their tracks more efficiently. Several versions of Slavebot have been widely circulated in the US and Europe and are the most widely distributed examples of this type of Trojan horse.[2]

[edit] Current use

Due to the popularity of botnets among hackers and the availability of advertising services that permit authors to violate their users' privacy, Trojan horses are becoming more common. According to a survey conducted by BitDefender from January to June 2009, "Trojan-type malware is on the rise, accounting for 83-percent of the global malware detected in the world". This virus has a relationship with worms as it spreads with the help given by worms and travel across the internet with them. [3]

BitDefender also states that approximately 15% of computers are botnets - usually an effect of a Trojan infection.[4]

[edit] Popular Trojan Horses

  • Netbus (by Carl-Fredrik Neikter)
  • Subseven (by Mobman)
  • Y3K Remote Administration Tool (by Konstantinos & Evangelos Tselentis)
  • Back Orifice (Sir Dystic)

[edit] See also

[edit] References

  1. ^ [1]
  2. ^ a b Jamie Crapanzano (2003): "Deconstructing SubSeven, the Trojan Horse of Choice", SANS Institute, Retrieved on 2009-06-11
  3. ^ BitDefender.com Malware and Spam Survey
  4. ^ Datta, Ganesh. "What are Trojans?". SecurAid. http://securaid.com/index.php/windows/trojans. 

[edit] External links

Personal tools
Namespaces
Variants
Actions
Navigation
Interaction
Toolbox
Print/export
Languages