From the network security threats -password the back door

This is the earliest and most ancient method. Through the crack password weak account, to get the system control. After seizing control, can reset the password and identity, as the entrance into the system.

In the information system, will have the user’s identity verification procedures. Through the control of the process of the source code to the back door, sequence password require special treatment, can obtain system privileges.

(2) Login the back door

This is the commonly used method in the Unix system. An intruder from gaining access to Login. C source code generation, and implanted the back door password. When the user input back door after the password, make its neglect of the librarian password. This method strong concealment.

(3) service the back door

Unix and Linux because the code is easy to get to, so the two system version pay particular attention to, especially from network downloaded program.

This method is mainly through the special TCP port, the invaders for Acer 3810T battery this some port through remote connection, get control of the server, and complete the invasion of action.

(4) process hidden door

Hidden process is commonly used in Windows, hackers technology especially under the system. “The process of hidden to hide the trace of starting the program, avoid is seen in all users from invasion to run the program. Use process back door that invasion in hidden process with household display process list will not be displayed.

(5) network through the back door

The invaders through the network through the back door hide their network connection. This method through the known as the network port communication, sometimes can make the invaders bypass firewall.

(6) DOS-the most simple and efficient attack

DOS attack Chinese name is “denial of service attack”, do not arrive destination attack is a denial of service attack.

DOS the Internet is common attack, the nature of the attack way is to make the hardware and software to lose the ability of Banks to offer services to users.

DOS attack according to specific target can be summarized as two: in the attack against the network hardware and the attack.

The attack on the hardware is the main hardware weaknesses attack. The typical party type is using the network equipment oneself the flaws of the processing mechanism, the devices to hang up, or restart the collapse, so that the network interruption.

Network attack is to use the defects of the agreement, sends a packet, make sure that the server hang or reduce the performance, as do not arrive destination attack. DOS to preventing, there are some common methods:

(1) restrain radio address;

(2) filter ICMP, the PING and UDP communication;

(3) through the timing mechanism effectively control communication queue the number of hang up;

(4) use a firewall, filter invalid connection request.

(7) note holes

Vulnerability is

Holes are hardware, network, and software design reason because by the defects. Discover the network, computer hardware and software vulnerabilities in the world, is this not tired of hackers happy things. And in the so-called hacker culture inside, these loopholes to be made public. Of course, the purpose is to promote the public seems to the quality improvement of software, another effect, it is to let the man attacking you also share the loophole.

System vulnerabilities was found most is Microsoft’s Windows, almost every new version came out, and immediately you will in the network spread the corresponding loophole report. And, of course, and can’t say is the worst in the world of the Windows operating system, just because the use of the most, and hackers seems to most interested in it.

In an early version of Windows, a notorious input method holes.

After Windows startup, show this most familiar login screen, asked to enter with account and password. Pay attention to the average user name is the default, as long as the input password. If the password is not correct, Windows will not allow the user to enter.

Use password verified identity, it is the most common system security measures. Unfortunately, Windows here HP NC6300 battery made a super low error. When start Windows into login tip interface, any user can through the “Microsoft pinyin input method”, “QuanPin input method” and “zheng code”, three input method of switching, and then into the “help” of the input method. Use the help of input method, can open system resource manager. Appear at this time what was the result?

This means that has been around a user login mechanism. If the user “Administrator” default Administrator users without modifying words, intruders have Administrator’s identity, can do as they wish.

This loophole has quickly corrected. But like a lot. For the software speaking, all the error is called the worm, Bug, this is very humor, a few ‘the little mistake, even give you called caused again big losses.

May be the most famous worm is “millennium bug…….” This worm is also known as the “two thousand, years problem”, americans also is called it “the Y2K”.

Computer problem is simple. It is a PC in the 1980 s was IBM, it was the invention of the storage space is very precious, # so adopted a kind of save resources is to s method, the top two save, for example, on January 1, 1996, in computers save as “on January 1, 96″. This representation is too lack of foresight, how have no thought of the 21 st century will come so quickly?

Of course, the y2k bug crisis passes quickly. But do you know when the problem to the outbreak of the American government doing anything? ^

The United States congress to pass a bill: because the loss caused by computer problem of software ^ and computer company shall not be prosecuted.

(8) the E-mail

E-mail the Internet is the earliest and most successful application and is in addition to web site users other than most tool of communication, of course is the target of information and tools. And E-mail relevant information against mainly has:

(1) attack mail server

Mail server on the network to provide mail service host and software system. To post a server to attack is part of the network attack, almost all of the network attack means can be used for attack server. The difference is, still can use email against mail server. Imagine, if you to transfer large junk mail server information, there will be any problems. Let it stop service too simple. Of course, here the attacker will know how to hide his, it’s too easy to turn off the account, or junk information is a filter out.

Mail bombs is doing just that.

(2) through the monitoring network to steal the email address

Before we introduced the sniffer. May be you’ll feel very strange and your E-mail address and not to open, how always have everywhere spam find you.

Tell you, this thing is sniffer. Use sniffer capture mail box from the network address is very simple, because every email address is such format-XXX@xxx.xxx. This feature is too obvious, pay attention to the @ symbol, put on both sides of the string took it down, almost one hundred percent is the email address.

(3) against the mailbox

Very simple, direct to your mailbox send information is it. Let your mailbox were blocked, or used to let you see something you don’t want to look at the information. If you exhausted every day next class to go home, sit to a computer, and prepared to deal with some friends to your email, but you received dozens of junk e-mails feeling is very depressed.

The attack to mail still have a kind of method, is Dell 5000e battery from the network your account number, when intercepted but including password. Then, you will never have no secret.

For some sensitive department, it is forbidden to use the Internet mail transfer is correct.

(4) use email to send illegal or junk information do these things people with a purpose. Most email support group, but also some function developed a special E-mail group software.

(5) use email attachments transmission malicious programs

Mail have support accessories, the attachment is a computer file, and at the same time, this text a can also be possible, this will be enough.

Comments are closed.