65
Trường Đại Hc Công NghThông Tin Trường Đại Hc Công NghThông Tin Khoa Mng y Tính và Truyn Thông Khoa Mng y Tính và Truyn Thông AN TOÀN AN TOÀN AN TOÀN AN TOÀN MNG MÁY TÍNH MNG MÁY TÍNH ThS. Tô Nguyn Nht Quang ThS. Tô Nguyn Nht Quang

An Toan Mang May Tinh - Bai 2a

Embed Size (px)

DESCRIPTION

slide an toan mang uit

Citation preview

  • Trng i Hc Cng Ngh Thng TinTrng i Hc Cng Ngh Thng TinKhoa Mng My Tnh v Truyn ThngKhoa Mng My Tnh v Truyn Thng g y y g g y y g

    AN TONAN TONAN TON AN TON MNG MY TNH MNG MY TNH

    ThS. T Nguyn Nht QuangThS. T Nguyn Nht Quang

  • NI DUNG MN HCNI DUNG MN HCNI DUNG MN HCNI DUNG MN HC1.1. Tng quan v an ninh mngTng quan v an ninh mngg q gg q g2.2. Cc phn mm gy hiCc phn mm gy hi3.3. Cc gii thut m ho d liuCc gii thut m ho d liug g 4.4. M ho kho cng khai v qun l khoM ho kho cng khai v qun l kho5.5. Chng thc d liuChng thc d liu6.6. Mt s giao thc bo mt mngMt s giao thc bo mt mng7.7. Bo mt mng khng dyBo mt mng khng dy8.8. Bo mt mng vnh aiBo mt mng vnh ai9.9. Tm kim pht hin xm nhpTm kim pht hin xm nhp

    ATMMT ATMMT -- TNNQTNNQ 22

  • BI 2BI 2

    CC PHN MM GY HICC PHN MM GY HI

  • A. TROJAN V BACKDOORA. TROJAN V BACKDOOR

  • Ni dungNi dungNi dungNi dung

    11 Lch s hnh thnh TrojanLch s hnh thnh Trojan1.1. Lch s hnh thnh TrojanLch s hnh thnh Trojan

    2.2. Khi nim v TrojanKhi nim v Trojan

    Ph l i T jPh l i T j3.3. Phn loi TrojanPhn loi Trojan

    4.4. Mt s Trojan ph binMt s Trojan ph bin

    5.5. Phng chng TrojanPhng chng Trojan

    66 Mt s cng i cng cc Trojan thng dngMt s cng i cng cc Trojan thng dng6.6. Mt s cng i cng cc Trojan thng dngMt s cng i cng cc Trojan thng dng

    7.7. Bi tpBi tp

    ATMMT ATMMT -- TNNQTNNQ 55

  • 1 Lch s hnh thnh Trojan1 Lch s hnh thnh Trojan1. Lch s hnh thnh Trojan1. Lch s hnh thnh Trojan

    Nga Trojan trongNga Trojan trongNga Trojan trong Nga Trojan trong truyn thuyt Hy Lp c truyn thuyt Hy Lp c i th k 17i th k 17i th k 17.i th k 17.

    Trojan trn my tnh Trojan trn my tnh t ti l t ti lc to ra u tin l c to ra u tin l Back Orifice, c cng Back Orifice, c cng h l 31337 h l 31337xm nhp l 31337.xm nhp l 31337.

    ATMMT ATMMT -- TNNQTNNQ 66

  • 2 Khi nim v Trojan2 Khi nim v Trojan2. Khi nim v Trojan2. Khi nim v TrojanTrojan l chng trnh gy tn hi n ngi Trojan l chng trnh gy tn hi n ngi dng my tnh phc v cho mc ch ring nodng my tnh phc v cho mc ch ring nodng my tnh, phc v cho mc ch ring no dng my tnh, phc v cho mc ch ring no ca hacker. ca hacker.Thng hot ng b mt v ngi dng khng Thng hot ng b mt v ngi dng khng

    h h t h h t nhn ra s hot ng ny.nhn ra s hot ng ny.Cng dng hay gp nht ca trojan l thit lp Cng dng hay gp nht ca trojan l thit lp quyn iu khin t xa cho hacker trn my b quyn iu khin t xa cho hacker trn my b q y y q y y nhim trojan.nhim trojan.

    ATMMT ATMMT -- TNNQTNNQ 77

  • 2 Khi nim v Trojan2 Khi nim v Trojan2. Khi nim v Trojan2. Khi nim v Trojan

    ATMMT ATMMT -- TNNQTNNQ 88

  • 2 Khi nim v Trojan2 Khi nim v Trojan2. Khi nim v Trojan2. Khi nim v Trojan

    Trojan khng t nhn bn nh virus myTrojan khng t nhn bn nh virus myTrojan khng t nhn bn nh virus my Trojan khng t nhn bn nh virus my tnh m ch chy ngm trong my b tnh m ch chy ngm trong my b nhimnhimnhim.nhim.Trojan thng lm chm tc my tnh, Trojan thng lm chm tc my tnh, cm chnh sa registrycm chnh sa registrycm chnh sa registrycm chnh sa registry

    ATMMT ATMMT -- TNNQTNNQ 99

  • 2. Khi nim v Trojan2. Khi nim v Trojan Cc con ng Trojan xm nhp vo h thngCc con ng Trojan xm nhp vo h thng

    ng d ngng d ngng dng ng dng Messenger.Messenger.File nh kmFile nh kmFile nh km.File nh km.Truy cp vt l.Truy cp vt l.D t W b E ilD t W b E ilDuyt Web v Email.Duyt Web v Email.Chia s file.Chia s file.Ph i hPh i hPhn mm min ph.Phn mm min ph.Download tp tin, tr Download tp tin, tr h i th i t

    ATMMT ATMMT -- TNNQTNNQ 1010

    chi, screensaver t chi, screensaver t internetinternet

  • 2. Khi nim v Trojan2. Khi nim v Trojan Cc con ng Trojan xm nhp vo h thngCc con ng Trojan xm nhp vo h thng

    Graffiti.exe

    One file kexe maker

    ATMMT ATMMT -- TNNQTNNQ 1111

  • 2. Khi nim v Trojan2. Khi nim v Trojan Cc con ng Trojan xm nhp vo h thngCc con ng Trojan xm nhp vo h thng

    ATMMT ATMMT -- TNNQTNNQ 1212

  • 2. Khi nim v Trojan2. Khi nim v Trojan Cc con ng Trojan xm nhp vo h thngCc con ng Trojan xm nhp vo h thng

    ATMMT ATMMT -- TNNQTNNQ 1313

  • 3 Phn loi Trojan3 Phn loi Trojan3. Phn loi Trojan3. Phn loi Trojan

    Loi iu khin t xa (RAT)Loi iu khin t xa (RAT)Loi iu khin t xa (RAT)Loi iu khin t xa (RAT)

    KeyloggersKeyloggers

    Trojan ly cp passwordTrojan ly cp password

    FTP trojansFTP trojansFTP trojansFTP trojans

    Trojan ph hoiTrojan ph hoi

    Trojan chim quyn kiu leo thangTrojan chim quyn kiu leo thang

    ATMMT ATMMT -- TNNQTNNQ 1414

  • 3 Phn loi Trojan3 Phn loi Trojan3. Phn loi Trojan3. Phn loi Trojan

    ATMMT ATMMT -- TNNQTNNQ 1515

  • 3 1 Trojan iu khin t xa (RAT)3 1 Trojan iu khin t xa (RAT)3.1. Trojan iu khin t xa (RAT)3.1. Trojan iu khin t xa (RAT)

    RAT bin my tnh b nhim trojan thnhRAT bin my tnh b nhim trojan thnhRAT bin my tnh b nhim trojan thnh RAT bin my tnh b nhim trojan thnh mt server my tnh client ca hacker mt server my tnh client ca hacker truy cp vo v nm quyn iu khintruy cp vo v nm quyn iu khintruy cp vo v nm quyn iu khin.truy cp vo v nm quyn iu khin.T ng kch hot mi khi my tnh hot T ng kch hot mi khi my tnh hot ngngng.ng.Gm 2 file, mt cho server, mt cho client.Gm 2 file, mt cho server, mt cho client.Thng c ngy trang di mt kiu Thng c ngy trang di mt kiu file bnh thng no giu kiu exe.file bnh thng no giu kiu exe.

    ATMMT ATMMT -- TNNQTNNQ 1616

  • 3 1 Trojan iu khin t xa (RAT)3 1 Trojan iu khin t xa (RAT)3.1. Trojan iu khin t xa (RAT)3.1. Trojan iu khin t xa (RAT)

    Mi RAT thng chy server di mt cngMi RAT thng chy server di mt cngMi RAT thng chy server di mt cng Mi RAT thng chy server di mt cng ring bit cho php hacker thm nhp vo my ring bit cho php hacker thm nhp vo my b nhim trojan v tin hnh iu khin t xa.b nhim trojan v tin hnh iu khin t xa.

    Thng v hiu ho vic chnh sa registry nn Thng v hiu ho vic chnh sa registry nn kh xo trojan ny.kh xo trojan ny.j yj y

    i khi c th s dng trong vic qun l my i khi c th s dng trong vic qun l my tnh t xa.tnh t xa.t t at t a

    Ph bin c Back Orifice, Girlfriend, NetbusPh bin c Back Orifice, Girlfriend, Netbus

    ATMMT ATMMT -- TNNQTNNQ 1717

  • 3 2 Keyloggers3 2 Keyloggers3.2. Keyloggers3.2. Keyloggers

    Keylogger bao gm hai loi,Keylogger bao gm hai loi,Keylogger bao gm hai loi, Keylogger bao gm hai loi, mt loi keylogger phn cng mt loi keylogger phn cng v mt loi l phn mm.v mt loi l phn mm.

    Nh gn, s dng t b nh Nh gn, s dng t b nh nn kh pht hin.nn kh pht hin.p p

    Hot ng n gin, ch yu l Hot ng n gin, ch yu l ghi li din bin ca bn phm ghi li din bin ca bn phm g d b ca b pg d b ca b pri lu li trn my hoc gi v ri lu li trn my hoc gi v cho hacker qua email.cho hacker qua email.

    ATMMT ATMMT -- TNNQTNNQ 1818

  • 3 2 Keyloggers3 2 Keyloggers3.2. Keyloggers3.2. Keyloggers

    Nu dng gim st con ci, ngi thn xemNu dng gim st con ci, ngi thn xemNu dng gim st con ci, ngi thn xem Nu dng gim st con ci, ngi thn xem h lm g vi PC, vi internet, khi chat vi ngi h lm g vi PC, vi internet, khi chat vi ngi l th keylogger l tt. l th keylogger l tt.

    Khi s dng keylogger nhm nh cp cc Khi s dng keylogger nhm nh cp cc thng tin c nhn (ti khon c nhn, mt khu, thng tin c nhn (ti khon c nhn, mt khu, g ( , ,g ( , ,th tn dng) th keylogger l xu. th tn dng) th keylogger l xu.

    ATMMT ATMMT -- TNNQTNNQ 1919

  • 3 2 Keyloggers3 2 Keyloggers3.2. Keyloggers3.2. KeyloggersMt keylogger thng gm ba phn chnh:Mt keylogger thng gm ba phn chnh: y gg g g p y gg g g pChng trnh iu khin: iu phi hot ng, tinh Chng trnh iu khin: iu phi hot ng, tinh chnh cc thit lp, xem cc tp tin nht k. Thng chnh cc thit lp, xem cc tp tin nht k. Thng thng ch c th gi bng t hp phm ttthng ch c th gi bng t hp phm ttthng ch c th gi bng t hp phm tt. thng ch c th gi bng t hp phm tt. Tp tin hook, hoc l mt chng trnh monitor dng Tp tin hook, hoc l mt chng trnh monitor dng ghi nhn li cc thao tc bn phm, capture screen. ghi nhn li cc thao tc bn phm, capture screen. ghi nhn li cc thao tc bn phm, capture screen. ghi nhn li cc thao tc bn phm, capture screen.Tp tin nht k (log), ni cha ng ton b nhng g Tp tin nht k (log), ni cha ng ton b nhng g hook ghi nhn c. hook ghi nhn c. Ngoi ra, ty theo loi c th c thm phn chng Ngoi ra, ty theo loi c th c thm phn chng trnh bo v (protect), chng trnh thng bo trnh bo v (protect), chng trnh thng bo (report)(report)

    ATMMT ATMMT -- TNNQTNNQ 2020

    (report)(report)

  • 3 2 Keyloggers3 2 Keyloggers3.2. Keyloggers3.2. Keyloggers

    ATMMT ATMMT -- TNNQTNNQ 2121

  • 3 2 Keyloggers3 2 Keyloggers3.2. Keyloggers3.2. Keyloggers

    ATMMT ATMMT -- TNNQTNNQ 2222

  • 3 3 Trojan n trm password3 3 Trojan n trm password3.3. Trojan n trm password3.3. Trojan n trm password

    n cp cc loi mt khu lu trn my bn cp cc loi mt khu lu trn my bn cp cc loi mt khu lu trn my b n cp cc loi mt khu lu trn my b nhim nh mt khu ca ICQ, IRC, nhim nh mt khu ca ICQ, IRC, Hotmail Yahoo ri gi v cho hackerHotmail Yahoo ri gi v cho hackerHotmail, Yahoo ri gi v cho hacker Hotmail, Yahoo ri gi v cho hacker qua email.qua email.

    Cc loi trojan ph Cc loi trojan ph bin l Barri, bin l Barri, Kuang, Barok.Kuang, Barok.

    ATMMT ATMMT -- TNNQTNNQ 2323

  • 3 4 FTP Trojan3 4 FTP Trojan3.4. FTP Trojan3.4. FTP Trojan

    Loi ny m cng 21 trn my b nhimLoi ny m cng 21 trn my b nhimLoi ny m cng 21 trn my b nhim Loi ny m cng 21 trn my b nhim nn mi ngi u c th truy cp my nn mi ngi u c th truy cp my ny ti d liuny ti d liuny ti d liu.ny ti d liu.

    ATMMT ATMMT -- TNNQTNNQ 2424

  • 3 5 Trojan ph hoi3 5 Trojan ph hoi3.5. Trojan ph hoi3.5. Trojan ph hoi

    Mc ch chnh l ph hoiMc ch chnh l ph hoiMc ch chnh l ph hoiMc ch chnh l ph hoi

    Ph hu a cng, m ho cc filePh hu a cng, m ho cc file

    Rt nguy him, kh kim sotRt nguy him, kh kim sot

    ATMMT ATMMT -- TNNQTNNQ 2525

  • 3.6. Trojan chim quyn 3.6. Trojan chim quyn ki l th ki l th kiu leo thang c quynkiu leo thang c quyn

    Thng c gn vo mt ng dng hThng c gn vo mt ng dng hThng c gn vo mt ng dng h Thng c gn vo mt ng dng h thng no v s cho hacker quyn cao thng no v s cho hacker quyn cao hn quyn c trong h thng khi nghn quyn c trong h thng khi nghn quyn c trong h thng khi ng hn quyn c trong h thng khi ng dng ny chy.dng ny chy.

    ATMMT ATMMT -- TNNQTNNQ 2626

  • 4. Mt s Trojan ph bin4. Mt s Trojan ph binG SG SKGB SPYKGB SPY

    L loi trojan mnh, c s dng rng ri.L loi trojan mnh, c s dng rng ri.L loi trojan mnh, c s dng rng ri. L loi trojan mnh, c s dng rng ri. Version c cp nht lin tc.Version c cp nht lin tc.C th theo di cc phm nhn, mn hnhC th theo di cc phm nhn, mn hnhp ,p ,C cc tab trong chng trnh: C cc tab trong chng trnh: -- General optionsGeneral options -- Advanced optionsAdvanced optionspp pp-- PasswordPassword -- ScreenshotScreenshot-- Email DeliveryEmail Delivery -- FPT DeliveryFPT Delivery-- FiltersFilters -- Alert NotificationsAlert Notifications-- InvisibilityInvisibility

    ATMMT ATMMT -- TNNQTNNQ 2727

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin G SG SKGB SPYKGB SPY

    ATMMT ATMMT -- TNNQTNNQ 2828

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin KGB SPYKGB SPYKGB SPYKGB SPY

    ATMMT ATMMT -- TNNQTNNQ 2929

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin ffBlazing Tool Perfect KeyloggerBlazing Tool Perfect Keylogger

    L mt trojan mnh, c s dng rng L mt trojan mnh, c s dng rng ri trn internetri trn internetri trn internet.ri trn internet.Cho php nhn thng tin t my b nhim Cho php nhn thng tin t my b nhim trojan t email hoc fpt servertrojan t email hoc fpt servertrojan t email hoc fpt server.trojan t email hoc fpt server.C th lu li cc phm nhn, cc link C th lu li cc phm nhn, cc link

    b i d h tb i d h tweb, ni dung chatweb, ni dung chat

    ATMMT ATMMT -- TNNQTNNQ 3030

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin Blazing Tool Perfect KeyloggerBlazing Tool Perfect KeyloggerBlazing Tool Perfect KeyloggerBlazing Tool Perfect Keylogger

    ATMMT ATMMT -- TNNQTNNQ 3131

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin 007 Spy Software007 Spy Software007 Spy Software007 Spy Software

    ATMMT ATMMT -- TNNQTNNQ 3232

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin 007 Spy Software007 Spy Software007 Spy Software007 Spy Software

    ATMMT ATMMT -- TNNQTNNQ 3333

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin St lth K lSt lth K lStealth KeyloggerStealth Keylogger

    ATMMT ATMMT -- TNNQTNNQ 3434

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin DJI RATDJI RAT

    ATMMT ATMMT -- TNNQTNNQ 3535

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin SSNET BUSNET BUS

    ATMMT ATMMT -- TNNQTNNQ 3636

  • 4. Mt s Trojan ph bin 4. Mt s Trojan ph bin HackerzRATHackerzRAT

    ATMMT ATMMT -- TNNQTNNQ 3737

  • 4 Mt s Trojan ph4 Mt s Trojan ph binbin4. Mt s Trojan ph 4. Mt s Trojan ph bin bin

    ATMMT ATMMT -- TNNQTNNQ 3838

  • 5. Phng chng 5. Phng chng Trojan Trojan

    ATMMT ATMMT -- TNNQTNNQ 3939

  • 5 Phng chng Trojan5 Phng chng Trojan5. Phng chng Trojan5. Phng chng Trojan

    Hn ch s dng chung my tnh ci tHn ch s dng chung my tnh ci tHn ch s dng chung my tnh, ci t Hn ch s dng chung my tnh, ci t mt khu bo v.mt khu bo v.Khng m cc tp tin l khng r ngunKhng m cc tp tin l khng r ngunKhng m cc tp tin l khng r ngun Khng m cc tp tin l khng r ngun gc, ch cc file c phn m rng l gc, ch cc file c phn m rng l exe com bat scr swf zip rar gifexe com bat scr swf zip rar gifexe, com, bat, scr, swf, zip, rar, gifexe, com, bat, scr, swf, zip, rar, gifKhng vo cc trang web l.Khng vo cc trang web l.Khng click vo cc ng link l.Khng click vo cc ng link l.Khng ci t cc phn mm l.Khng ci t cc phn mm l.

    ATMMT ATMMT -- TNNQTNNQ 4040

    g p g p

  • 5 Phng chng Trojan5 Phng chng Trojan5. Phng chng Trojan5. Phng chng Trojan

    Khng download chng trnh t ccKhng download chng trnh t ccKhng download chng trnh t cc Khng download chng trnh t cc ngun khng tin cy.ngun khng tin cy.Lun lun t bo v mnh bng ccLun lun t bo v mnh bng ccLun lun t bo v mnh bng cc Lun lun t bo v mnh bng cc chng chnh chuyn dng chng virus, chng chnh chuyn dng chng virus, chng spyware v dng tng la khichng spyware v dng tng la khichng spyware v dng tng la khi chng spyware v dng tng la khi ng nhp Internet. ng nhp Internet. Th ht bTh ht bThng xuyn cp nht y cc bn Thng xuyn cp nht y cc bn cp nht bo mt ca h iu hnh. cp nht bo mt ca h iu hnh.

    ATMMT ATMMT -- TNNQTNNQ 4141

  • 5 Phng chng Trojan5 Phng chng Trojan5. Phng chng Trojan5. Phng chng Trojan

    Qut cc port ang m vi cc cng c nhQut cc port ang m vi cc cng c nhQut cc port ang m vi cc cng c nh Qut cc port ang m vi cc cng c nh Netstat, Fport, TCPViewNetstat, Fport, TCPViewQut cc tin trnh ang chy vi Process Qut cc tin trnh ang chy vi Process Q g yQ g yViewer, Whats on my computer, InsiderViewer, Whats on my computer, InsiderQut nhng thay i trong Registry vi Qut nhng thay i trong Registry vi g y g g yg y g g yMsConfig, Whats running on my computerMsConfig, Whats running on my computerQut nhng hot ng mng vi Ethereal, Qut nhng hot ng mng vi Ethereal, WireSharkWireSharkChy cc phn mm dit Trojan.Chy cc phn mm dit Trojan.

    ATMMT ATMMT -- TNNQTNNQ 4242

  • 5 Phng chng Trojan5 Phng chng Trojan5. Phng chng Trojan5. Phng chng Trojan

    ATMMT ATMMT -- TNNQTNNQ 4343

  • 5. Phng chng Trojan5. Phng chng TrojanTrojan HunterTrojan HunterTrojan HunterTrojan Hunter

    ATMMT ATMMT -- TNNQTNNQ 4444

  • 5. Phng chng Trojan 5. Phng chng Trojan SSSpyware DoctorSpyware Doctor

    ATMMT ATMMT -- TNNQTNNQ 4545

  • 5. Phng chng Trojan 5. Phng chng Trojan CCTCPViewTCPView

    ATMMT ATMMT -- TNNQTNNQ 4646

  • 5. Phng chng Trojan 5. Phng chng Trojan CurrPorts ToolCurrPorts ToolCurrPorts ToolCurrPorts Tool

    ATMMT ATMMT -- TNNQTNNQ 4747

  • 5. Phng chng Trojan 5. Phng chng Trojan Process ViewerProcess ViewerProcess ViewerProcess Viewer

    ATMMT ATMMT -- TNNQTNNQ 4848

  • 5. Phng chng Trojan 5. Phng chng Trojan Whats runningWhats runningWhat s runningWhat s running

    ATMMT ATMMT -- TNNQTNNQ 4949

  • 5. Phng chng Trojan 5. Phng chng Trojan Capsa Network AnalyzerCapsa Network AnalyzerCapsa Network AnalyzerCapsa Network Analyzer

    ATMMT ATMMT -- TNNQTNNQ 5050

  • 5. Phng chng Trojan 5. Phng chng Trojan Pen TestingPen TestingPen TestingPen Testing

    ATMMT ATMMT -- TNNQTNNQ 5151

  • 5. Phng chng Trojan 5. Phng chng Trojan Pen TestingPen TestingPen TestingPen Testing

    ATMMT ATMMT -- TNNQTNNQ 5252

  • 5. Phng chng Trojan 5. Phng chng Trojan Pen TestingPen TestingPen TestingPen Testing

    ATMMT ATMMT -- TNNQTNNQ 5353

  • 6. Mt s cng 6. Mt s cng i cng cc Trojan thng dngi cng cc Trojan thng dng

    ATMMT ATMMT -- TNNQTNNQ 5454

  • 6. Mt s cng 6. Mt s cng i cng cc Trojan thng dngi cng cc Trojan thng dng

    Satanz Backdoor|666Satanz Backdoor|666 FTP99CMP|1492FTP99CMP|1492 WinCrash|4092WinCrash|4092 DeepThroat|6771DeepThroat|6771Satanz Backdoor|666 Satanz Backdoor|666

    Silencer|1001 Silencer|1001

    ShivkaShivka--Burka|1600 Burka|1600

    FTP99CMP|1492 FTP99CMP|1492

    BackDoor|1999 BackDoor|1999

    Trojan Cow|2001 Trojan Cow|2001

    WinCrash|4092 WinCrash|4092

    ICQTrojan|4590 ICQTrojan|4590

    Sockets de Troie|5000 Sockets de Troie|5000

    DeepThroat|6771 DeepThroat|6771

    GateCrasher|6969 GateCrasher|6969

    Priority|6969 Priority|6969 ||

    SpySender|1807 SpySender|1807

    Shockrave|1981 Shockrave|1981

    j |j |

    Ripper|2023 Ripper|2023

    Bugs|2115 Bugs|2115

    ||

    Sockets de Troie Sockets de Troie 1.x|5001 1.x|5001

    Firehotcker|5321Firehotcker|5321

    y|y|

    Remote Grab|7000 Remote Grab|7000

    NetMonitor|7300 NetMonitor|7300

    WebEx|1001 WebEx|1001

    Doly Trojan|1011 Doly Trojan|1011

    Deep Throat|2140 Deep Throat|2140

    The Invasor|2140 The Invasor|2140

    Firehotcker|5321 Firehotcker|5321

    Blade Runner|5400 Blade Runner|5400

    Blade Runner 1.x|5401 Blade Runner 1.x|5401

    NetMonitor 1.x|7301 NetMonitor 1.x|7301

    NetMonitor 2.x|7306 NetMonitor 2.x|7306

    Psyber Stream Psyber Stream Server|1170 Server|1170

    Ultors Trojan|1234 Ultors Trojan|1234

    Phineas Phucker|2801 Phineas Phucker|2801

    Masters Masters Paradise|30129 Paradise|30129

    Blade Runner 2.x|5402 Blade Runner 2.x|5402

    RoboRobo--Hack|5569 Hack|5569

    NetMonitor 3.x|7307 NetMonitor 3.x|7307

    NetMonitor 4.x|7308 NetMonitor 4.x|7308

    ICKiller|7789ICKiller|7789

    ATMMT ATMMT -- TNNQTNNQ 5555

    VooDoo Doll|1245 VooDoo Doll|1245 Portal of Doom|3700 Portal of Doom|3700 DeepThroat|6670 DeepThroat|6670 ICKiller|7789 ICKiller|7789

  • 6. Mt s cng 6. Mt s cng i cng cc Trojan thng dngi cng cc Trojan thng dng

    Portal of Doom|9872 Portal of Doom|9872 Hack?99 Hack?99 KeyLogger|12223KeyLogger|12223

    Evil FTP|23456 Evil FTP|23456 Masters Paradise Masters Paradise 1 x|404221 x|40422

    Portal of Doom Portal of Doom 1.x|9873 1.x|9873

    Portal of Doom Portal of Doom

    KeyLogger|12223KeyLogger|12223

    GabanBus|1245 GabanBus|1245

    NetBus|1245NetBus|1245

    Ugly FTP|23456 Ugly FTP|23456

    Delta|26274 Delta|26274

    1.x|40422 1.x|40422

    Masters Paradise Masters Paradise 2.x|40423 2.x|40423

    2.x|9874 2.x|9874

    Portal of Doom Portal of Doom 3.x|9875 3.x|9875

    NetBus|1245 NetBus|1245

    WhackWhack--aa--mole|12361 mole|12361

    WhackWhack--aa--mole mole 1 |123621 |12362

    Back Orifice|31337 Back Orifice|31337

    Back Orifice|31338 Back Orifice|31338

    DeepBO|31338DeepBO|31338

    Masters Paradise Masters Paradise 3.x|40426 3.x|40426

    Sockets de Troie|50505 Sockets de Troie|50505

    Portal of Doom Portal of Doom 4.x|10067 4.x|10067

    Portal of Doom Portal of Doom 5 |101675 |10167

    1.x|12362 1.x|12362

    Priority|16969 Priority|16969

    Millennium|20001 Millennium|20001

    DeepBO|31338 DeepBO|31338

    NetSpy DK|31339 NetSpy DK|31339

    BOWhack|31666 BOWhack|31666

    Fore|50766 Fore|50766

    Remote Windows Remote Windows Shutdown|53001 Shutdown|53001

    5.x|10167 5.x|10167

    iNiiNi--Killer|9989 Killer|9989

    Senna Spy|11000 Senna Spy|11000

    ||

    NetBus 2 Pro|20034 NetBus 2 Pro|20034

    GirlFriend|21544 GirlFriend|21544

    BigGluck|34324 BigGluck|34324

    The Spy|40412 The Spy|40412

    Telecommando|61466 Telecommando|61466

    Devil|65000 Devil|65000

    ATMMT ATMMT -- TNNQTNNQ 5656

    py|py|The tHing|6400 The tHing|6400

  • 6. Mt s cng 6. Mt s cng i cng cc Trojan thng dngi cng cc Trojan thng dng

    NetBus 1 x|12346NetBus 1 x|12346 Gatecrasher |6969Gatecrasher |6969 Stealth Spy |555Stealth Spy |555 BladeRunner | 5400BladeRunner | 5400NetBus 1.x|12346 NetBus 1.x|12346

    NetBus Pro 20034 NetBus Pro 20034

    SubSeven|1243 SubSeven|1243

    Gatecrasher |6969 Gatecrasher |6969

    Telecommando | 61466 Telecommando | 61466

    Gjamer |12076 Gjamer |12076

    Stealth Spy |555 Stealth Spy |555

    Pass Ripper |2023 Pass Ripper |2023

    Attack FTP |666 Attack FTP |666

    BladeRunner | 5400 BladeRunner | 5400

    IcqTrojan | 4950 IcqTrojan | 4950

    InIkiller | 9989 InIkiller | 9989 ||

    NetSphere|30100 NetSphere|30100

    Silencer |1001 Silencer |1001

    j |j |

    IcqTrojen| 4950 IcqTrojen| 4950

    Priotrity |16969 Priotrity |16969

    ||

    GirlFriend | 21554 GirlFriend | 21554

    Fore, Schwindler| Fore, Schwindler| 5076650766

    ||

    PortalOfDoom | 9872 PortalOfDoom | 9872

    ProgenicTrojan | 11223 ProgenicTrojan | 11223

    Millenium |20000 Millenium |20000

    Devil 1.03 |65000 Devil 1.03 |65000

    Vodoo | 1245 Vodoo | 1245

    Wincrash | 5742 Wincrash | 5742

    50766 50766

    Tiny Telnet Server| Tiny Telnet Server| 34324 34324

    Prosiak 0.47 | 22222 Prosiak 0.47 | 22222

    RemoteWindowsShutdRemoteWindowsShutdown | 53001 own | 53001

    NetMonitor| 7306 NetMonitor| 7306

    Streaming Audio Streaming Audio Trojan| 1170 Trojan| 1170

    Wincrash2| 2583 Wincrash2| 2583

    Netspy |1033 Netspy |1033

    ShockRave | 1981ShockRave | 1981

    Kuang |30999 Kuang |30999

    Senna Spy Trojans| Senna Spy Trojans| 11000 11000

    RoboHack |5569 RoboHack |5569

    Silencer | 1001 Silencer | 1001

    ATMMT ATMMT -- TNNQTNNQ 5757

    Socket23 |30303 Socket23 |30303 ShockRave | 1981 ShockRave | 1981

    WhackJob | 23456 WhackJob | 23456 Striker | 2565 Striker | 2565

  • 7 Bi tp7 Bi tp7. Bi tp7. Bi tp1.1. Di y lit k mt s Worm ph bin v port tng ng. Di y lit k mt s Worm ph bin v port tng ng.

    Tm kim ti liu lin quan v m t cch hot ng ca 5 Tm kim ti liu lin quan v m t cch hot ng ca 5 Worm khc nhau trong danh sch.Worm khc nhau trong danh sch.

    ATMMT ATMMT -- TNNQTNNQ 5858

  • 7 Bi tp7 Bi tp7. Bi tp7. Bi tp2.2. Di y lit k mt s Trojan ph bin v port tng Di y lit k mt s Trojan ph bin v port tng

    ng. Tm kim ti liu lin quan v m t cch hot ng ng. Tm kim ti liu lin quan v m t cch hot ng ca 5 Trojan khc nhau trong danh sch.ca 5 Trojan khc nhau trong danh sch.

    ATMMT ATMMT -- TNNQTNNQ 5959

  • 7 Bi tp7 Bi tp7. Bi tp7. Bi tp3.3. Xy dng nhng quy tc ACL chn cc Worm v cc Xy dng nhng quy tc ACL chn cc Worm v cc

    Trojan ( nu trong bi 1 v 2) xm nhp vo mng ni b.Trojan ( nu trong bi 1 v 2) xm nhp vo mng ni b.j ( g ) p g j ( g ) p g

    4.4. M t chc nng qut Heuristic tm Virus.M t chc nng qut Heuristic tm Virus.

    5.5. M t s ging nhau v khc nhauM t s ging nhau v khc nhau trong cch hot ngtrong cch hot ng5.5. M t s ging nhau v khc nhau M t s ging nhau v khc nhau trong cch hot ng trong cch hot ng gia gia cc phn mm cc phn mm McAfee VirusScanMcAfee VirusScan vv Norton AntiVirusNorton AntiVirus..

    6.6. Tm kim t cc trang web c lin quan danh sch Virus v Tm kim t cc trang web c lin quan danh sch Virus v Trojan mi xut hin trong 2 tun qua. Nu mt s c Trojan mi xut hin trong 2 tun qua. Nu mt s c im chnh ca chng.im chnh ca chng.

    Gii th h t i S t Ad i i t t kh dGii th h t i S t Ad i i t t kh d7.7. Gii thch ti sao System Administrator khng nn s dng Gii thch ti sao System Administrator khng nn s dng mt ti khon ngi dng c mt khu supermt ti khon ngi dng c mt khu super--user duyt user duyt Web hoc gi v nhn EWeb hoc gi v nhn E--Mail.Mail.

    ATMMT ATMMT -- TNNQTNNQ 6060

  • 7 Bi tp7 Bi tp7. Bi tp7. Bi tp8.8. Web 2.0 xut hin vo nm 2004, i din cho th h th Web 2.0 xut hin vo nm 2004, i din cho th h th

    hai ca cng ngh Web. Bng di y m t vi k thut hai ca cng ngh Web. Bng di y m t vi k thut g g g y g g g y tng ng gia Web 2.0 v Web 1.0 th h trc:tng ng gia Web 2.0 v Web 1.0 th h trc:

    Web 2.0 c cng mt s vn v bo mt nh Web 1.0 Web 2.0 c cng mt s vn v bo mt nh Web 1.0 v cn pht sinh thm mt s vn mi. Tm cc ti liu v cn pht sinh thm mt s vn mi. Tm cc ti liu

    ATMMT ATMMT -- TNNQTNNQ 6161

    lin quan v m t 5 vn bo mt trong Web 2.0.lin quan v m t 5 vn bo mt trong Web 2.0.

  • 7 Bi tp7 Bi tp7. Bi tp7. Bi tp9.9. Vo trang Vo trang http://www.microsoft.com/downloadshttp://www.microsoft.com/downloads, download , download

    v v ci t trn my tnh cc phn mm:v v ci t trn my tnh cc phn mm:1.1. Windows DefenderWindows Defender

    2.2. Microsoft Security EssentialsMicrosoft Security Essentials

    Ch Wi d D f d t S ii th hCh Wi d D f d t S ii th h Chy Windows Defender qut Spyware, gii thch c Chy Windows Defender qut Spyware, gii thch c ch hot ng ca phn mm ny.ch hot ng ca phn mm ny.

    nh gi Microsoft Security Essentials vi mt s phnnh gi Microsoft Security Essentials vi mt s phn nh gi Microsoft Security Essentials vi mt s phn nh gi Microsoft Security Essentials vi mt s phn mm tng t ph bin nht hin nay v:mm tng t ph bin nht hin nay v:

    1.1. Kh nng chng m c hiKh nng chng m c hi

    2.2. Tng la tch hp vo IETng la tch hp vo IE

    3.3. H thng gim st mng tng kh nng ngn chn tn cng H thng gim st mng tng kh nng ngn chn tn cng t bn ngoit bn ngoi

    ATMMT ATMMT -- TNNQTNNQ 6262

    t bn ngoit bn ngoi

    4.4. Tiu tn ti nguyn, thi gian hot ngTiu tn ti nguyn, thi gian hot ng

  • 5 Bi tp5 Bi tp5. Bi tp5. Bi tp10.10. Trong h iu hnh Windows, cookies cTrong h iu hnh Windows, cookies caa trnh duyt IE trnh duyt IE

    c lu tr trn a Cc lu tr trn a C trong th mctrong th mc Documents andDocuments andc lu tr trn a C c lu tr trn a C trong th mctrong th mc Documents and Documents and Settings. Settings. Vo th mc lVo th mc l tn ngi dng, tn ngi dng, vovo th mc th mc Cookies ChnCookies Chn v mv m ngu nhin mt tp tin cookiengu nhin mt tp tin cookie GiiGiiCookies. Chn Cookies. Chn v m v m ngu nhin mt tp tin cookiengu nhin mt tp tin cookie. . Gii Gii thch nhng g bn thy, v tr li cc cu hithch nhng g bn thy, v tr li cc cu hi::

    Nu cookie c truyn ti cc my ch WebNu cookie c truyn ti cc my ch Web di dngdi dng Nu cookie c truyn ti cc my ch Web Nu cookie c truyn ti cc my ch Web di dng di dng plaintext,plaintext, lit k v lit k v m t cc mi e da bo mt tim m t cc mi e da bo mt tim tngtngm ngi dngm ngi dng c th c th s gps gp..

    Nu ngi dng c php chnh sa cc tp tin cookie lu Nu ngi dng c php chnh sa cc tp tin cookie lu tr trn my tnh tr trn my tnh cc bcc b, , lit klit k v m t cc mi e da v m t cc mi e da

    ATMMT ATMMT -- TNNQTNNQ 6363

    bo mt bo mt tim tng c th xy ra cho tim tng c th xy ra cho cc my ch Web.cc my ch Web.

  • 5 Bi tp5 Bi tp5. Bi tp5. Bi tp11.11. Nu chc nng v cch s dng cc cng c:Nu chc nng v cch s dng cc cng c:

    NetstatNetstat FportFport FportFport TCPViewTCPView CurrPorts ToolCurrPorts Tool Process ViewerProcess Viewer Whats runningWhats running One file exe maker

    ATMMT ATMMT -- TNNQTNNQ 6464

    One file exe maker