PDA

View Full Version : Malware's use of the default browser


Joeythedude
April 9th, 2009, 03:13 PM
I remember reading that it was best to set another browser than IE as the default browser as malware would often use that setting when trying to phone home.

Is that still true ?

Does much known malware use the default browser setting when it tries to phone home ?

Julian
April 9th, 2009, 03:39 PM
Yes, malware learned to use multiple browsers, using Firefox to send data is common.

raven211
April 9th, 2009, 04:14 PM
Opera?

Julian
April 9th, 2009, 04:23 PM
Don't know but would find the answer interesting.

A comment of an expert would be appreciated :)

Dogbiscuit
April 9th, 2009, 05:35 PM
-{ Quote: "Does much known malware use the default browser setting when it tries to phone home ?" }-
In an admin account, malware can do virtually anything it's programmed to do once it's running (i.e., take complete control of a system). That includes changing the default browser, disabling the current browser, etc.

See here (http://www.wilderssecurity.com/showpost.php?p=1009368&postcount=1) for an example.

Joeythedude
April 9th, 2009, 06:59 PM
Is there any statistics of the common behaviours/practices of malware in the wild ?

For example if say 30% would have included the code to change the default browser if need ? After all they can't cover every user senario , esp when they don't need to .

I'm interested in simple steps to block the majority of what real-world malware currently does , rather than going for ironclad protection levels.

Kerodo
April 9th, 2009, 07:18 PM
-{ Quote: "
I'm interested in simple steps to block the majority of what real-world malware currently does , rather than going for ironclad protection levels." }-
See any of the several threads here on LUA/SRP etc. That is probably your best bet.

Dogbiscuit
April 10th, 2009, 04:08 AM
-{ Quote: "Is there any statistics of the common behaviours/practices of malware in the wild ?" }-
I don't know of any offhand.
-{ Quote: "I'm interested in simple steps to block the majority of what real-world malware currently does , rather than going for ironclad protection levels." }-
Do you mean you're interested in blocking what real-world malware does once it's on your system, or blocking real-world malware from getting on your system in the first place?

blacknight
April 10th, 2009, 04:51 AM
Don't you think to use an HIPS ?

Joeythedude
April 10th, 2009, 05:05 PM
Well i'd like to keep this thread on how useful/accurate the advice about the default browser is these days , if a person didn't use anything apart from a standard security suite.