Subscribe via RSS ... Subscribe via e-mail ... Follow me on Twitter ... Follow me on Facebook ...

System reconfiguration

System reconfiguration malware makes sure a specific value is set within the configuration of an application. For example, the proxy server entry in the Microsoft Windows system registry to make Internet Explorer to send its web requests to an attackers intercepting web proxy server (see the following sub chapter “Proxy reconfiguration”).
Malware that modifies target systems configuration is typically running in the background and makes sure the changes stay there permanently. This is done by observing the configuration value and in case the value was reset the malware reassigns its own value again. To be less noisy the malware can modify the configuration once, stops afterwards and deletes itself.

In the following chapters I will describe situations of typical system reconfiguration examples attackers are using and what benefit they have by doing so.

Leave a comment


But please respect the commenting rules. Critizism is appreciated and also general comments of course. If you're rude, I have to delete your comment. Also use your personal/nick name but avoid using business names. Have fun and thanks for participating the discussion.