Spyware: Technical Overview Jody Blanke Mercer University ALSB, Ottawa August 21, 2004
What is Spyware? FTC definition – “software that aids in gathering information about a person or organization without their knowledge and which may send such information to another entity without the consumer’s consent, or asserts control over a computer without the consumer’s knowledge” Spyware Adware Hijacker Trojan Keystroke logger Browser helper object (BHO)
How do you get it? “Trojan horse” - bundled as part of other software package Kazaa (12 different spyware programs; at least two with every version) ClockSync (WhenU) Precision Time (Gator) “Drive-by download” – HTML code transmitted by browser when visiting a web site request installation of program One spyware program helps install another; self-updating E-mail or links that, when opened, initiate transfer of code
How do you get rid of it? Be careful what you download Be careful what you consent to Install Spybot Search & Destroy http://www.safer-networking.org Install SpywareBlaster http://www.javacoolsoftware.com/spywareblaster.html Install Ad-Aware http://www.lavasoftusa.com/support/download/ Install Google Toolbar http://toolbar.google.com/ Visit PestPatrol Research http://research.pestpatrol.com/
Google Toolbar