Difference between revisions of "Spyware"

From OWASP
Jump to: navigation, search
(Description)
m (Reverted edits by OloleTotad (Talk) to last version by KirstenS)
 
(11 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 
{{Template:Attack}}
 
{{Template:Attack}}
 +
<br>
 +
[[Category:OWASP ASDR Project]]
  
==Description==
+
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}'''
  
The spyware is a program that captures statistic information from user´s computer and sends it over internet without user acceptance. This information is usually obtained from cookies and web browser’s history. The spyware can also install other software, display advertisement, or redirect the web browser activity.
 
A spyware differs from virus, worm and adware from various ways. The spyware does not self-replicate and distribute like virus and worm, and not necessarily displays advertisements like adware. The common characteristics between spyware and virus, worm, and adware are:
 
  
1. exploitation of infected computer for commercial purposes
+
==Description==
 +
Spyware is a program that captures statistical information from a user's computer and sends it over internet without user acceptance. This information is usually obtained from cookies and the web browser’s history. Spyware can also install other software, display advertisements, or redirect the web browser activity.
 +
Spyware differs from a virus, worm, and adware in various ways. Spyware does not self-replicate and distribute itself like viruses and worms, and does not necessarily display advertisements like adware. The common characteristics between spyware and viruses, worms, and adware are:
 +
# exploitation of the infected computer for commercial purposes
 +
# the display, in some cases, of advertisements
  
2. the display, in some cases, of advertisements
+
==Risk Factors==
 
+
== Risk Factor ==
+
  
 
High
 
High
  
Some Spywares are very dificult to remove because they can hide they-selfs into Browser Cookies and Offline HTML Content in Temporary files.
+
Some Spyware is very dificult to remove because it can hide in Browser Cookies and Offline HTML Content in Temporary files.
  
 
+
==Examples==
 
+
==Example ==
+
  
 
<center>
 
<center>
Line 27: Line 27:
 
</center>
 
</center>
  
==References==
 
 
*http://cwe.mitre.org/data/definitions/506.html -  Malicious
 
*http://en.wikipedia.org/wiki/Spyware - Spyware
 
 
==Related Threats==
 
 
*[[:Category:Client-side Attacks]]
 
  
==Related Attacks==
+
==Related [[Threat Agents]]==
 +
* [[:Category:Client-side Attacks]]
 +
[[Category:FIXME|not a threat agent that is currently there]]
  
 +
==Related [[Attacks]]==
 
* [[Trojan Horse]]
 
* [[Trojan Horse]]
 
* [[Phishing]]
 
* [[Phishing]]
 
* [[:Category:Malicious Code Attack]]
 
* [[:Category:Malicious Code Attack]]
  
==Related Vulnerabilities==
+
==Related [[Vulnerabilities]]==
 +
* TBD
  
TBD
+
==Related [[Controls]]==
 +
* TBD
  
==Related Countermeasures==
+
==References==
 +
* http://cwe.mitre.org/data/definitions/506.html -  Malicious
 +
* http://en.wikipedia.org/wiki/Spyware - Spyware
  
TBD
 
  
 
[[Category:Resource Manipulation]]
 
[[Category:Resource Manipulation]]
  
 
[[Category:Attack]]
 
[[Category:Attack]]

Latest revision as of 14:32, 26 May 2009

This is an Attack. To view all attacks, please see the Attack Category page.



Last revision (mm/dd/yy): 05/26/2009


Description

Spyware is a program that captures statistical information from a user's computer and sends it over internet without user acceptance. This information is usually obtained from cookies and the web browser’s history. Spyware can also install other software, display advertisements, or redirect the web browser activity. Spyware differs from a virus, worm, and adware in various ways. Spyware does not self-replicate and distribute itself like viruses and worms, and does not necessarily display advertisements like adware. The common characteristics between spyware and viruses, worms, and adware are:

  1. exploitation of the infected computer for commercial purposes
  2. the display, in some cases, of advertisements

Risk Factors

High

Some Spyware is very dificult to remove because it can hide in Browser Cookies and Offline HTML Content in Temporary files.

Examples

Figura2.jpg

Figure 1. A lot of toolbars added by spyware, and some working as spyware


Related Threat Agents

Related Attacks

Related Vulnerabilities

  • TBD

Related Controls

  • TBD

References