5 ms·
I know very little about this type of security, how can one remotely hack into a computer just because it is connected to the internet and has some known vulner
by copx 13y ago
I know very little about this type of security, how can one remotely hack into a computer just because it is connected to the internet and has some known vulnerability?
I mean as far as I know my computer does not execute arbitrary code someone sends it through the internet without asking. So how do you exploit those vulnerabilities?
I understand how you can exploit a vulnerability in a browser, those things actually execute whatever code happens to be on the pages you visit, they load images etc. by default. But just Windows XP with an open internet connection... how does code execution happen there?
- mitchty 13y agoImagine a problem in tcp packet handling that happens due to a problem parsing a tcp packet and further on up the chain the affected service has a buffer overflow in how it reads the data contained in the tcp packet(s) allowing you to inject arbitrary code into that service, lets say the service is RDP or whatever. Then just by having a system being online and able to accept malicious packets to this service, you can with say shodan scan for that vulnerable port across the entire internet, see if the ip is running xp via tcp fingerprinting, then send your malformed packets to the system and add your shiny new xp machine to your botnet for whatever nefarious purposes you need. Also probably patching the hole you used to get in so that nobody else can use it for their purposes. Now this is highly high level and remote vulnerabilities like these are much rarer than browser vulnerabilities, but from what I've heard there are a number of these vulnerabilities floating around just waiting for microsoft to abandon support for xp. Once that happens we might see more xp botnet nodes showing up and causing havoc.
- copx 13y agoI see, thank you for the explanation.
- dmfdmf 13y agoA little late to reply but... my clients are using XP for web access and email. So its just a matter of time before they get infected via an unclosed security hole.