{"id":905,"date":"2014-10-27T17:34:37","date_gmt":"2014-10-27T17:34:37","guid":{"rendered":"http:\/\/blogs.secure-bits.com\/?p=905"},"modified":"2014-10-27T17:34:37","modified_gmt":"2014-10-27T17:34:37","slug":"malware-and-their-target","status":"publish","type":"post","link":"https:\/\/blogs.secure-bits.com\/?p=905","title":{"rendered":"Malware and their target&#8230;"},"content":{"rendered":"<p>Malware targets applications, hardware, and operating systems (OS) by exploiting known\/unknown vulnerabilities in their software code. Why is that important to know? Well, knowing which components of your computer used for exploit is half of the battle in protecting your system. If you don&#8217;t want to read about this subject and just want to protect your system, here&#8217;s a shortcut for <a title=\"Malware protection\" href=\"http:\/\/blogs.secure-bits.com\/?p=833\" target=\"_blank\">protecting against malware&#8230;<\/a>; the link will take you to my blog on the subject&#8230;<\/p>\n<p>Comparing malware introduced in subsequent years, in our examples below 2012 vs. 2013, will not just identify the main targets, but also show the direction that the malware heading. It should also remove some of the myth, that people have about system vulnerabilities&#8230; Let&#8217;s look at the target types first, shall we?<\/p>\n<p style=\"padding-left: 30px;\"><em><\/em><span style=\"color: #008000;\"><em>Image source: <a title=\"Netwars Project\" href=\"http:\/\/netwars-project.com\/webdoc\" target=\"_blank\">Netwar Project<\/a><\/em><\/span><\/p>\n<p><strong>Malware targets:<\/strong><\/p>\n<div id=\"attachment_906\" style=\"width: 910px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-types.png\" target=\"new\"><img aria-describedby=\"caption-attachment-906\" decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-906\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-types-900x458.png\" alt=\"Exploit by types\" width=\"900\" height=\"458\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-types-900x458.png 900w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-types-500x254.png 500w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-types.png 1642w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/a><p id=\"caption-attachment-906\" class=\"wp-caption-text\"><em><a href=\"http:\/\/netwars-project.com\/webdoc\" target=\"new\"><span style=\"color: #008000;\">Image source:<\/span> Netwars Project<\/a><\/em><\/p><\/div>\n<p>By and large, the applications are the most targeted software for exploits, followed by hardware and operating systems. Let&#8217;s leave the hardware out of this analysis, that&#8217;s another blog, and continue with the operating system platforms.<\/p>\n<p><strong>Operating system:<\/strong><\/p>\n<p><div id=\"attachment_911\" style=\"width: 882px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-OS.png\" target=\"new\"><img aria-describedby=\"caption-attachment-911\" decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-911\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-OS-872x900.png\" alt=\"OS exploits\" width=\"872\" height=\"900\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-OS-872x900.png 872w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-OS-290x300.png 290w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-OS.png 896w\" sizes=\"(max-width: 872px) 100vw, 872px\" \/><\/a><p id=\"caption-attachment-911\" class=\"wp-caption-text\"><a href=\"http:\/\/netwars-project.com\/webdoc\" target=\"new\">Image source: Netwars Project<\/a><\/p><\/div><br \/>\nThe operating system vulnerability had increased by close to 300% across all popular platforms, pretty much evenly. The number of critical vulnerabilities increase from year to year had been from 30 to close to 100%. The greater number of vulnerabilities for Windows platform is largely due to the greater operating system market share for Windows. Believe it or not, hackers do know about ROI (Return on Investment) and prefer to target Windows platform dues to its market saturation. <\/p>\n<p><strong>Browsers:<\/strong><\/p>\n<p><div id=\"attachment_921\" style=\"width: 910px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-browser.png\" target=\"new\"><img aria-describedby=\"caption-attachment-921\" decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-921\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-browser-900x900.png\" alt=\"Browsers\" width=\"900\" height=\"900\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-browser-900x900.png 900w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-browser-150x150.png 150w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-browser-300x300.png 300w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/exploit-by-browser.png 908w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/a><p id=\"caption-attachment-921\" class=\"wp-caption-text\"><a href=\"http:\/\/netwars-project.com\/webdoc\" target=\"new\">Image source: Netwars Project<\/a><\/p><\/div><br \/>\nThe vulnerability of the Mozilla browsers seems to start decreasing as its market share decreasing, while Chrome had about 50% increase due to its growing market share. Internet Explorer (IE) vulnerabilities on the other hand tripled from year to year, keep in mind that IE numbers include version 6 to 10. In another word, non-supported but still used versions.<\/p>\n<p><strong>JAVA:<\/strong><\/p>\n<p><div id=\"attachment_923\" style=\"width: 888px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/JAVA-exploits.png\" target=\"new\"><img aria-describedby=\"caption-attachment-923\" decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-923\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/JAVA-exploits-878x900.png\" alt=\"JAVA\" width=\"878\" height=\"900\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/JAVA-exploits-878x900.png 878w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/JAVA-exploits-292x300.png 292w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/JAVA-exploits.png 910w\" sizes=\"(max-width: 878px) 100vw, 878px\" \/><\/a><p id=\"caption-attachment-923\" class=\"wp-caption-text\"><a href=\"http:\/\/netwars-project.com\/webdoc\" target=\"new\">Image source: Netwars Project<\/a><\/p><\/div><br \/>\nJAVA is one of the hackers favored applications, right after the Adobe software. It&#8217;s easy to program a JAVA applet and most people do have JAVA installed. It does help that the auto update feature is broken most of the times and the security updates aren&#8217;t as frequent as they should be.<\/p>\n<p><strong>Adobe Acrobat Reader:<\/strong><\/p>\n<p><div id=\"attachment_926\" style=\"width: 908px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Acrobat-exploits.png\" target=\"new\"><img aria-describedby=\"caption-attachment-926\" decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-926\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Acrobat-exploits-898x900.png\" alt=\"Acrobat\" width=\"898\" height=\"900\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Acrobat-exploits-898x900.png 898w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Acrobat-exploits-150x150.png 150w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Acrobat-exploits-299x300.png 299w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Acrobat-exploits.png 936w\" sizes=\"(max-width: 898px) 100vw, 898px\" \/><\/a><p id=\"caption-attachment-926\" class=\"wp-caption-text\"><a href=\"http:\/\/netwars-project.com\/webdoc\" target=\"new\">Image source: Netwars Project<\/a><\/p><\/div><br \/>\nThe Adobe Acrobat Reader is probably the hackers most favored application. Practically everyone with computer has this application and Adobe isn&#8217;t known for creating secured code and\/or releasing security patches in a timely manner.<\/p>\n<p><strong>Adobe Flash:<\/strong><\/p>\n<p><div id=\"attachment_928\" style=\"width: 886px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Flash-player-exploits.png\" target=\"new\"><img aria-describedby=\"caption-attachment-928\" decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-928\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Flash-player-exploits-876x900.png\" alt=\"Adobe Flash\" width=\"876\" height=\"900\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Flash-player-exploits-876x900.png 876w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Flash-player-exploits-292x300.png 292w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2014\/07\/Flash-player-exploits.png 898w\" sizes=\"(max-width: 876px) 100vw, 876px\" \/><\/a><p id=\"caption-attachment-928\" class=\"wp-caption-text\"><a href=\"http:\/\/netwars-project.com\/webdoc\" target=\"new\">Image source: Netwars Project<\/a><\/p><\/div><br \/>\nThe number of Flash Player vulnerabilities had actually decreased from year to date. That&#8217;s good news, but mainly due to the news that Adobe had announced that stopped developing flash for the mobile platform. The replacement for flash will be HTLM version 5 and Adobe AIR. Hopefully, the desktop platform will be the next where flash disappears.<\/p>\n<p>There are other hackers favored applications, such as Microsoft Office, media players, etc., but these applications did not have the size of growth year-to-year as the applications listed above.<\/p>\n<p>So, again, why is that important to know? Well, if you keep your operating system and applications up to date, you&#8217;ve just substantially decreased the chance of your system being exploited&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware targets applications, hardware, and operating systems (OS) by exploiting known\/unknown vulnerabilities in their software code. Why is that important to know? Well, knowing which components of your computer used for exploit is half of the battle in protecting your &hellip; <a href=\"https:\/\/blogs.secure-bits.com\/?p=905\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[25,24],"tags":[],"_links":{"self":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts\/905"}],"collection":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=905"}],"version-history":[{"count":31,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts\/905\/revisions"}],"predecessor-version":[{"id":1022,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts\/905\/revisions\/1022"}],"wp:attachment":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}