Development of windows malicious codes for remote computers.

number: 
737
إنجليزية
department: 
Degree: 
Imprint: 
Computer Science
Author: 
Manar Saad Salih Al-Taie
Supervisor: 
Dr.Imad H Al-Hussaini
Dr. Venus W. Samawi
year: 
2002
Abstract:

Due to the increasing attacks of malicious code, it becomes important to understand the behavior of different types of malicious code. Traditional examples of malicious code include Trojan horses, viruses and worms. This work concerns with the development of two types of malicious codes works under windows environments. These are RAT (Remote Access Trojan) and DV (Destructive Virus). RAT provides an access to a remote computer(s) depending on the concept of client/server software system and performs different attacking types on the remote (victim's) computer. Windows sockets for RAT are used to perform remote accessing since it provides the ability to access through drives even if they are non-sharable. DV spreads among different computers on network as an attachment via email messages and performs its payload after spreading from each victim computer. This work also concerns with the development of Anti-software dealing with each of the developed malicious codes using scan string approach. Both the malicious codes and their Anti-software are implemented using Visual Basic programming Language version 6 (VB) under Windows Millennium. The developed codes were tested under different environments (Windows Millennium, Windows 98, Windows 2000, and Windows XP) and the results obtained are quite encouraging.