As a reference to my post Trojan Horse: Absolute Beginner's Tutorial, this post explains about infection of Trojan Horse virus and ports used for infection. Trojan Horse is a favorite hacktool used for hacking and the tutorial provides the information necessary for that. After being hacked by using trojan, various symptoms are seen and trojan virus removal becomes important.The post explains necessary precautions to prevent trojan virus attacks.
Infection by a Trojan horse virus usually comes after opening a contaminated file containing the Trojan horse and is indicated by the following symptoms:
- Abnormal activity by the modem,network adapter or hard drive: data is being loaded without any activity from the user;
- Strange reactions from the mouse
- Programs opening unexpectedly;
- Repeated crashes.
Principle of a Trojan horse
As a Trojan horse is usually (and increasingly) intended to open a port on your machine so that a hacker can gain control of it (such as by stealing personal data stored on the hard drive), the hacker's goal is to first infect your machine by making you open an infected file containing the Trojan and then to access your machine through the opened port.
However, to be able to infiltrate your machine, the hacker normally has to know its IP Address. So:
- Either you have a fixed IP address(as with businesses, or with individuals with a cable or similar connection, etc.) in which case your IP address can easily be discovered;
- or your IP address is dynamic (reassigned each time you connect), as with modem connections; in which case the hacker must scan IP addresses at random in order to detect those which correspond to infected machines.
Protect yourself from Trojans
As i have explained in my post Firewall- A hindrance in hacking, Firewall is used to protect the user from various hacking attempts.
Installing a firewall (a program which filters data entering and leaving your machine) is enough to protect you from this kind of intrusion. A firewall monitors both data leaving your machine (normally initiated by the programs you are using) and data entering it. However, the firewall may detect unknown outside connections even if a hacker is not specifically targeting you.. They may be tests carried out by your Internet service provider, or a hacker randomly scanning a range of IP addresses.
For Windows systems, there are two free high-performance firewalls:
In case of infection
If a program whose origins you are unsure of attempts to open a connection, the firewall will ask you to confirm it before initiating the connection. It is important to not authorise connections for a program you don't recognise, because it might very well be a Trojan horse.
If this reoccurs, it may be helpful to check that your computer isn't affected by a Trojan, by using a program that detects and deletes them (called an anti-Trojan).
One example is The Cleaner, which can be downloaded from http://www.moosoft.com.
List of ports commonly used by Trojans
Trojan horses commonly open a port on the infected machine and wait for a connection to open on that port, so that hackers will be able to gain total control over the computer. The article:
Ports used by Trojans
is a (non exhaustive) list of the most common ports used by Trojan horses (source: Site de Rico)
Enjoy HaCkInG.....
ads


0 comments