1
1

00:00:00,290  -->  00:00:01,123
<v ->Malware.</v>
2

2

00:00:01,123  -->  00:00:02,300
In this lesson,
3

3

00:00:02,300  -->  00:00:03,680
we're going to discuss some different types
4

4

00:00:03,680  -->  00:00:05,184
of malware that you may come across
5

5

00:00:05,184  -->  00:00:08,620
while working as a cyber security or network technician.
6

6

00:00:08,620  -->  00:00:10,250
So, what is malware?
7

7

00:00:10,250  -->  00:00:13,570
Well, malware is a shorthand term for malicious software.
8

8

00:00:13,570  -->  00:00:14,810
This is software that's designed
9

9

00:00:14,810  -->  00:00:16,360
to infiltrate a computer system
10

10

00:00:16,360  -->  00:00:17,780
and possibly damage it without
11

11

00:00:17,780  -->  00:00:19,690
the user's knowledge or consent.
12

12

00:00:19,690  -->  00:00:22,700
Simply put, malware is some kind of bad software code
13

13

00:00:22,700  -->  00:00:25,610
that wants to do harm to our computers and our networks.
14

14

00:00:25,610  -->  00:00:29,047
Malware comes in many varieties, including viruses, worms,
15

15

00:00:29,047  -->  00:00:33,060
Trojan horses, ransomware, spyware, and rootkits.
16

16

00:00:33,060  -->  00:00:35,760
The first type of malware we have is known as viruses.
17

17

00:00:35,760  -->  00:00:38,230
A computer virus is simply made up of malicious code
18

18

00:00:38,230  -->  00:00:40,760
that's run on a machine without the user's knowledge.
19

19

00:00:40,760  -->  00:00:42,316
This code allows it to infect the computer
20

20

00:00:42,316  -->  00:00:44,370
whenever that code is run.
21

21

00:00:44,370  -->  00:00:46,350
Now, what does this look like in the real world?
22

22

00:00:46,350  -->  00:00:47,814
Well, one of your users may have gone
23

23

00:00:47,814  -->  00:00:49,950
to a website to download a new game,
24

24

00:00:49,950  -->  00:00:50,860
and when they did that,
25

25

00:00:50,860  -->  00:00:52,780
they actually download an installation file
26

26

00:00:52,780  -->  00:00:55,670
that contained a virus or malicious code inside of it.
27

27

00:00:55,670  -->  00:00:57,690
When they ran that program to install the game,
28

28

00:00:57,690  -->  00:00:59,480
they actually just installed the virus onto
29

29

00:00:59,480  -->  00:01:00,510
the client machine,
30

30

00:01:00,510  -->  00:01:03,040
and now, that virus has taken hold.
31

31

00:01:03,040  -->  00:01:03,873
At this point,
32

32

00:01:03,873  -->  00:01:05,272
the virus is going to want to reproduce and spread,
33

33

00:01:05,272  -->  00:01:08,840
and it does this because you had a user action occur.
34

34

00:01:08,840  -->  00:01:09,734
This was namely the opening
35

35

00:01:09,734  -->  00:01:11,976
and running of the game's install file.
36

36

00:01:11,976  -->  00:01:13,440
Once this has been done,
37

37

00:01:13,440  -->  00:01:14,712
the virus can now begin to replicate
38

38

00:01:14,712  -->  00:01:17,401
and attempt to spread further across the network.
39

39

00:01:17,401  -->  00:01:20,530
Our second type of malware is known as a worm.
40

40

00:01:20,530  -->  00:01:22,610
Now a worm is a piece of malicious software,
41

41

00:01:22,610  -->  00:01:23,750
much like a virus.
42

42

00:01:23,750  -->  00:01:27,158
But it can replicate itself without any user interaction.
43

43

00:01:27,158  -->  00:01:29,926
This is a key distinction between a virus and a worm.
44

44

00:01:29,926  -->  00:01:31,578
Remember, I said the user had
45

45

00:01:31,578  -->  00:01:33,960
to install the program or open a file
46

46

00:01:33,960  -->  00:01:35,590
in order to have the virus take action
47

47

00:01:35,590  -->  00:01:37,040
and begin its replication.
48

48

00:01:37,040  -->  00:01:39,430
But with worms, this simply isn't the case.
49

49

00:01:39,430  -->  00:01:41,530
Worms are able to self-replicate
50

50

00:01:41,530  -->  00:01:42,990
and they spread throughout your network
51

51

00:01:42,990  -->  00:01:44,959
without a user's consent or action.
52

52

00:01:44,959  -->  00:01:47,050
This occurs because worms take advantage
53

53

00:01:47,050  -->  00:01:48,810
of security vulnerabilities that exist
54

54

00:01:48,810  -->  00:01:50,040
within operating systems,
55

55

00:01:50,040  -->  00:01:52,370
network protocols, and other applications.
56

56

00:01:52,370  -->  00:01:53,350
If the warm determines
57

57

00:01:53,350  -->  00:01:54,820
that there is a computer on the network
58

58

00:01:54,820  -->  00:01:56,699
that doesn't have the latest security patch installed,
59

59

00:01:56,699  -->  00:01:58,134
it can then take advantage of that
60

60

00:01:58,134  -->  00:01:59,930
and exploit that vulnerability
61

61

00:01:59,930  -->  00:02:02,890
to spread from victim to victim across the entire network,
62

62

00:02:02,890  -->  00:02:06,020
or even across the internet and the entire world.
63

63

00:02:06,020  -->  00:02:06,900
Because of this,
64

64

00:02:06,900  -->  00:02:09,110
worms can cause disruption to your normal network traffic
65

65

00:02:09,110  -->  00:02:11,150
and your computing activities,
66

66

00:02:11,150  -->  00:02:12,980
because as they're spreading and replicating
67

67

00:02:12,980  -->  00:02:14,270
from victim to victim,
68

68

00:02:14,270  -->  00:02:16,090
they're also using its processing power,
69

69

00:02:16,090  -->  00:02:18,140
its memory, and its network traffic,
70

70

00:02:18,140  -->  00:02:20,510
it's going to be using all these different resources,
71

71

00:02:20,510  -->  00:02:22,580
and not for something that you want them to do.
72

72

00:02:22,580  -->  00:02:24,795
Eventually, this can start slowing down your systems,
73

73

00:02:24,795  -->  00:02:26,070
or in some cases,
74

74

00:02:26,070  -->  00:02:28,980
it can cause your systems or your networks to crash.
75

75

00:02:28,980  -->  00:02:30,966
Worms are known for spreading far and wide over
76

76

00:02:30,966  -->  00:02:33,840
the internet in a relatively short amount of time.
77

77

00:02:33,840  -->  00:02:36,570
Back in 2001, there was a worm named Nimda,
78

78

00:02:36,570  -->  00:02:38,025
which is admin spelled backwards.
79

79

00:02:38,025  -->  00:02:39,880
Now it was able to propagate across
80

80

00:02:39,880  -->  00:02:42,358
the entire internet in just 22 minutes.
81

81

00:02:42,358  -->  00:02:44,534
Then in 2009, we had another worm.
82

82

00:02:44,534  -->  00:02:46,830
This one was known as Conficker.
83

83

00:02:46,830  -->  00:02:48,330
This was probably one of the largest worms
84

84

00:02:48,330  -->  00:02:49,860
that we as cybersecurity professionals
85

85

00:02:49,860  -->  00:02:51,070
have seen to date.
86

86

00:02:51,070  -->  00:02:52,409
Conficker was able to infect between nine
87

87

00:02:52,409  -->  00:02:55,408
and 15 million machines worldwide.
88

88

00:02:55,408  -->  00:02:57,870
This worm was infecting as many machines
89

89

00:02:57,870  -->  00:02:59,730
as it could by leveraging exploit
90

90

00:02:59,730  -->  00:03:02,058
against a missing Microsoft Windows security patch.
91

91

00:03:02,058  -->  00:03:04,080
This was specifically the patch associated
92

92

00:03:04,080  -->  00:03:07,007
with the MS-08-067 eight security bulletin.
93

93

00:03:07,007  -->  00:03:09,169
Now, the vulnerability was a coding error
94

94

00:03:09,169  -->  00:03:10,476
with the way Microsoft Windows
95

95

00:03:10,476  -->  00:03:13,000
was performing file and printer sharing.
96

96

00:03:13,000  -->  00:03:14,470
Conficker sought out those machines
97

97

00:03:14,470  -->  00:03:15,930
that were missing the security patch,
98

98

00:03:15,930  -->  00:03:17,640
installed this piece of code on them,
99

99

00:03:17,640  -->  00:03:20,157
and then those machines became part of a botnet.
100

100

00:03:20,157  -->  00:03:21,811
Ultimately, this botnet was able
101

101

00:03:21,811  -->  00:03:23,580
to be shut down before it was used
102

102

00:03:23,580  -->  00:03:25,540
for negative or malicious purposes,
103

103

00:03:25,540  -->  00:03:27,680
but it does show the true power of these worms,
104

104

00:03:27,680  -->  00:03:28,970
and how they can gather up lots
105

105

00:03:28,970  -->  00:03:31,740
and lots of zombies for a botnet really quickly
106

106

00:03:31,740  -->  00:03:32,764
for use later on.
107

107

00:03:32,764  -->  00:03:34,480
The third type of malware we have
108

108

00:03:34,480  -->  00:03:36,280
is known as a Trojan horse.
109

109

00:03:36,280  -->  00:03:37,388
A Trojan horse gets his name
110

110

00:03:37,388  -->  00:03:39,590
from the legendary trick that was used during
111

111

00:03:39,590  -->  00:03:41,788
the Trojan War back in ancient Greece.
112

112

00:03:41,788  -->  00:03:44,180
Greece and Troy were at war for 10 years,
113

113

00:03:44,180  -->  00:03:45,700
and there was no end in sight.
114

114

00:03:45,700  -->  00:03:46,540
After a long siege,
115

115

00:03:46,540  -->  00:03:48,810
the Greeks decided they were getting restless,
116

116

00:03:48,810  -->  00:03:49,643
and they decided they wanted
117

117

00:03:49,643  -->  00:03:51,070
to try something a little different
118

118

00:03:51,070  -->  00:03:52,610
to get this war over with.
119

119

00:03:52,610  -->  00:03:55,330
So, they decided to construct a large wooden horse,
120

120

00:03:55,330  -->  00:03:57,760
and they gave it to the city of Troy as a peace offering,
121

121

00:03:57,760  -->  00:03:59,540
or so the story goes.
122

122

00:03:59,540  -->  00:04:00,540
Now, this seemingly harmless gift
123

123

00:04:00,540  -->  00:04:02,770
was actually filled with Greek soldiers.
124

124

00:04:02,770  -->  00:04:04,301
And once it was wheeled inside the city,
125

125

00:04:04,301  -->  00:04:05,700
day turned to night,
126

126

00:04:05,700  -->  00:04:08,010
and the soldiers emerged from within the horse.
127

127

00:04:08,010  -->  00:04:09,450
These soldiers immediately opened
128

128

00:04:09,450  -->  00:04:11,210
the walled city gates and began letting
129

129

00:04:11,210  -->  00:04:12,470
in their fellow soldiers
130

130

00:04:12,470  -->  00:04:14,250
that were from the invading Greek army.
131

131

00:04:14,250  -->  00:04:16,630
They got into the city and they laid waste to it.
132

132

00:04:16,630  -->  00:04:19,320
This was the first example of a Trojan horse.
133

133

00:04:19,320  -->  00:04:21,950
Now in the world of cybersecurity and computer networking,
134

134

00:04:21,950  -->  00:04:23,916
Trojan horses work much the same way.
135

135

00:04:23,916  -->  00:04:25,968
Trojan horses are pieces of malicious code
136

136

00:04:25,968  -->  00:04:28,340
that's disguised as a piece of harmless
137

137

00:04:28,340  -->  00:04:29,840
or desirable software.
138

138

00:04:29,840  -->  00:04:31,700
Basically, a Trojan says I'm going
139

139

00:04:31,700  -->  00:04:33,180
to perform this function for you.
140

140

00:04:33,180  -->  00:04:35,423
And it may very well perform that desired function.
141

141

00:04:35,423  -->  00:04:38,074
But it can also perform a malicious function too.
142

142

00:04:38,074  -->  00:04:39,660
Now, when I was a kid,
143

143

00:04:39,660  -->  00:04:41,290
there was a new game out called Tetris
144

144

00:04:41,290  -->  00:04:42,780
that you probably have heard of at this point,
145

145

00:04:42,780  -->  00:04:44,340
and it was extremely popular,
146

146

00:04:44,340  -->  00:04:45,920
everybody wanted to get a copy of it.
147

147

00:04:45,920  -->  00:04:46,930
So a lot of times,
148

148

00:04:46,930  -->  00:04:48,650
you might have a friend who put a copy of it
149

149

00:04:48,650  -->  00:04:50,990
on a disc, and they handed it to you so you can install it
150

150

00:04:50,990  -->  00:04:53,460
at home, and you could play this great new game to.
151

151

00:04:53,460  -->  00:04:54,556
Well, one person was really smart
152

152

00:04:54,556  -->  00:04:56,109
and they used a copy of Tetris
153

153

00:04:56,109  -->  00:04:59,740
and embedded a Trojan horse inside that copy of Tetris.
154

154

00:04:59,740  -->  00:05:01,468
Now, if you took that disc and installed
155

155

00:05:01,468  -->  00:05:03,240
that game on your computer,
156

156

00:05:03,240  -->  00:05:05,121
that game would launch and play just like normal.
157

157

00:05:05,121  -->  00:05:07,165
You could play Tetris, no issue at all.
158

158

00:05:07,165  -->  00:05:09,675
But in the background, the Trojan horse part of this,
159

159

00:05:09,675  -->  00:05:12,360
opened up something that allowed a connection
160

160

00:05:12,360  -->  00:05:14,880
between your system and the attacker's system,
161

161

00:05:14,880  -->  00:05:16,270
allowing them to have remote control
162

162

00:05:16,270  -->  00:05:19,000
and steal your information or destroy your data.
163

163

00:05:19,000  -->  00:05:20,064
This is one of the earliest examples
164

164

00:05:20,064  -->  00:05:21,570
of what we now refer to
165

165

00:05:21,570  -->  00:05:24,410
as a RAT, or Remote Access Trojan.
166

166

00:05:24,410  -->  00:05:26,340
A RAT is a common type of Trojan
167

167

00:05:26,340  -->  00:05:27,930
that's still widely used today.
168

168

00:05:27,930  -->  00:05:29,730
It provides the attacker with remote control
169

169

00:05:29,730  -->  00:05:30,764
of a victim system.
170

170

00:05:30,764  -->  00:05:33,570
These techniques are still really used a lot today,
171

171

00:05:33,570  -->  00:05:35,570
but instead of somebody handing you a disc,
172

172

00:05:35,570  -->  00:05:36,630
they instead post the file
173

173

00:05:36,630  -->  00:05:38,700
on a website and they wait for you to download it.
174

174

00:05:38,700  -->  00:05:40,400
Remember, whenever you're downloading
175

175

00:05:40,400  -->  00:05:41,600
a program from the internet,
176

176

00:05:41,600  -->  00:05:42,433
always be careful,
177

177

00:05:42,433  -->  00:05:43,590
because you don't know what other code
178

178

00:05:43,590  -->  00:05:45,085
is inside of that lurking there.
179

179

00:05:45,085  -->  00:05:47,116
Anytime you or your users are downloading a file,
180

180

00:05:47,116  -->  00:05:49,662
you have to make sure you check it for viruses, worms,
181

181

00:05:49,662  -->  00:05:52,157
and Trojans before you install it.
182

182

00:05:52,157  -->  00:05:54,908
The fourth type of malware we have is known as ransomware.
183

183

00:05:54,908  -->  00:05:56,260
If you've watched the news
184

184

00:05:56,260  -->  00:05:58,260
or scrolled Facebook in the last year or two,
185

185

00:05:58,260  -->  00:06:00,030
you probably already know what ransomware is
186

186

00:06:00,030  -->  00:06:02,570
because it keeps showing up all over our news feeds.
187

187

00:06:02,570  -->  00:06:03,884
Ransomware is a type of malware
188

188

00:06:03,884  -->  00:06:06,573
that restricts access to a victim's computer system
189

189

00:06:06,573  -->  00:06:10,270
or their files until a ransom or payment is received.
190

190

00:06:10,270  -->  00:06:12,318
Essentially, someone's going to break into a network,
191

191

00:06:12,318  -->  00:06:14,080
a server or a computer,
192

192

00:06:14,080  -->  00:06:15,190
and then they're going to encrypt all
193

193

00:06:15,190  -->  00:06:16,990
the files or change the passwords,
194

194

00:06:16,990  -->  00:06:18,770
or do something else to hold that system hostage
195

195

00:06:18,770  -->  00:06:20,700
until you pay up.
196

196

00:06:20,700  -->  00:06:22,360
One day, you may reboot your computer
197

197

00:06:22,360  -->  00:06:23,549
and it says something like this,
198

198

00:06:23,549  -->  00:06:25,190
your computer has been locked.
199

199

00:06:25,190  -->  00:06:26,457
You have to pay a fine of $200
200

200

00:06:26,457  -->  00:06:28,900
and be able to pay it through this link using Bitcoin
201

201

00:06:28,900  -->  00:06:30,028
and able to get access back.
202

202

00:06:30,028  -->  00:06:31,400
If you pay me,
203

203

00:06:31,400  -->  00:06:32,588
I'll give you a secret unlock code,
204

204

00:06:32,588  -->  00:06:34,380
and you can put it in that white box,
205

205

00:06:34,380  -->  00:06:36,896
and you can hit OK, and have access to all your stuff.
206

206

00:06:36,896  -->  00:06:38,429
This is what ransomware looks like
207

207

00:06:38,429  -->  00:06:40,310
when it targets end users.
208

208

00:06:40,310  -->  00:06:41,326
But even more recently,
209

209

00:06:41,326  -->  00:06:43,036
we're seeing large-scale ransom attacks
210

210

00:06:43,036  -->  00:06:45,930
against large corporations and local governments,
211

211

00:06:45,930  -->  00:06:46,910
including oil pipelines,
212

212

00:06:46,910  -->  00:06:49,710
hospital systems, and even city governments.
213

213

00:06:49,710  -->  00:06:51,204
Back in 2018, the city of Atlanta
214

214

00:06:51,204  -->  00:06:53,404
got infected with the SamSam ransomware.
215

215

00:06:53,404  -->  00:06:54,831
This started spreading across
216

216

00:06:54,831  -->  00:06:56,960
a lot of their systems throughout the city,
217

217

00:06:56,960  -->  00:07:00,092
and it ended up costing them over $17 million to fix it.
218

218

00:07:00,092  -->  00:07:02,360
They ended up not paying the ransom,
219

219

00:07:02,360  -->  00:07:04,490
but instead, they spent about $6 million
220

220

00:07:04,490  -->  00:07:06,760
in services and contracts and software upgrades,
221

221

00:07:06,760  -->  00:07:09,350
and another $11 million in hardware upgrades
222

222

00:07:09,350  -->  00:07:11,760
to be able to deal with the SamSam ransomware.
223

223

00:07:11,760  -->  00:07:13,490
This made it the costliest cyber attack
224

224

00:07:13,490  -->  00:07:14,924
affecting the government in 2018.
225

225

00:07:14,924  -->  00:07:17,410
And this was despite them not paying
226

226

00:07:17,410  -->  00:07:19,117
the ransom demanded by the attackers.
227

227

00:07:19,117  -->  00:07:21,330
Usually, ransomware is going to get
228

228

00:07:21,330  -->  00:07:22,928
a foothold into your network somewhere
229

229

00:07:22,928  -->  00:07:24,370
because of a vulnerability
230

230

00:07:24,370  -->  00:07:25,860
in a piece of software on one
231

231

00:07:25,860  -->  00:07:27,700
of your servers or your clients.
232

232

00:07:27,700  -->  00:07:28,913
Once it gets into the network though,
233

233

00:07:28,913  -->  00:07:30,950
it's going to attempt to steal your data
234

234

00:07:30,950  -->  00:07:31,846
and hold it hostage.
235

235

00:07:31,846  -->  00:07:33,400
Once they do that,
236

236

00:07:33,400  -->  00:07:34,734
you have no way to decrypt that data
237

237

00:07:34,734  -->  00:07:37,804
unless you pay the ransom or restore from an offline backup.
238

238

00:07:37,804  -->  00:07:41,230
The fifth type of malware we have is known as spyware.
239

239

00:07:41,230  -->  00:07:42,540
Spyware is a type of malicious software
240

240

00:07:42,540  -->  00:07:44,300
that's installed on your system,
241

241

00:07:44,300  -->  00:07:46,605
and it gathers information about you without your consent.
242

242

00:07:46,605  -->  00:07:48,860
Normally, this will be installed either
243

243

00:07:48,860  -->  00:07:50,652
from a website or some third-party software
244

244

00:07:50,652  -->  00:07:52,860
that you have installed on your system.
245

245

00:07:52,860  -->  00:07:54,900
That software is going to look through all your files.
246

246

00:07:54,900  -->  00:07:56,360
It's going to look through all your emails,
247

247

00:07:56,360  -->  00:07:57,430
all of your instant messages,
248

248

00:07:57,430  -->  00:07:58,450
all your calendar invites,
249

249

00:07:58,450  -->  00:08:00,750
and what other information you may have on your system,
250

250

00:08:00,750  -->  00:08:02,324
it's going to look through that together information
251

251

00:08:02,324  -->  00:08:04,380
and build a profile on you.
252

252

00:08:04,380  -->  00:08:05,756
This is the best case scenario.
253

253

00:08:05,756  -->  00:08:07,160
Now, after all,
254

254

00:08:07,160  -->  00:08:08,812
spyware may just be trying to figure out things
255

255

00:08:08,812  -->  00:08:10,370
they can advertise to you.
256

256

00:08:10,370  -->  00:08:11,230
And in this case,
257

257

00:08:11,230  -->  00:08:13,730
we call this a thing called adware.
258

258

00:08:13,730  -->  00:08:15,620
Now, this allows you to display advertisements
259

259

00:08:15,620  -->  00:08:17,600
to you based on what they think you'd like best
260

260

00:08:17,600  -->  00:08:19,010
and what you're most likely to buy.
261

261

00:08:19,010  -->  00:08:20,273
Now, in the worst case,
262

262

00:08:20,273  -->  00:08:22,326
spyware could include a key logger.
263

263

00:08:22,326  -->  00:08:24,690
Now, a key logger can allow an attacker
264

264

00:08:24,690  -->  00:08:26,972
to capture any keystrokes you make on a victim machine,
265

265

00:08:26,972  -->  00:08:29,420
such as the website addresses you type in,
266

266

00:08:29,420  -->  00:08:32,040
the usernames, and even the password you enter.
267

267

00:08:32,040  -->  00:08:33,270
Spyware and key loggers
268

268

00:08:33,270  -->  00:08:34,490
can collect those details
269

269

00:08:34,490  -->  00:08:36,220
and send it all back to the attacker,
270

270

00:08:36,220  -->  00:08:37,970
complete with screenshots that they're taking
271

271

00:08:37,970  -->  00:08:40,255
on a regular interval of your computer screen.
272

272

00:08:40,255  -->  00:08:42,230
Now our sixth type of malware we have
273

273

00:08:42,230  -->  00:08:43,710
is known as a rootkit.
274

274

00:08:43,710  -->  00:08:45,280
A rootkit is a specific type of software
275

275

00:08:45,280  -->  00:08:47,810
that's designed to gain administrative level control
276

276

00:08:47,810  -->  00:08:49,850
over a computer system or network device
277

277

00:08:49,850  -->  00:08:51,270
without being detected.
278

278

00:08:51,270  -->  00:08:52,570
Now, this is really important
279

279

00:08:52,570  -->  00:08:54,130
because when we talk about root
280

280

00:08:54,130  -->  00:08:55,516
or administrator level permissions,
281

281

00:08:55,516  -->  00:08:57,530
this is the highest level of permissions
282

282

00:08:57,530  -->  00:08:58,958
that someone can have on a system.
283

283

00:08:58,958  -->  00:09:00,770
If you're using a Windows machine,
284

284

00:09:00,770  -->  00:09:03,090
for example, that will be your administrator account
285

285

00:09:03,090  -->  00:09:04,770
that allows somebody to install programs,
286

286

00:09:04,770  -->  00:09:06,974
delete programs, open ports, and shut ports.
287

287

00:09:06,974  -->  00:09:09,129
Basically, they can do whatever they want on your system.
288

288

00:09:09,129  -->  00:09:11,198
This type of access is known as root access
289

289

00:09:11,198  -->  00:09:14,400
if you're using Unix, Linux or OS X,
290

290

00:09:14,400  -->  00:09:15,759
which is a Mac operating system.
291

291

00:09:15,759  -->  00:09:17,453
Either way, gaining administrative
292

292

00:09:17,453  -->  00:09:19,920
or root access is great for an attacker,
293

293

00:09:19,920  -->  00:09:21,970
but it is horrible for you and your security.
294

294

00:09:21,970  -->  00:09:23,180
Now in our networks,
295

295

00:09:23,180  -->  00:09:25,580
the most common place to find a rootkit would be
296

296

00:09:25,580  -->  00:09:26,470
if the attacker was able
297

297

00:09:26,470  -->  00:09:29,400
to compromise the firmware on our routers or switches.
298

298

00:09:29,400  -->  00:09:30,289
There have been documented cases
299

299

00:09:30,289  -->  00:09:32,180
of this for pretty much every brand
300

300

00:09:32,180  -->  00:09:33,550
of router and switch out there.
301

301

00:09:33,550  -->  00:09:34,790
So it's important to keep up to date
302

302

00:09:34,790  -->  00:09:35,950
with the latest threats based
303

303

00:09:35,950  -->  00:09:36,783
on the type of equipment
304

304

00:09:36,783  -->  00:09:39,000
that you're using inside your networks.
305

305

00:09:39,000  -->  00:09:40,076
Rootkits are extremely powerful,
306

306

00:09:40,076  -->  00:09:41,690
and they're really difficult
307

307

00:09:41,690  -->  00:09:43,740
to detect, because the operating system itself
308

308

00:09:43,740  -->  00:09:44,770
can be blinded to them,
309

309

00:09:44,770  -->  00:09:47,480
since they're loaded before the operating system itself is.
310

310

00:09:47,480  -->  00:09:49,320
To detect them, the best way is to boot
311

311

00:09:49,320  -->  00:09:50,430
from an external device,
312

312

00:09:50,430  -->  00:09:51,860
and then scan the device to ensure
313

313

00:09:51,860  -->  00:09:53,548
that you can probably detect those rootkits.
314

314

00:09:53,548  -->  00:09:55,148
As I said earlier in this lesson,
315

315

00:09:55,148  -->  00:09:57,263
there are lots of different types of malware.
316

316

00:09:57,263  -->  00:09:59,532
In this lesson, we discussed just a few of them.
317

317

00:09:59,532  -->  00:10:02,262
We talked about viruses and worms, and Trojan horses,
318

318

00:10:02,262  -->  00:10:04,870
and ransomware, and spyware, and rootkits.
319

319

00:10:04,870  -->  00:10:06,200
But there are many others out there
320

320

00:10:06,200  -->  00:10:07,033
that you're going to learn
321

321

00:10:07,033  -->  00:10:07,866
about as you continue
322

322

00:10:07,866  -->  00:10:10,381
to advance in your cybersecurity career.
323

323

00:10:10,381  -->  00:10:13,103
(offbeat motivating music)
