Christopher Boyd

Christopher Boyd

Chris Boyd re-diverts here. For the association footballer, see Kris Boyd.

Christopher Boyd
Other names Paperghost
Occupation Webmaster
Known for Computer Security

Christopher Boyd, better known as his online pseudonym Paperghost, is a computer security researcher awarded a Microsoft Most Valuable Professional award for computer security.[1]

Boyd is former Director of Malware Research for security company FaceTime, and currently works for Sunbelt Software.

Contents

Computer security

In July 2004, Boyd launched Vitalsecurity.org and he has been instrumental in uncovering and bringing to the public attention issues of privacy and spyware.

In November 2004, a modular hacking technique was employed to compromise Windows end-users by hacking Apache servers.[2] When hacked, the servers would redirect a user on any of the server's websites, leading them to a set of ever-changing infection pages. These pages employed recoded viruses, trojans, malware and spyware. This technique is used heavily today by the groups behind the spyware CoolWebSearch (CWS).

The idea that alternative browsers such as Opera and Firefox could somehow enhance end-user security was cut down in March 2005[3] with the discovery of a Java applet that, if agreed to, would install a large (and varied) adware bundle onto the end-user's PC. It was found that having the "rogue" site in the user's blocklists and security tools would do nothing, the install bypassing these tactics completely if the end-user clicked "Yes". An updated Firefox .XPI installer (which infected Internet Explorer) was also deployed in some of these installs.

BitTorrent controversy

In June 2005, it was discovered that more and more Adware makers were turning to alternative sources for their installs, as more end-users become aware of the more common install tactics.[4] A reliance on crude social engineering and P2P systems that were previously clean was now on the rise. Boyd discovered that BitTorrent forums and file-sharing sites were used as a major source of distribution for Aurora (a program produced by Direct Revenue) and a number of other major adware programs, wrapped up in bundles produced by Metrix Marketing Group (MMG), a company who lost control of their own network.[5] Potentially copyright infringing files, illegal pornography and incorrect / absent disclosure was exposed on such a scale as to cause the companies involved (Direct Revenue, 180solutions and others) to publicly declare their discontinuation of these methods.

This story caused such an uproar that numerous media pundits weighed in, and (in some cases) made a delicate situation worse. An article by John C. Dvorak of PC Magazine alleged Boyd was part of some "Grand Microsoft Conspiracy" to bad-mouth BitTorrent to the benefit of their planned P2P tool, Avalanche.[6] Furious P2P users (who were not familiar with the backstory of the investigation) even went as far to say Boyd was in league with the RIAA, out to create further problems for file-sharers by bringing these bundles to light. However - Dvorak's piece caused something approaching outrage on the other side of the fence, leading a fellow Ziff Davis Media publication to go head to head with Dvorak.[7] Dave Methvin of PC Pitstop followed up the investigation with his findings.[8] He alleges that some of the films distributed contained potentially illegal underage pornography, and not long after, MMG went offline and the Adware companies all pulled out of this particular distribution.

Fake Google toolbar

In October 2005, Boyd discovered a "fake" Google Toolbar which was being distributed via Instant Messaging.[9] The toolbar allowed the user to store credit card details, and also opened up a fake Google search page. Boyd also tracked the toolbar back to 2003, through three different versions, each one exploiting vulnerabilities in the Windows operating system.

Instant messaging rootkit

In October / November 2005, Boyd discovered what is considered to be the first known instance of a rootkit being distributed via instant messaging, hidden inside a large payload of adware and spyware.[10] Over a period of months, the group behind the attacks distributed numerous inventive payloads (such as a forced install of BitTorrent[11] to spread movie files) and were eventually traced back to the Middle-East.

Adware critic

Boyd is a notoriously fierce critic of adware companies, famously causing 180solutions to label him a "fanatic" on their Weblog, with bad feeling in evidence on both sides to this day.[12] He is regularly referenced on other leading antispyware sites such as Sunbelt Blog, Suzi Turner's ZDNet blog and Ben Edelman's home page.

Security discoveries

In 2006, Boyd has continued to make significant discoveries in the field of security, including

  • The discovery of a 150,000 strong Botnet ring that used a custom-built Perl script to steal payment data from third party shopping cart applications[13]
  • An expose of a web-browser that redirected end-users to potentially illegal pornography[14]
  • An Instant Messaging Worm that installs its own web browser.[15]
  • The discovery that Adware makers Zango were promoting their content on Myspace.[16]
  • A modular, multi-chained string of infections dubbed the "Pipeline Worm".[17]
  • An Instant Messaging infection that uses Botnet-style tactics to enable click fraud.[18]
  • The discovery of a worm using Quicktime files to spread across MySpace with the intent of pushing Zango Adware.[19]

In December 2009, Boyd posted a message on Twitter indicating he was no longer working for FaceTime and was seeking employment.[20]

From February 2010 Christopher Boyd is working for Sunbelt Software.

References


Wikimedia Foundation. 2010.

Игры ⚽ Нужна курсовая?

Look at other dictionaries:

  • Thomas Christopher Boyd — (born 14 August 1916) was a British Labour Party politician.At the 1955 general election, he was elected as Member of Parliament (MP) for Bristol North West, defeating the sitting Conservative MP Joseph Gurney Braithwaite. He served in the House… …   Wikipedia

  • Boyd (surname) — Boyd is a surname of Scottish origin, and may refer to:A*Adam Boyd, English footballer *Alan Lennox Boyd, British politician (Viscount Boyd) *Alan Stephenson Boyd, American politician *Alex Boyd, Scottish photographer *Alfred Boyd, Canadian… …   Wikipedia

  • Christopher Shyer — Born Downsview, Ontario, Canada Occupation Actor Years active 1994 present Christopher Shyer (sometimes credited as Chris Shyer) is a Canadian actor who has appeared in over 50 film and television roles. Con …   Wikipedia

  • Christopher Eccleston — As the Ninth Doctor in Doctor Who. Born 16 February 1964 (1964 02 16) (age 47) Salford, Lancashire, England …   Wikipedia

  • Christopher Lloyd — en 2007. Nombre real Christopher Allen Lloyd Nacimiento 22 de octubre de 1938 (73 años) …   Wikipedia Español

  • Christopher Fitzgerald (actor) — Christopher Fitzgerald Born Christopher Cantwell Fitzgerald November 26, 1972 (1972 11 26) (age 38) Bryn Mawr, Pennsylvania Spouse Jessica Stone (2003 present) Christopher Cantwell Fitzgerald (born November 26, 1972) is an American actor,… …   Wikipedia

  • Christopher Lloyd (Schauspieler) — Christopher Lloyd (2010) Christopher Allen Lloyd (* 22. Oktober 1938 in Stamford, Connecticut) ist ein US amerikanischer Schauspieler. Inhaltsverzeichnis …   Deutsch Wikipedia

  • Christopher Raymond Perry — (December 4, 1761 – June 1, 1818) was an officer in the United States Navy. He was the father of Oliver Hazard Perry and Matthew Calbraith Perry. Contents 1 Biography 1.1 Early life 1.2 Marriage and family …   Wikipedia

  • Christopher Challis — Born 18 March 1919 (1919 03 18) (age 92) London, United Kingdom Occupation Cinematographer Christopher Challis BSC, FRPS[1] (born 18 March …   Wikipedia

  • Christopher Brookmyre — (born 6 September 1968) is a Scottish novelist whose novels mix comedy, politics, social comment and action with a strong narrative. He has been referred to as a Tartan Noir author.[1] His debut novel was Quite Ugly One Morning and subsequent… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”