I LOVE YOU VIRUS.pptx

EzraBehr 345 views 27 slides Jun 10, 2023
Slide 1
Slide 1 of 27
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27

About This Presentation

a well built presentation on the I LOVE YOU virus, how it works, its effect and how one can protect himself against it.


Slide Content

FILE EXTENSION EXPLOITS (“I LOVE YOU” VIRUS) Ezra behr

THE POINT OF THIS PRESENTATION Explain what file extensions are Bring awareness to possible extension viruses How to protect yourself from such viruses Showing the affect of the “I LOVE YOU” virus

I LOVE YOU Let's delve into the story of the “I LOVE YOU“ virus…

I LOVE YOU The "I LOVE YOU" virus, also known as the Love Bug or the Love letter worm, was one of the most notorious computer viruses in history. It first appeared in May 2000 and quickly spread worldwide, causing significant damage to computer systems.

I LOVE YOU The virus originated in the Philippines and was created by two computer science students, Reonel Ramones and Onel de Guzman. They designed the virus as a malicious script disguised as a love confession. The virus was distributed via email with the subject line "I LOVE YOU" and an attachment named "LOVE-LETTER-FOR-YOU.TXT.vbs.“ Notice the ending of the file…

I LOVE YOU When unsuspecting users clicked on the attachment, the virus activated and began wreaking havoc. It would: Send a copy of itself using Microsoft Outlook to all the users contacts It would infect the IRC (Internet Relay Chat) program so that the next time a user starts chatting on the web the worm can spread to everyone who connects to the chat server. It would search for pictures, videos and music files and would overwrite or replace them with a copy of itself It would install a password stealing program that would become active when the recipient opens Internet Explorer and reboots the computer.

I LOVE YOU The impact of the "I LOVE YOU" virus was immense. Within hours, it had infected millions of computers around the world, causing widespread disruptions to businesses and individuals. The virus targeted banks, government institutions, and even large corporations, leading to the shutdown of email systems and financial losses estimated in the billions of dollars.

I LOVE YOU Some of the companies that the virus hit

I LOVE YOU The overall damage was HUGE! Data loss Email system was disrupted Financial losses (targeting banks and trying to steal passwords and sensitive info) Productivity impact Global reach

LET’S TRY UNDERSTAND... Let’s understand how the virus worked and why it only popped up in the year 2000 and why did it only affect windows computers. In order to understand such thing, we will first need to learn about FILE EXTENSIONS.

FILE EXTENSIONS A file extension is a set of characters that follows the last period in a file name, which identifies the type of file and the program that can open it. File extensions are used to help operating systems and software applications identify and associate files with the appropriate program. File extensions can be used to identify potentially malicious files that could harm a computer

VIDEO FILE EXTENSION EXAMPLES Some common applications that play video files: .mp4 . mkv .mov . avi .m4v VLC Windows Media Player QuickTime

IMAGE FILE EXTENSION EXAMPLES Some common applications that open image files: .jpg . png .raw .bmp .eps Windows Photos Irfanview Apple Photos

TEXT FILE EXTENSION EXAMPLES Some common applications that open text files: .txt .docx .pdf Adobe Acrobat Notepad Microsoft Word

PROGRAM FILE EXTENSION EXAMPLES .exe .bat .vbs “.exe” is the most used extension. These files can run scripts/programs on the computer and access critical Files on the OS. Hence, if a hacker can install such files on your computer, they can steal passwords, Credit Card info, encrypt personal files and hold it for ransom.

BACK TO US If you remember, the virus “I LOVE YOU” was a .vbs file "LOVE-LETTER-FOR-YOU.TXT.vbs“ So, whenever a user would open the file, it would install a software that would infect the computer.

THE BEGGING QUESTION!!! The begging question is, couldn’t the user see that the file ended in .vbs? If so, why did he install the program? There are 2 answer: The user had no idea about file extensions, so they didn’t know what they were getting into. The user didn’t realize that it’s a . vbs because it had a .txt in the name and once the program was installed the . vbs was HIDDEN.

HIDDEN FILE EXTENSIONS What is a hidden file extension? In Windows 2000 Microsoft set the default behavior of file explorer to hide known file extensions such as .mp4, .pdf, .vbs and so on from the user. Before Windows 2000 After Windows 2000

THE REASON The original reason that Microsoft did this was to simplify the layout for less savvy users. Another reason why this was done, was to prevent users from accidently changing the extension when renaming the file, thus corrupting the file.

Live demo of corrupting a file by renaming it.

THE PROBLEM

THE PROBLEM Hiding the file extension opens a golden door for hacker to install malware on the computer. For example, a hacker can call a virus that ends with .exe “document1” and change the icon to a document icon and the user wouldn’t know the wiser because the extension is hidden and the icon looks like a document icon .

I LOVE YOU That is how the “I LOVE YOU” virus was made. The hackers used the new Microsoft feature to get innocent people to download and open their virus. And in our case the hackers went even further by adding a .txt part to the file name so that the few people who did know something about file extensions got misled.

HOW TO ENABLE FILE NAME EXTENSIONS? 1. Go to the settings (options) of the file explorer

HOW TO ENABLE FILE NAME EXTENSIONS? 2. In the folder options go to “View” 3. Toggle the “Hide extensions to known file types” off. 4. Than click “Apply”

IN CONCLUSION How can we protect ourselves against such viruses? Enable file name extension, so you can see what kind of file you’re opening. Be aware not to download anything from any unknow sites, and if you do have any suspicions ask a professional or scan the file for viruses.

THE END