Providing Free and Editor Tested Downloads

< HOME | MAC | GEEK - WEAR | SHOPPING | SUPPORT FORUM | TOP DOWNLOADS | >
MajorGeeks.com - If your computer could ask you for it, it would.

Admin Tools
All In One
Android
Anti-Spyware
Anti-Virus
Appearance
Back Up
Benchmarking
Bios
Browsers
CD\DVD\Blu-Ray
Covert Ops
Data Recovery
Diagnostics
Drive Cleaners
Drive Utilities
Driver Tools
Drivers
Ergonomics
Firewalls
Game Tweaks
Graphics
Input Device
Internet Tools
Mail Utilities
Memory
Messaging
Microsoft
Misc
Monitoring
Multimedia
Networking
Office Tools
ProcessManagement
Processor
Registry
Security
System Info
Toys
Video
Macintosh
Games
News Archive
- Off Base
- Way Off Base


· iDevice Manager 2.1.0.0
· DeviceLock 7.2 Build 48899
· SlimBoat 1.1.32
· CD Recovery Toolbox Free 2.0
· WebBrowserPassView 1.41
· MP3jam 1.1.0.1
· BDtoAVCHD 1.8.7
· SpeedUpMyPC 5.3.8.0
· Mozilla Firefox 22.0 Beta 2
· VideoMach 5.9.13

· New? Start Here
· Top Freeware Picks
· Malware Removal
· Compatibility Database
· Geektionary
· Geek Shopping
· Free Magazines
· Useful Links
· Top Freeware Picks
· Folding@Home
· About Us
· Copyright
· Privacy
· Terms Of Service
· Uninstall

There are currently 2796 user(s) online:
Google, Live Search, MSN, Yahoo

YouTube

FaceBook

Twitter

RSS / XML Feed

Pintrest



Follow @majorgeeks
· Google · Yahoo · MSN


1. K-Lite Codec Pack Update
2. IObit SmartDefrag
3. Malwarebytes Anti-Malware
4. Win7codecs
5. IObit Malware Fighter
6. JetClean
7. x64 Components
8. SpywareBlaster
9. Windows 8 Codecs
10. Advanced SystemCare Free 6.2.0.254 (0424)
More >>

The plane! The plane! Fantasy Island airplane used to smuggle drugs after show finished (Video)

What's The Best Browser to Protect You against Malware?

7-Data-Recovery 3 Day Giveaway - $29.95 Value! (2 Days Left)

Friday Photo Bombs!

Female fan who flipped off Noah in photo identified as Filomena Tobias

Majorgeeks updates website to new CMS and design – didn’t break EVERYTHING

First time setup and installation of an SSD drive

Friday Photo Bombs!

NASA dumping Windows for Linux

World Of Warcraft loses 1.3 million subscribers in 3 months





MajorGeeks.com » News » September 2012 » Hackers turn NetWire into trojan

Hackers turn NetWire into trojan


Posted on: 09/04/2012 04:52 PM [ Comments ]


Hackers are using remote maintenance tool NetWire, which can be used to monitor computers running Windows, Mac OS X, Linux and Solaris, as a trojan. Anti-virus software companies have responded by identifying the program as malware.

World Wired Labs describes its NetWire product as an extended remote maintenance application. The host application runs under Windows, various versions of Linux, Mac OS X and Solaris, while the "administrators’ workstation" client, from where a host can be controlled, runs under Windows only. The basic version costs $65, the Pro version, which can be extended using add-ons, is priced at $105. Prices for the Advanced version are available on request.

So far, so simple. But the line in the price list that says "undetected" hints that there's more to this than meets the eye – this amounts to a promise that the Windows version of NetWire Advanced will not be detected by anti-virus software. We find ourselves in a grey area.

The company calls NetWire a reliable tool for remote maintenance of business infrastructure, which is able to cross operating system barriers. The connection between the client and server is protected using AES encryption and is limited to a single TCP port. But the company also advertises "special remote access requirements", from monitoring to parental supervision. In this case, NetWire monitors all processes and even generates screenshots.

The program is advertised in a very different light on hacker forums. Here, the emphasis is on NetWire's ability to use reverse proxying to pass through any firewall or router, its ability to read browser passwords from any browser and the fact that its keylogger does not require administrator privileges. Extensions for sniffing out TrueCrypt passwords and logging instant messaging conversations are also in the pipeline. Seen from this angle, the remote maintenance tool starts to look a lot like a trojan toolkit.

The company behind the product is not at all happy about its product finding its way into some of the darker corners of the web. Each time a remote maintenance host is generated, NetWire displays a disclaimer which requires the user to confirm that he or she will not use NetWire to gain unauthorised access to another computer or to perform other illegal activities.

The hacker who had been promoting NetWire as a multi-platform trojan was quickly ejected from World Wired Labs' affiliate program. That has not, however, stopped other hackers from offering special "crypters", which claim to be able to hide NetWire executables from anti-virus programs, on private hacking forums.

So it's no great surprise that the remote maintenance program now finds itself in the firing line from anti-virus software companies. Dr. Web describes NetWire as a password stealer and lists it as "BackDoor.Wirenet.1". Other companies have dubbed it "TrojanSpy", "NetWired" and "NetWeird". According to VirusTotal, the Standard version of NetWire for Windows is currently detected by 16 anti-virus programs, the Linux version by 6, the Solaris version by 4, and the Mac version by 9 scan engines. Bizarrely, the Windows client is detected more frequently than the hosts, with 26 of 42 programs raising the alarm. The toolkit is therefore viewed as being more malicious than its compiled code.








Like it? Share it....




Comments
comments powered by Disqus

« U.S., Canadian zoos use apps to teach apes · Hackers turn NetWire into trojan · Google suspicious sign-in alert contains a trojan »

MajorGeeks.com » News » September 2012 » Hackers turn NetWire into trojan
© 2000-2013 MajorGeeks.com
Powered by Contentteller® Business Edition