//flex table opened by JP

Click to See Complete Forum and Search --> : McAfee no longer scanning for NetBus


socalgal
05-24-2000, 06:28 PM
Received this from the TDS mailbot today. I don't use McAfee and haven't researched whether McAfee has this info on their site, but thought it may be informative for some of you.
--------------------------------------------

TDS - http://tds.diamondcs.com.au

In a surprise move, anti-virus vendor McAfee have decided to stop scanning
for NetBus, the trojan-turned-remote admin tool. Less than two years ago,
hundreds of thousands of NetBus trojan servers resided on infected
machines around the world. Today, newer versions of the software are being
sold as remote administration shareware.

While NetBus Pro lives up to it's claim of being a remote administration
tool, it still has the ability to run as a trojan. It has built-in
settings that allow the server owner to configure the server so that it is
completely invisible. Additional testing here at the DiamondCS lab and by
TLSecurity (http://www.tlsecurity.net) has proven how easy it is to modify
just a few bytes in the server to prevent the server from logging it's
activity, and various other things that the author put in that could
possible give the server away as being a trojan.

Regardless of whether a program is labelled a "trojan" or a "remote
administration tool", DiamondCS will always make detection available to
the user if there is any chance of the software being used in unauthorised
or trojaneous situations. You - the end user, has the right to know and
the right to choose what software is running on your system.

Related article: http://www.theregister.co.uk/000523-000018.html
Thomas C. Greene in Washington

Mntsnow
05-24-2000, 07:42 PM
Yep! It's amazing to me that Mcaffe is doing this. Rumor has it that Norton will no longer scan for it either. From what I have been able to find out about this is BECAUSE it has "turned into a "admin" tool" and people were messing it up because it was being found! At this point I would prefer to have them market 2 versions. One for the "consumer/home" and one for the "corporate" types. (I mean think about it...All they have to do is create the virus dif's With and Without that 1 call...Not to hard to do!) I personally do not see the need to have NETBUS on a system NOR do I want it! http://sysopt.earthweb.com/forum/frown.gif

Mntsnow

[This message has been edited by Mntsnow (edited 05-24-2000).]

socalgal
05-24-2000, 08:49 PM
Great... (not). I just did a quick check at Norton's site (I use NAV) and didn't find this info there - but then again that doesn't especially surprise. In any case, not good news and it doesn't make much sense, IMO. http://sysopt.earthweb.com/forum/frown.gif

Looks like this will give more support and business to the trojan detector/scanner business!