Intrusion Detection Systems mailing list archives

Re: Blackice trojaned and very buggy


From: robert_david_graham () yahoo com (Robert Graham)
Date: Thu, 9 Mar 2000 21:54:18 -0800 (PST)



--- jeff andrews <jandrews () watchmail com> wrote:
---
warning - Saw on other mailing lists and confirmed with blackice's Graham
that there are trojaned versions of blackice being passed out.  be careful
where you get your copy and check its authenticity.  

besides trojaned versions of blackice floating around, on
http://grc.com/su-firewalls.htm has a detailed review of BID, and it says
blackice is very buggy and breaks every other day.  not sure i'd rely on it
for ids.

Both of these are true, but the interpretation is wrong. 

BlackICE Defender is commonly pirated, probably because it appeals to the
hacker mentality. Lots of pirated software is trojaned (lots of free software
is, too). Doesn't take too much brains to realize that trojaned versions of
BlackICE will find its way onto pirate sites. For this reason, we have
Authenticode sign every copy. If you are going to pirate the software, at least
check the signature. 

Secondly, a couple months ago we shipped a buggy copy, and pulled it a couple
days later. Unfortunately, this has proven to be the version posted to many
websites. And there are LOTS of pirated copies of BlackICE Defender floating
around, and grc.com encourages them to vent. All customers with legitimate
copies should hit the "update" button an upgrade to the latest version.
Actually, our support engineers are sitting around twiddling their thumbs
because the lastest version is very, very solid.

In short, if you pirate software, you should expect buggy trojaned software.

Rob.

__________________________________________________
Do You Yahoo!?
Talk to your friends online with Yahoo! Messenger.
http://im.yahoo.com



Current thread: