Vulnerability Development mailing list archives

Re: All Advantage Spyware


From: Jonathan Rickman <jonathan () XCORPS NET>
Date: Wed, 13 Sep 2000 08:44:12 -0400

It seems that the page referred
to(http://home.cyberarmy.com/acecww/advert.txt) concerning the
AllAdvantage
advert.dll files may be a false report. Steve Gibson of Gibson Research
has
informed me (via one of the GRC NGs) that the text is a direct copy of
the
original FUD report about the Aureate 'spyware' dll that was included in
earlier versions of advertising supported software. If this is correct,
then
it could be a case of someone who was caught out by AA attempting to get
some sort of bad publicity happening for AA.

I spoke with the owner of that page earlier in the week. He admits that he
has done no research regarding his claims. He says he is just passing the
word along. After doing some searching, I believe this link is the
original source of the report, or at least a COMPLETE copy.

http://www.nls.net/netlink_has_learned_of_an_activi.htm

Once again, we have had no success in verifying these claims. We are
having trouble locating an earlier copy of the advert.dll file for
analysis. The file gets updated automatically, so it's a matter of finding
a PC that had it installed some time ago and hasn't connected to the net
since. The newer versions quite simply DO NOT send this kind of info
back to the aureate servers. If anyone can find a copy of this file that
is at least a year old, please send it to me.

--
Jonathan Rickman
X Corps Security
http://www.xcorps.net


-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: PGP 6.5.2

mQENAzm0QZQAAAEIAN3uNRQlWHMrHwKgTNzpYps6SLipfNvH+0uZi0TvxyXFHiiH
kivQYxlcPn/4Za4eyl5XZvP6lGQ3DXcCzT+9di75HqFtTiHeE9YScR0WEeBB1ywL
j8nKxFdGMCJ3a3khSafPvyTUQKGaEWQGnui+6UieWeBhDHdE/o21qNd0+6M49P73
0pVTdmdn1jPj1cU+vrqkNWMfNNNhLyPjrdPzoL6SoYzCs6p5YhLWaNOiet/91RhK
VpC8uy2cUIWNOAyAOtDJwF4GY+AIVP2WTLg6L/FByDH507HP4NvkbnwPAkDSTh7M
TlXvdoeNiaEUCYCgx8CFSCAg/pl819+gts810D8ABRG0JkpvbmF0aGFuIFJpY2tt
YW4gPGpvbmF0aGFuQHhjb3Jwcy5uZXQ+iQEVAwUQObRBlNffoLbPNdA/AQETwwf/
d4W131UXeWd1+hcCR1bkFJRx+08fNtHzbMzjqquA4IRPftt72M6RzDsRn1xpsdh+
RqP0oeZ0IfnByhXQ7x65JxRUaYW2mw8GNQOeTkJ2uNDg3SaFG2HGYxASohP2r8D6
Yh1WIfEgf3YDwoKyGAfJTgcfHZe85+hgg6R60KbGMAhWf5Tbb6IEpzdvBi/HoYHC
c1km8esjnMPDmR1aLjcRffaMmWGwXk/33oZRo3Q0SO/MvqWyo1kZnq2JIxX0MDAm
nm2p0cZtQc1sECkC1XyyyH8tgWhXwzYpucpsQ3IhWFrCuL7y4t/wREOgd4KaSxkN
OKraa8g7Nyh4s8rSHFvq5A==
=XYFV
-----END PGP PUBLIC KEY BLOCK-----


Current thread: