Security Basics mailing list archives

RE: Spy Software


From: "CHRIS GRABENSTEIN" <LFGRABC () LF VCCS EDU>
Date: Fri, 11 Apr 2003 12:24:06 -0400

I was just reading up on this the other day.  Spector sends a lot of info
back to a domain owned by spectorsoft using an undocumented protocol.  This
could easily include passwords, confidential documents, etc.  I don't have
the URL with me, but its easy enough to find.  Configure your firewall
appropriately or consider another product.  Personally, I wouldn't go near
it.

|-----Original Message-----
|From: Richard Pachito [mailto:alpyha () prodigy net] 
|Sent: Thursday, April 10, 2003 7:35 PM
|To: security-basics () securityfocus com
|Subject: Spy Software
|
|
|Hello, I administer workstations for a small company and the 
|boss recently
|asked me to isntall sofware called "Spector Pro".  It is a 
|'spy' utility
|that captures keystrokes, e-mails, instant-messages 
|(YIM,AIM,ICQ), and takes
|screen shots every X amount of time.
|
|What I was wondering is how exactly does this program hide 
|itself in the
|system.  I've called their techs a few times to end with a 
|repsonse of 'we
|are not authorized to disclose such information'.
|
|The recorded data is saved in a C:\winnt\system32\netext\ folder but no
|exec.  There is nothing unusual listed in Task Manager that 
|would lead me to
|the application running in the background.  Would anyone 
|happen to know how
|exactly this application works.  I believe a user would have 
|the right to
|know what is running on their system, and I'm kinda ticked off 
|that Spector
|Soft denys such information.
|
|
|-------------------------------------------------------------------
|Is SPAM over-loading your e-mail server, disk space or bandwidth?
|SurfControl E-Mail Filter is flexible, intelligent and policy-driven
|protection.
|http://www.securityfocus.com/SurfControl-security-basics2
|Download your free fully functional trial, complete with 
|30-days of free technical support.
|Stop SPAM before it stops you.
|-------------------------------------------------------------------
|
|

-------------------------------------------------------------------
Is SPAM over-loading your e-mail server, disk space or bandwidth?
SurfControl E-Mail Filter is flexible, intelligent and policy-driven
protection.
http://www.securityfocus.com/SurfControl-security-basics2
Download your free fully functional trial, complete with 30-days of free technical support.
Stop SPAM before it stops you.
-------------------------------------------------------------------


Current thread: