Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow X-scan v3.3
EH-Net
February 07, 2012, 12:19:32 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: X-scan v3.3  (Read 7073 times)
0 Members and 1 Guest are viewing this topic.
CJS
Newbie
*
Offline Offline

Posts: 8


View Profile
« on: February 22, 2008, 03:08:05 PM »

I noticed that X-scan 3.3 was recommended in a thread in these forums (SlimJim100 gave a video of it), so I downloaded it from xfocus.org to try it out.

BUT, my AVG anti-virus claimed it has a worm, specifically the file "common_pass.dic" in the /dat directory. And of course AVG labeled about 21 other different files as "potentially dangerous" but that's not surprising given what the program is supposed to do. Also, I noticed that Mcafee Siteadvisor found numerous "red" downloads from the xfocus website.

I uploaded the common_pass.dic file to virustotal.com to get more opinions, and most of the virus programs didn't complain about it.

I guess I'm just looking for a little more reassurance at this point.  Cheesy
Is this program still considered safe to use?
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1166


View Profile WWW
« Reply #1 on: February 22, 2008, 04:23:42 PM »

well... did you actually read what was in the file?
Logged

...tests i took go here...

http://carnal0wnage.attackresearch.com/
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #2 on: February 25, 2008, 06:22:52 AM »

but the download page is not opening I think...can any1 give proper link of downloading xscan
Logged
CJS
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #3 on: February 25, 2008, 08:51:19 AM »

well... did you actually read what was in the file?

Looks like a data/text file obviously, so why would AVG flag it as a worm? I didn't think text files under any circumstance could be harmful, unless some other program somehow "used" the contents to aid that program in some malicious behavior. Any comments about this?
Logged
dean
Full Member
***
Offline Offline

Posts: 135


View Profile
« Reply #4 on: February 25, 2008, 09:33:13 AM »

Antivirus/antispyware/antimalware applications do not just scan a single file and deem it to be safe. If the file is part of a larger package and it is scanned the application will make the determination that you may be infected/compromised based on that file and the package it's part of.

For example: SSH brute force scripts may download and use a standard dictionary file and if this is discovered by your AV it will alert you to that fact.

Antivirus apps don't just scan for viruses. They scan for all forms of potentially malicious software. Eg: keyloggers, BHOs, etc.... I always wonder why Symantec flags netcat as do many other AV apps.

If you are intending to run tools such as that you might want to consider disabling or removing whatever host based firewalls, IDS/IPS, AV, antispyware apps you have running. You are going to have to whitelist/exclude so many files anyway that it's going to render the tools pretty ineffective.

Ideally, you would want your regular workstation you use for daily tasks to not to be used for testing tools, reversing malware, pentesting, etc....

dean
Logged

<script>alert('%52%54%46%4D')</script>
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #5 on: February 27, 2008, 07:21:50 AM »

people please help me downloading x scan,i am unable to download it,can you please tell me the procedure...
Logged
sgt_mjc
Sr. Member
****
Offline Offline

Posts: 294


View Profile
« Reply #6 on: February 27, 2008, 07:36:53 AM »

Use your tools in a VM. This gives your host protection even without an AV like dean mentioned. Good luck.
Logged

Mike Conway
CISSP
CompTia Security +
C|EH
CJS
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #7 on: February 27, 2008, 07:37:29 AM »

people please help me downloading x scan,i am unable to download it,can you please tell me the procedure...
Not sure why you are having a problem, but here is a direct link to the program:
http://xfocus.org/programs/200507/X-Scan-v3.3-en.rar
Hope this helps.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.231 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.