[13526] in bugtraq

home help back first fref pref prev next nref lref last post

RFPoison is not a trojan, and the source will prove it

daemon@ATHENA.MIT.EDU (.rain.forest.puppy.)
Mon Jan 24 02:25:30 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.LNX.4.10.10001221533190.25496-100000@eight.wiretrip.net>
Date:         Sat, 22 Jan 2000 15:44:52 -0600
Reply-To: ".rain.forest.puppy." <rfp@WIRETRIP.NET>
From: ".rain.forest.puppy." <rfp@WIRETRIP.NET>
X-To:         bugtraq@securityfocus.com, vacuum@technotronic.com,
              win2ksecadvice@listserv.ntsecurity.net
To: BUGTRAQ@SECURITYFOCUS.COM

It seems an AVP trojan signature has been pegging RFPoison.exe (the one
available on my website, PacketStorm, etc) as Trojan.Win32.Aleph.  I can't
find any information on this trojan.  My personal feeling is that it's a
false alarm, but in any event, I wanted to make amends.

I placed a new .zip/.exe on my site that contains a freshly-compiled
version that does not report as being Trojan.Win32.Aleph.  As a bonus, I
also made the source code available, so you can compile yourself.  I also
modified the source (and therefore the new binary) to not reboot/crash
when you use it.

Thank you, you may now go about your business.
- rain.forest.puppy

home help back first fref pref prev next nref lref last post