<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Fuck Spyware!</title>
	<atom:link href="http://bruner.net/2004/01/07/fuck-spyware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bruner.net/2004/01/07/fuck-spyware/</link>
	<description>All Bruner, All the Time*</description>
	<pubDate>Thu, 08 Jan 2009 22:05:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: True Orient</title>
		<link>http://www.bruner.net/2004/01/07/fuck-spyware/#comment-81</link>
		<dc:creator>True Orient</dc:creator>
		<pubDate>Tue, 07 Dec 2004 20:33:38 +0000</pubDate>
		<guid isPermaLink="false">http://bruner.docgonzales.com/?p=929#comment-81</guid>
		<description>It gets worse when self proclaimed good guys employ sleazeware methods!



Read on...



DiamondCS is a reputable software firm that developed one of the best Anti-tojan applications I have seen, TDS-3. Unfortunately, DCS employs a hardcode technique that redirects the user to its site with numeric IP 64.91.255.87 upon pressing the F5 function key. Of course there is nothing wrong with this process. This fact could have remained unnoticed had it not been for a spate of really nasty IGN/CWS infections that showed the DCS redirects along with the nasties in hijacked Host files and shown below:

O1 - Hosts: 69.20.16.183 auto.search.msn.com

O1 - Hosts: 69.20.16.183 search.netscape.com

O1 - Hosts: 69.20.16.183 ieautosearch

O1 - Hosts: 69.20.16.183 ieautosearch

O1 - Hosts: 69.20.16.183 ieautosearch

O1 - Hosts: 69.20.16.183 ieautosearch

O1 - Hosts: 64.91.255.87 www.dcsresearch.com

O1 - Hosts: 69.20.16.183 ieautosearch

O1 - Hosts: 69.20.16.183 ieautosearch



A quick google search of "O1 - Hosts: 64.91.255.87 www.dcsresearch.com" will provide at least 1,500 links (Yup! that many!). It should be noted that an HJT 01 entry will only appear if a Hostfile hijack is involved. Redirecting to the local host to will not appear in the HJT log. When asked about this, representatives of DCS at Wilders Security Forum replied that this is perfectly normal since it simply redirects from an alleged "bad site" to the legitimate DCS IP.



If such were the intention, a simple redirect to the local host would have sufficed as this blocking technique is acceptable. However, redirecting to a preferred website is in any laguage, a hijack. This type of redirect is the method used by hijackers with the same objectives: redirecting to the chosen website. DCS

cannot claim that since they are reputable, a redirect to their site is acceptable. No one has nor can give them that privilege/status. A hijack is a hijack is a hijack.... The method is absolutely wrong!

Now comes an interesting scenario.



Quote:

"It?s becoming such a sizeable problem in the US that the Government voted unanimously in Spring 2004 to approve the first-ever anti-spyware bill. The Securely Protect Yourself Against Cyber Trespass (Spy Act), approved by the US House of Representatives, would levy fines up to $3 million for those who illegally collect personal information, change a browser's default home page or bookmarks, log keystrokes, or steal identities"

Quoted from http://www.net-security.org/article.php?id=746



Do you realize that if I invested in TDS3, bookmarked www.dcsresearch.com or set my homepage to www.dcsresearch.com, the chances are I will be redirected to DiamondCS? This can be documented and I can then sue DCS for illegally redirecting my browser, right? And all because DiamondCS has chosen to adopt a Trojan method instead of a Hostfile block or Help update? Think about it.



Too, what are the chances of a crazy picking up this post and doing exactly the above? This is a possibility they brought upon themselves for insisting that what they were doing was simply protecting their interests. They chose the

expedient/easier route now they are susceptible to legal issues.... Sooner or later, this will happen....



Your thoughts?</description>
		<content:encoded><![CDATA[<p>It gets worse when self proclaimed good guys employ sleazeware methods!</p>
<p>Read on&#8230;</p>
<p>DiamondCS is a reputable software firm that developed one of the best Anti-tojan applications I have seen, TDS-3. Unfortunately, DCS employs a hardcode technique that redirects the user to its site with numeric IP 64.91.255.87 upon pressing the F5 function key. Of course there is nothing wrong with this process. This fact could have remained unnoticed had it not been for a spate of really nasty IGN/CWS infections that showed the DCS redirects along with the nasties in hijacked Host files and shown below:</p>
<p>O1 - Hosts: 69.20.16.183 auto.search.msn.com</p>
<p>O1 - Hosts: 69.20.16.183 search.netscape.com</p>
<p>O1 - Hosts: 69.20.16.183 ieautosearch</p>
<p>O1 - Hosts: 69.20.16.183 ieautosearch</p>
<p>O1 - Hosts: 69.20.16.183 ieautosearch</p>
<p>O1 - Hosts: 69.20.16.183 ieautosearch</p>
<p>O1 - Hosts: 64.91.255.87 <a href="http://www.dcsresearch.com" rel="nofollow">http://www.dcsresearch.com</a></p>
<p>O1 - Hosts: 69.20.16.183 ieautosearch</p>
<p>O1 - Hosts: 69.20.16.183 ieautosearch</p>
<p>A quick google search of &#8220;O1 - Hosts: 64.91.255.87 <a href="http://www.dcsresearch.com" rel="nofollow">http://www.dcsresearch.com</a>&#8221; will provide at least 1,500 links (Yup! that many!). It should be noted that an HJT 01 entry will only appear if a Hostfile hijack is involved. Redirecting to the local host to will not appear in the HJT log. When asked about this, representatives of DCS at Wilders Security Forum replied that this is perfectly normal since it simply redirects from an alleged &#8220;bad site&#8221; to the legitimate DCS IP.</p>
<p>If such were the intention, a simple redirect to the local host would have sufficed as this blocking technique is acceptable. However, redirecting to a preferred website is in any laguage, a hijack. This type of redirect is the method used by hijackers with the same objectives: redirecting to the chosen website. DCS</p>
<p>cannot claim that since they are reputable, a redirect to their site is acceptable. No one has nor can give them that privilege/status. A hijack is a hijack is a hijack&#8230;. The method is absolutely wrong!</p>
<p>Now comes an interesting scenario.</p>
<p>Quote:</p>
<p>&#8220;It?s becoming such a sizeable problem in the US that the Government voted unanimously in Spring 2004 to approve the first-ever anti-spyware bill. The Securely Protect Yourself Against Cyber Trespass (Spy Act), approved by the US House of Representatives, would levy fines up to $3 million for those who illegally collect personal information, change a browser&#8217;s default home page or bookmarks, log keystrokes, or steal identities&#8221;</p>
<p>Quoted from <a href="http://www.net-security.org/article.php?id=746" rel="nofollow">http://www.net-security.org/article.php?id=746</a></p>
<p>Do you realize that if I invested in TDS3, bookmarked <a href="http://www.dcsresearch.com" rel="nofollow">http://www.dcsresearch.com</a> or set my homepage to <a href="http://www.dcsresearch.com" rel="nofollow">http://www.dcsresearch.com</a>, the chances are I will be redirected to DiamondCS? This can be documented and I can then sue DCS for illegally redirecting my browser, right? And all because DiamondCS has chosen to adopt a Trojan method instead of a Hostfile block or Help update? Think about it.</p>
<p>Too, what are the chances of a crazy picking up this post and doing exactly the above? This is a possibility they brought upon themselves for insisting that what they were doing was simply protecting their interests. They chose the</p>
<p>expedient/easier route now they are susceptible to legal issues&#8230;. Sooner or later, this will happen&#8230;.</p>
<p>Your thoughts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HEIDI</title>
		<link>http://www.bruner.net/2004/01/07/fuck-spyware/#comment-80</link>
		<dc:creator>HEIDI</dc:creator>
		<pubDate>Fri, 10 Sep 2004 14:57:38 +0000</pubDate>
		<guid isPermaLink="false">http://bruner.docgonzales.com/?p=929#comment-80</guid>
		<description>I AM FEELING THAT THE WRITERS OF THIS FUCKING INVASION OF PRIVASY ARE WANKERS. LET THEM WANK AND WE WILL FIND THEM.</description>
		<content:encoded><![CDATA[<p>I AM FEELING THAT THE WRITERS OF THIS FUCKING INVASION OF PRIVASY ARE WANKERS. LET THEM WANK AND WE WILL FIND THEM.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jimbo</title>
		<link>http://www.bruner.net/2004/01/07/fuck-spyware/#comment-79</link>
		<dc:creator>jimbo</dc:creator>
		<pubDate>Fri, 10 Sep 2004 10:21:31 +0000</pubDate>
		<guid isPermaLink="false">http://bruner.docgonzales.com/?p=929#comment-79</guid>
		<description>spyware is a piece of SHIT!</description>
		<content:encoded><![CDATA[<p>spyware is a piece of SHIT!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Henly</title>
		<link>http://www.bruner.net/2004/01/07/fuck-spyware/#comment-78</link>
		<dc:creator>Mark Henly</dc:creator>
		<pubDate>Fri, 11 Jun 2004 01:02:06 +0000</pubDate>
		<guid isPermaLink="false">http://bruner.docgonzales.com/?p=929#comment-78</guid>
		<description>Great info !! If you ever want to chat about spyware come see me at http://www.spywareboard.com</description>
		<content:encoded><![CDATA[<p>Great info !! If you ever want to chat about spyware come see me at <a href="http://www.spywareboard.com" rel="nofollow">http://www.spywareboard.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TAKETHIS</title>
		<link>http://www.bruner.net/2004/01/07/fuck-spyware/#comment-77</link>
		<dc:creator>TAKETHIS</dc:creator>
		<pubDate>Thu, 03 Jun 2004 02:39:05 +0000</pubDate>
		<guid isPermaLink="false">http://bruner.docgonzales.com/?p=929#comment-77</guid>
		<description>yah fuck them!</description>
		<content:encoded><![CDATA[<p>yah fuck them!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Deon</title>
		<link>http://www.bruner.net/2004/01/07/fuck-spyware/#comment-76</link>
		<dc:creator>Deon</dc:creator>
		<pubDate>Wed, 02 Jun 2004 07:28:07 +0000</pubDate>
		<guid isPermaLink="false">http://bruner.docgonzales.com/?p=929#comment-76</guid>
		<description>MotherFucker spyware, shit!!! absolutlety fucking basterd man!!! fucking bullsit!!!I'm gonna fucking kill all of fucking spywares!!! FFFFFFFFFFFFFFFFUUUUUUUUUCCCCCCCKKKKK!!!!</description>
		<content:encoded><![CDATA[<p>MotherFucker spyware, shit!!! absolutlety fucking basterd man!!! fucking bullsit!!!I&#8217;m gonna fucking kill all of fucking spywares!!! FFFFFFFFFFFFFFFFUUUUUUUUUCCCCCCCKKKKK!!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.713 seconds -->
