Results 1 to 4 of 4
  1. #1
    atenzor's Avatar
    Join Date
    Apr 2012
    Gender
    male
    Posts
    227
    Reputation
    10
    Thanks
    133

    keyloggers and online virus scanners bypass?

    Ok, so lately I was thinking how some hacker "could" potentially send a keylogger or
    other form of virus by submitting files through our forums.

    Obviously the rules say you need screenshots and two virus scans (jotti and virustotal).

    Leaving aside the screenshots, let's discuss about the scanners. Scanners do their job yes,
    but what tells us here or a moderator that the file submitted is the same as the one that was scanned?

    I could, for example, create a file called rotmg_client.zip (containing keylogger)
    and one called rotmg_client.zip (placed somewhere else on my computer, without a keylogger)
    and both files are named the same, and have the same filesize.

    I send the non-virus one to jotti/virustotal, obviously it reports everything is good and then I send the
    virus one through these forums and people think it's the same file.

    In other words, to sum it up, am I missing something here? is there a way for moderators
    to then manually scan again the submitted file? But if moderators scan them, why is there
    a need for jotti/virustotal? And if people have to scan them again then manually, well again,
    what is the point in jotti/virustotal? Because otherwise, people could do this and we have no clue.

    Thanks
    Last edited by atenzor; 07-16-2013 at 04:06 PM.

  2. #2
    Raple's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Posts
    10,149
    Reputation
    3856
    Thanks
    9,494
    Well, one thing is even though you said they'd be the same file size, they wouldn't be.
    Also, I'm pretty sure minions check through them, so if all the new folder contained was random files and then a keylogger, they would know.

  3. #3
    krazyshank's Avatar
    Join Date
    Jan 2012
    Gender
    male
    Location
    RealmStock
    Posts
    2,589
    Reputation
    467
    Thanks
    16,668
    My Mood
    Angelic
    Each file has a hash code. The hash code is kind of like a series of characters that represents the file. You could have two zip files, exactly the same size and name, but they would have different hash code's. The online scanners show the hash code of the file scanned, so when a minion comes along to approve it, they can make sure the hash of the file uploaded matches that of the file in the scan. However, I have made a key logger that captures every key c
    Pressed system wide and uploads it to me, which goes undetected by online scanners, so you're never fully safe! That's why Hux and nilly do their best to make zure files are safe, regardless of scans.

    Accepting PayPal - Bitcoin - Giftcards - Items:

    Find it here: MPGH Sales Thread

  4. The Following User Says Thank You to krazyshank For This Useful Post:

    marinepower (07-16-2013)

  5. #4
    atenzor's Avatar
    Join Date
    Apr 2012
    Gender
    male
    Posts
    227
    Reputation
    10
    Thanks
    133
    ah ok, thanks for info

Similar Threads

  1. Virus Scanner
    By Elmo in forum Spammers Corner
    Replies: 9
    Last Post: 07-11-2010, 01:23 PM
  2. How to fix combatguy's keylogger and virus!!!!!
    By zebramanz in forum Combat Arms Hacks & Cheats
    Replies: 8
    Last Post: 03-28-2009, 10:20 PM
  3. Can anyone send me a virus scanner?
    By turbo159 in forum WarRock - International Hacks
    Replies: 4
    Last Post: 06-06-2007, 06:10 AM
  4. help me pls and ill give u bypass
    By Mikeck901323 in forum WarRock - International Hacks
    Replies: 18
    Last Post: 05-27-2007, 08:29 AM
  5. Cabal Online - Virus?
    By Dave84311 in forum General Game Hacking
    Replies: 0
    Last Post: 02-19-2006, 07:54 PM