Go Back   AnandTech Forums > Software > Security

Forums
· Hardware and Technology
· CPUs and Overclocking
· Motherboards
· Video Cards and Graphics
· Memory and Storage
· Power Supplies
· Cases & Cooling
· SFF, Notebooks, Pre-Built/Barebones PCs
· Networking
· Peripherals
· General Hardware
· Highly Technical
· Computer Help
· Home Theater PCs
· Consumer Electronics
· Digital and Video Cameras
· Mobile Devices & Gadgets
· Audio/Video & Home Theater
· Software
· Software for Windows
· All Things Apple
· *nix Software
· Operating Systems
· Programming
· PC Gaming
· Console Gaming
· Distributed Computing
· Security
· Social
· Off Topic
· Politics and News
· Discussion Club
· Love and Relationships
· The Garage
· Health and Fitness
· Merchandise and Shopping
· For Sale/Trade
· Hot Deals
· Free Stuff
· Contests and Sweepstakes
· Black Friday 2012
· Forum Issues
· Technical Forum Issues
· Personal Forum Issues
· Suggestion Box
· Moderator Resources
· Moderator Discussions
   

Reply
 
Thread Tools
Old 08-27-2012, 02:29 AM   #1
toaries
Junior Member
 
Join Date: Aug 2012
Posts: 5
Default Help Needed Regarding:TrendMicro Antivirus considering java App as ahigly risk thread

Hello

I have a java application which sniff the network traffic, I am using jpcap and winpcap in my application. Application runs fine with AVG antivirus.but when i did deploy my java application at customer environment where customer has Tren Micro Antivirus.
At that customer end trend micro is repotting my Java Application as high risk thread and also consider as dialup app which is trying to accessing the other pcs. But in actual it really not like that its only sniff the traffic which comes on that particular pc’s LAN Card.
What could be the possible reason for that as with AVG antivirus it working fine but with Treand Micro Antivirus it considering the highly risk thread

Plz let me know its possible reason and solution


Thanks

Regards
Mudasser
toaries is offline   Reply With Quote
Old 08-28-2012, 02:21 AM   #2
jjsbasmt
Senior Member
 
jjsbasmt's Avatar
 
Join Date: Jan 2005
Location: SW PA
Posts: 356
Default

I think the several AV Programs out there would consider "packet sniffers" a threat by nature of what they do and how they operate. It is understandable how easy one could misuse "sniffers" so in order to be cautious I've noticed that many AV programs warn about these even if you just download them without deploying.
__________________
Q9550 on Asus P5Q Turbo, 8GB OCZ Gold PC8500, PC P&C Silencer 500, Sapphire Radeon HD5670, Caviar Blk 1 TB, SONY SATA Lightscribe, Antec Front Panel Internal SATA Drive Bay w/eSATA, 12 in-one Media Card Reader, Dell 22" HDMI, Win 7 Pro 64, in CoolerMaster Centurion, Protected by APC XS 1000
jjsbasmt is offline   Reply With Quote
Old 08-29-2012, 10:52 PM   #3
foghorn67
Lifer
 
foghorn67's Avatar
 
Join Date: Jan 2006
Posts: 10,209
Default

There are several articles going around about Java in the past day or two. Everyone seems to be saying to disable it right away.
Mozilla Firefox as of today, has Java disabled as default.
http://www.slate.com/blogs/future_te...ight_now_.html
__________________
AT Garage -Wrong Wheel Drive V6 club member.
foghorn67 is online now   Reply With Quote
Old 08-31-2012, 09:33 PM   #4
MrColin
Golden Member
 
MrColin's Avatar
 
Join Date: May 2003
Posts: 1,925
Default

Signature based antivirus apps will probably flag the packet sniffer binary unless you:
A) pad the binary in a hex editor to defeat the signature recognition (works for viruses too!)
or
B) ad an exception to the antivirus file checking rules.
__________________
"Your heart is in the right place. But still, you are a very disturbed individual."

-Xionide
MrColin is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 01:17 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.