startkeylogger
February 22, 2006 12:50 PM   Subscribe

Interesting (Norton?) Bug If you're using norton, you might just have fallen off the internet. Or something. Try this on your friends!
posted by winjer (33 comments total)
 
Startkeylogger


Hey, it worked, you're all gone!
posted by Outlawyr at 12:52 PM on February 22, 2006


Works with a command line switch too!

Startkeylogger -dios
posted by 327.ca at 12:56 PM on February 22, 2006


What happens if I say "startkeylogger" to Edward Norton?
posted by brain_drain at 12:56 PM on February 22, 2006


If you're still using Norton products in this day and age, you don't belong on the internet with all us grown-ups anyway.
posted by Effigy2000 at 12:57 PM on February 22, 2006


I'm guessing Norton AV now automatically assumes any incoming cleartext 'startkeylogger' on any of the standard IRC ports = commands issued to a rootkit on the local machine, and immediately closes the connection.

God bless IRC.
posted by Ryvar at 12:58 PM on February 22, 2006


Also, What. The. Fuck. Norton?

Even if I'm a scriptkiddie with a single-digit IQ I'm not exactly going to start calling my functions 'startkeylogger.'

Now excuse me while I search and replace 'stealyourdata' and 'fuckupwindows' in all my rootkits.
posted by Ryvar at 1:02 PM on February 22, 2006


My quantum computer does this even when it's turned off. So I'm never online anymore.

Neither are you.

Or you.
posted by WolfDaddy at 1:03 PM on February 22, 2006


WolfDaddy: But your cat is forever oscillating between the dead and the living.
posted by slater at 1:10 PM on February 22, 2006


Ryvar : "I'm guessing Norton AV now automatically assumes any incoming cleartext 'startkeylogger' on any of the standard IRC ports = commands issued to a rootkit on the local machine, and immediately closes the connection."

Maybe they're just being overzealous - once upon a time, when the animals could speak and any Internet start-up would be over-funded I wrote an article entitled "There is no such a thing as an email virus" (free translation, it was in Portuguese). It took Microsoft only one or two years to prove me wrong (the Internet being an amazing recording medium, strangers emailed me for the next six years to tell me I was wrong). Formatted text (Word files) are know to be exploitable. By the end of the last year we saw the proof of concept for an image file exploit. How long till someone finds an Windows loophole that allows an ASCII text file to be somehow executed.
posted by nkyad at 1:14 PM on February 22, 2006


Okay, Norton sucks. So what Windows antivirus software is GOOD? I just deinstalled NAV 2006 a few days ago because it's intrusive and awful, and I need a replacement stat.
posted by killdevil at 1:16 PM on February 22, 2006


AVG For The Win! God Bless Norton, I really need to start using IRC again.
posted by Hexidecimal at 1:25 PM on February 22, 2006


killdevil, try Avast!. Its good.
posted by BrodieShadeTree at 1:33 PM on February 22, 2006


killdevil: NOD32 is what I use.
posted by loquacious at 1:35 PM on February 22, 2006


killdevil: Another vote for AVG here - we use it in our computers at home (all 6 of them) and I never had a problem in the last three years.
posted by nkyad at 1:38 PM on February 22, 2006


killdevil: I've read that Zone Micro's product is good, and that Zonealarm's is as well. Can't vouch for that, except to say that there is really no way that they can be as bad as Norton is.
posted by dammitjim at 1:38 PM on February 22, 2006


Man's there's a lot of Schrodinger's Cats flying around this site today.
posted by Astro Zombie at 2:07 PM on February 22, 2006


killdevil: I don't use Antivirus. I have a firewall

lol
posted by cellphone at 2:16 PM on February 22, 2006


Personal firewalls like norton regularly decide that large swathes of the internet are dangerous viruses and just disable users access to them, they are fantastically awful and cause us no end of headaches at work with phone calls form irate customers who are paying several hundred £ a month who have just lost all access to our site.

It's surprising just how stupid their developers must be really.
posted by public at 2:21 PM on February 22, 2006


Also, What. The. Fuck. Norton?

Norton!
posted by hangashore at 2:22 PM on February 22, 2006


Back in the day, we used to use the Ping of Death to either knock friends offline or even cause a blue screen system crash, depending on their system.

Good times.
posted by LordSludge at 2:27 PM on February 22, 2006


damn. wonder what happens if I type /hax0rr00t?

Nothing? Okay, what about

/j0rpwn3dwind0se


Nothing? what ab
posted by stenseng at 2:34 PM on February 22, 2006


Is there any actual evidence of this? I see an unsubstantiated report and a couple of "OMG l33t hax" comments. I'll bet it's more like some guy types "startkeylogger" in IRC, a bunch of people freak out and unplug their connections, and voila: "Connection reset by peer."

OMG L33T HAX
posted by chrominance at 2:38 PM on February 22, 2006


Avast and AVG are both decent. Antivir is supposed to be okay too. Those are the three most popular free ones that give resident protection (meaning they run in the background and monitor everything). There are a couple other free alternatives like BitDefender Free Edition or ClamWin that just do on-demand scanning (you have to manually start a scan of your system or of a particular file).

Personally I use NOD32 like loquacious does. It's lightweight and fast, has great detection rates and heuristics that are pretty effective at catching malware that don't yet have signatures. Its UI isn't the most new user friendly, however.

My second choice would probably be Kaspersky which seems to have the most comprehensive signature library in the industry and rolls out updated ones incredibly fast. Its heuristics aren't quite as good as NOD32's but aren't bad either.
posted by Pryde at 2:52 PM on February 22, 2006


I doubt this works.
posted by Protocols of the Elders of Awesome at 2:52 PM on February 22, 2006


Keyloggers are for noobs. If I want to know what your doing I just hack NSA.
posted by srboisvert at 3:15 PM on February 22, 2006


Sounds like a trick to get folks kickbanned from their favorite IRC channels to me.
posted by Spatch at 3:30 PM on February 22, 2006


Very funny trick.

Amusing opinion on the need for anti-virus.
posted by jam_pony at 3:39 PM on February 22, 2006


Another vote for Nod32. It's inexpensive, lightweight, efficient and doesn't cause a noticeable performance hit on your machine.
posted by fleetmouse at 5:28 PM on February 22, 2006


Amusing opinion on the need for anti-virus.
posted by jam_pony at 3:39 PM PST on February 22 [!]


Interchangable with homeland security!
posted by Balisong at 6:42 PM on February 22, 2006


For what it's worth, this was on a network where you'd expect something like this to work:

21:33 * icosahedral looks.
21:33 < icosahedral> startkeylogger
21:33 -!- godlife42m [~godlife42@ [redacted].washdc.fios.verizon.net]
has quit [Read error: Connection reset by peer]
21:33 < icosahedral> !

So do I get to make a defcon presentation now?
posted by icosahedral at 7:11 PM on February 22, 2006


Ryvar : "Also, What. The. Fuck. Norton?"

Would you guys care to leave the Emperor of the United States and Protector of Mexico alone?
posted by nkyad at 7:38 PM on February 22, 2006


Almost every machine i cleaned last year (about 550) for spyware & viruses had Nortons installed. After i would clean out each machine i would sell them a copy of kasperskys or if they declined i would install Free AVG. The ones who declined kasperskys & AVG and kept Nortons would eventually call me again for virus & spyware removal.

You dont know how many times a customer would tell me "But i just paid $80 for this"
posted by Dreamghost at 12:32 AM on February 23, 2006


I had Norton and it allowed my son to download the Love Letter virus which disabled NAV right off the bat. It completely destroyed all my files & I had to reformat.

Now I use AVG and Firefox and it's been smooth sailing ever since.
posted by The Mermaid at 3:46 AM on February 23, 2006


« Older Who Rules as Evil Empire?   |   And they that use this world, as not abusing it:... Newer »


This thread has been archived and is closed to new comments