E-Detective Spy Tool Used By Police and Governments Has Major Security Holes
DavidGilbert99 writes: A controversial intercept tool called E-Detective from Taiwanese based company Decision Group has a major security hole which could allow a hacker to remotely execute code and read all the data captured by the software. Considering over 100 law enforcement agencies and governments around the world use E-Detective, this could be a big problem. According to the International Business Times story: "E-Detective works by 'sniffing the network' it is monitoring and captures data packets before sending them to be reassembled and decoded. Unlike other products E-Detective promises to 'reconstruct the data to its original format' for the end users so that it will be seen the same way that it was seen on the network. E-Detective also advertises as a network forensic tool for private enterprises to "protect sensitive data from data leakage".
"E-Detective is capable of decoding, reassembling, and reconstructing various Internet applications and services such as "Email (POP3, IMAP and SMTP), Webmail (Yahoo Mail, Windows Live Hotmail, Gmail etc.), Instant Messaging (Yahoo, MSN, ICQ, QQ, Google Talk, IRC, UT Chat Room, Skype), File Transfer (FTP, P2P), Online Games, Telnet, HTTP (Link, Content, Reconstruct, Upload and Download, Video Streaming), VOIP (optional module) etc." ref
I don't understand, I thought all https traffic was encrypted and secure from eavesdropping?
Their kind wants to turn the entire world into a police state.
You secure a network by locking down its capabilities to what you need to do and NOTHING else. Hacking then becomes basically impossible... right there.
I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
So who is piggybacking on whom ?
Cops on crooks ?
Crooks on Cops ?
Will there be a difference ?
Both will leave us broke with a bad reputation on file.
This is my opinion based on what little I know and understand of the rumors and lies Thanks, Randal
Hackers.
"Persistence is annoying success." - ghee22 11:28:1999 - 10:53:PM
Of course, I couldn't want to be labeled a racist, so I would never prohibit an organization from buying a security tool built by the Chinese. Lets all run our secure data through E-Defective!
I'm an American. I love this country and the freedoms that we used to have.
Visit haktuts.com!
This just demonstrates that states attacking computers and placing backdoors does massively more damage than could ever be compensated by any possible benefits. Hence it is one of the most stupid things to do and only desired and done bu people that really have no clue or do not care how much damage they do. Usually the latter type of person is called "evil", and with good justification.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
But only them, because for anybody else exploiting holes is just too hard. Obviously.
Hello, Thanks for your valuable post. Hope you will give us the same valuable post in the future. I have found another good website. you can visit this website to know more. I have got a lot of knowledge from this website. Click Hare to go website. Thank you.
The Chinese have this outsourcing thing down from multiple angles.
It's UTTER SHIT. no features, no details. no statistics.no advanced filtering.
You can't even filter a specific port/protocol, the only thing it does is reading yahoo chat
SSL decryption is non-existent
Anything you think should be there is not
I have no idea why anyone would use/hack it, tcpdump is like 20 times stronger, It's not even comparable with wireshark.
Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion. -- Spazmania (174582)
So, basically a badly written tool, used clueless police who don't understand the technology, so they can spy on us, but which can be accessed by people who figure out it's easier to spy on the clueless idiots who use a badly written tool because they've already captured everything.
Go police, first you insist we have weak security so you incompetent morons can spy on us, and then you buy crap software with huge security holes so everybody else can spy on us.
This is why we can't have nice things.
And this is exactly why back doors in crypto and security to allow the fucking police to spy on us will never work.
Because the spying tools are additional security risks.
Lost at C:>. Found at C.
Does anyone have any banner or other information for this product that could be searched in Shodan? :)
By the way, if you haven't looked at the exploit on GitHub, it's ridiculously simple. The script on the server is there for file retrieval; pass it the path and filename to the file you want, encoded in base64, and it sends you the file.
Makes me want to ask the vendor, "Hi...I'm the idea of using service accounts with minimized rights for listening network services, Have we met?"
For your security, this post has been encrypted with ROT-13, twice.