BleepingComputer.com: Hijack This Logs Question

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Hijack This Logs Question

#1 User is offline   tufek22 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 17
  • Joined: 14-September 08

Posted 30 September 2008 - 11:59 AM

This is mostly directed at all the nice people helping everyone with their infection.

I was wondering if you use any parsing tools to figure out whats going on?

I have been looking over some of the tutorials because I would like to learn how some of this software works, and would be intrested in creating some kind of parser if it already doesnt exist.

Would appreciate any input on the type of functionality desired or possible modification to existing scripts.

I am guessing there is something like this already out there but it would be nice to help since I really appreciate everything you do here.

#2 User is offline   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,603
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 01 October 2008 - 07:40 AM

For the most part, we do not believe in parsers as they become prone to false positives. There are too many malware that impersonate valid names, or replace legitimate files, that parsers just become too dangerous.

That means that we parse each line one by one.

#3 User is offline   tufek22 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 17
  • Joined: 14-September 08

Posted 01 October 2008 - 06:55 PM

Good point,

Thanks for the answer.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users