Ericthecmh Posted July 12, 2014 Posted July 12, 2014 This is amazing. Thanks for sharing it with us! 1
Booch Posted July 12, 2014 Posted July 12, 2014 (edited) People use .NET and C++, not Java but I guess it would be useful is people throw in malicious JAR files Edited July 12, 2014 by Booch
Intestine Posted July 12, 2014 Posted July 12, 2014 Stop quoting people for your post count. sorry for making you mad.
The Hero of Time Posted July 12, 2014 Posted July 12, 2014 sorry for making you mad. aand another post 2
winnerowns Posted July 12, 2014 Posted July 12, 2014 Stop quoting people for your post count. Yeah you should at least write 8 words like this guy
DMoneigh Posted July 12, 2014 Author Posted July 12, 2014 This is amazing. Thanks for sharing it with us! No problem, please send me some feedback. People use .NET and C++, not Java but I guess it would be useful is people throw in malicious JAR files People do use Java. You're using this bot aren't you? Millions of people play Minecraft, have played Runescape, and others games that use Java. Browsing the web can make you a victim of a JDB attack. 1
Scean4 Posted July 13, 2014 Posted July 13, 2014 If i had more time i would decompile it and take a look myself but im a bit busy atm.
DMoneigh Posted July 13, 2014 Author Posted July 13, 2014 If i had more time i would decompile it and take a look myself but im a bit busy atm. There is nothing to decompile? It is Open-Source on Github.
Booch Posted July 13, 2014 Posted July 13, 2014 No problem, please send me some feedback. People do use Java. You're using this bot aren't you? Millions of people play Minecraft, have played Runescape, and others games that use Java. Browsing the web can make you a victim of a JDB attack. This bot is the last thing I'll use, I just lurk on the programming section of the forum for a laugh every now and then. Also, if you think your program will detect FUD Java Drive-By attacks you are heavily mistaken, people pay thousands for advanced Cryptos. I won't bother addressing the rest of your post
DMoneigh Posted July 13, 2014 Author Posted July 13, 2014 (edited) This bot is the last thing I'll use, I just lurk on the programming section of the forum for a laugh every now and then. Also, if you think your program will detect FUD Java Drive-By attacks you are heavily mistaken, people pay thousands for advanced Cryptos. I won't bother addressing the rest of your post Please proceed to create a malicious Java program that JScanner can't detect. Unobfuscated Results Obfuscated Results Edited July 13, 2014 by DMoneigh
Booch Posted July 15, 2014 Posted July 15, 2014 Please proceed to create a malicious Java program that JScanner can't detect. Unobfuscated Results Obfuscated Results "It allows users to scan class files, Jar files, and Applets for malicious code." Which is why I said this won't work on FUD JDB attacks, cause the user won't be able to deliberately scan the file.
DMoneigh Posted July 19, 2014 Author Posted July 19, 2014 Any other verification this works? If it helps, I have added a link to my yearly documented log on JScanner.