Re: NeWT Security Scanner



On Tue, 05 Jul 2005 20:30:36 GMT, "DanR" <dhr22@xxxxxxxxxxxxxx> wrote:

>I downloaded the NeWT program a couple of weeks ago from
>www.tenablesecurity.com/products/newt.shtml
>Had to fill out form, wait for email with access code to plugins, then get
>program. After installing the program it asked if I wanted to do an update (I
>think plug-in update) which I did. That is when the 8,000 files came streaming
>in.

Oops. I got interrupted and forgot to register. After I registered,
I got 8210 plugins. When I scanned the ..\plugin directory with AVG
Free 7.0.323, it took only about 2 minutes on my PIII-933 with 256MB
running W2KSP4. Methinks NAV is having a problem.

>I did some testing today. The file plugin.tar.ge (size 3,242KB) in the plugins
>folder takes forever for my NAV to scan.

It's ..\plugin\plugin.tar.gz and AVG Free takes about 2 seconds to
scan it. Probably because it's not scanning the files inside the
Gzipped archive. It's set to "scan inside archives" but apparently is
not scanning this one. Oh-oh.

So, I un-gzipped it to a 25.6MByte plugin.tar file and tried again.
Same thing. Takes about 2 seconds and claims it only scanned one
file. Aparently, Free AVG doesn't scan inside tar or tar.gz archives.

So, I created something that I knew it would scan. I took the 8210
files and conglomerated them into a 9.4MB ZIP file. AVG did scan the
8000 files inside the ZIP compressed archive in 1 min 30 seconds.
Methinks your NAV is busted. Any chance you have "Norton's
inoculation" feature turned on? That's where they run an MD5sum on
every file to see if it has been modified. That takes literally
forever inside compressed archives.

I'm not going to say anything about a company the delivers a product
that stores both the unarchived files, as well as the compressed
archives. I guess diskspace and bloat are not an issue.

>Apparently this is a compressed zip
>like file. (many files within one file) I gave up after half hour or so. NAV
>quickly scanned 6,500 of the files then slowly got to 6,800 but I aborted. (I
>have NAV set to scan within compressed files) I copied this file to another
>computer with AVG Free and it scanned it in a second. But only saw it as one
>file.

Yep. Exactly as I described above. Not good either way.

When I scan with Free AVG just the ..\plugin\scripts\ directory, it
only takes about 2 minutes.

>Now here is something even more strange. There is ONE file in the scripts folder
>that seems to literally take forever for NAV to scan. It is not large and as of
>now (still running on another computer) NAV has been scanning it for almost 4
>hours. It has slowly scanned 188 files within that file. There is constant disk
>activity. I'm afraid to even mention the name here on this public group because
>it might be a denial of service type file. I have more details on this file and
>can post them here if you think that is OK or email to directly at the address
>at the bottom of your posts.

Sure. Feel free to email. This is interesting. However, don't
expect an instant reply. I just spent part of the day on an 80ft
tower and really feel the traditional aches and pains.


--
Jeff Liebermann jeffl@xxxxxxxxxxxxxxxxxxxxxx
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 AE6KS 831-336-2558
.



Relevant Pages

  • Re: Ask EU - Norton AV 2006
    ... With the second version, it caused all kinds of little niggles, but I persevered for the period of the subscription. ... Uninstalling NAV can also be a painful process. ... I use AVG, which has caught more potential problems than NAV. ... Zone Alarm as a firewall. ...
    (uk.media.radio.archers)
  • Re: ipsf HIGHLIGHT option
    ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ... Search the archives at http://bama.ua.edu/archives/ibm-main.html ... No virus found in this incoming message. ... Checked by AVG. ...
    (bit.listserv.ibm-main)
  • Re: Is XNews a Vector for Malware?
    ... Does anybody know if XNews provides a portal for viruses to sneak ... I run AVG Free resident, and also manually scan the entire ... I'd used NAV for many years before this last ...
    (comp.security.firewalls)
  • Re: Virus protection
    ... I also used Norton AntiVirus for some time - just short of a year, ... till the dealer who installed a second hard drive suggested I try AVG ... I found AVG's performance really excellent, and I gave NAV ... The cost for the paid version is currently $33.30 US - for a two-year ...
    (microsoft.public.windowsxp.newusers)
  • Re: NAV
    ... > manually),I do updates on a regular basis for both NAV ... I even did a update and scan yesterday and NAV ... NAV is an anti virus program, ... Unless you actually got an AVG notice that it cleaned a viral infection, ...
    (microsoft.public.security.virus)