Re: WinPCap

From: George M. Garner Jr. (gmgarner_at_newsgroup.nospam)
Date: 12/16/04


Date: Thu, 16 Dec 2004 01:04:33 -0500

gmgrad,

If I suddenly found msword.exe on my computer and didn't install it I would
be just as worried. The software is riskware and you need to find out how
it got there.

WinPCap is legitimate software that adds "the ability to capture and send
raw data from a network card, with the possibility to filter and store in a
buffer the captured packets." http://winpcap.polito.it/. It is widely used
in the information security community. The same features may make it
attractive for many other purposes, some of which are legitimate and some of
which are not. Not knowing what software you have installed lately I cannot
say for what purpose it is being used on your machine. WinPcap comes with
an uninstall applet. Trying uninstalling it from the Control Panel->Add and
Remove Programs and see what breaks. If there is no option to remove it in
Add and Remove Programs (not a good sign) you can change the file access
permissions on it to NoAccess-Everyone. This will effectively prevent
anyone from accessing it. (I often find that adware programs are
self-healing and will simply reinstall a component if you delete it.)

With the introduction of SP2, Microsoft effectively disabled raw ip in
Windows XP. The change affects many legitimate software vendors as well as
certain malware. WinPcap represents one possible workaround, albeit not a
particularly stealthy one.

Regards,

George.



Relevant Pages

  • Re: Secure.dcom.exe
    ... I should also explain that in the context of the question asked, that installing a ethereal + winpcap, maybe a reboot etc.. ... > To: Lee Evans ... > quickly install on the host locally to decode the ... The contents of this message are to be used for the intended purpose only and are to be kept confidential at all times. ...
    (Incidents)
  • Re: Add/Remove Programs failure
    ... > While logged on as Administrator and trying to Remove a WinPcap program, ... > similarly-named files exist for other applications. ... > I was able to successfully install WinPcap 3.1 and the application that ...
    (microsoft.public.win2000.general)
  • Re: CD Keys???
    ... however, keep in mind ... Database Developer ... Is there anyone who might have a suggestion, I've got legitimate software, ...
    (microsoft.public.windowsxp.general)
  • Re: NGSECs penetration test sniffer
    ... >In particular it needs WinPcap to be installed. ... you really need to be able to uninstall WinPcap once the ... > Or is it just that I haven't figured out how install and uninstall ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: winpcap issues with using multiple products at the same time
    ... dont install it 3 times, install ONE time, and all those programs work from ... install Snort -skip the section of any instructions that say install winpcap ...
    (Security-Basics)