Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

EduSweep Powerful script analysis and detection for your network. Keep the nasties at bay for the low, low cost of nothing!

Go Back   EduGeek.net Forums > EduGeek Projects > Projects: > EduSweep
Reply
 
LinkBack Thread Tools Search Thread Language
Sponsored Links
Old 28-10-2008, 11:40 AM   #1
 
bizzel's Avatar
 
Join Date: Jul 2007
Location: Durham
Posts: 439
uk uk durham city
Thanks: 53
Thanked 78 Times in 26 Posts
Rep Power: 16 bizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nicebizzel is just really nice
Send a message via Skype™ to bizzel
Exclamation EduSweep 2: Sneak Peek 3

It’s nearly beta time, folks! Now that I have a little time free to work on my projects again there’s some good work going on behind the scenes and another component gets ticked off as finished. Today that’s the File Inspector - a new tool in this release.



I’ve lost count of the number of files I’ve come across and thought “What on earth is that doing there? Where did it come from!?”. All too often, harmless-looking files are renamed copies of dangerous scripts or programs. For example, what if My Coursework.doc is actually a copy of lophtcrack.exe or even a virus?

Often, you can do a little detective work of your own but the file inspector makes light work of it. With a single click you can access owner information, view created, modified and last access dates and, most importantly, whether the file is what it seems to be. During development I’ve worked with Marco Pontello to incorporate his TrID file analyser into EduSweep. Together with my own EduEngine 2, the file inspector can tell you if everything isn’t as it seems.

The inspector will show you, among other things:

* The extension that the file currently has - e.g .docx
* The extension that EduEngine and TrID think that it should really have - e.g. .exe
* The MIME type, as detected by Internet Explorer (application/x-zip-compressed)
* The most likely file format - e.g. Microsoft Word Open XML Document

When these have been detected, analysis notes will be presented which highlight any discrepancies and give the file an overall threat rating, allowing you to take appropriate action. Soon this technology will be integrated further, allowing the main engine to detect suspicious files for a truly intelligent scanner.
  Reply With Quote
Reply

Register now for FREE and post messages!


Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Birthday:      
Image Verification
  I agree to forum rules 

Similar Threads
Thread Thread Starter Forum Replies Last Post
EduSweep 2: Sneak Peek 2 bizzel EduSweep 0 29-09-2008 12:14 PM
EduSweep 2: Sneak Peek 1 bizzel EduSweep 1 20-09-2008 08:15 PM
EduSweep Update: Beta 6 Available bizzel EduSweep 14 03-06-2008 09:12 PM
EduSweep in use bizzel EduSweep 26 06-05-2008 10:40 AM


Tags
beta, edusweep


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 02:09 AM.
Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright EduGeek.net