PIFTS.exe
Mar 10 2009, 5:12 pm
By: Excalibur  

Mar 10 2009, 5:12 pm Excalibur Post #1

The sword and the faith

Quote
For all who are unaware, a program installed with Norton named PIFTS.exe has been causing major conflict in the past day. Anyone who asks what it is, or even mentions it on the Norton forums, is permanently banned, and the topic is deleted.


Well, we are getting closer to finding what it is - and it IS dangerous.


PIFTS
Public Internet and File Tracking System

It goes offshore because there's no law forbidding sending it to foreign governments. If governments want to spy on their own citizens, it is normal for them to have foreigners do it in order to get around normal restrictions about spying on their own people.


There have been confirmed reports of people who have managed to isolate the executable - Its code messes with your internet history. It also does something with google.

I reckon Norton is fucking finished after this hits mainstream news. I am now laughing at every idiot who ever installed any shitty symantec bullshit. :lol:




SEN Global Moderator and Resident Zealot
-------------------------
The sword and the faith.

:ex:
Sector 12
My stream, live PC building and tech discussion.

Mar 10 2009, 5:51 pm Fisty Post #2



Interesting way to acquire porn...

Also:


Post has been edited 1 time(s), last time on Mar 10 2009, 6:05 pm by Deathman101.



None.

Mar 10 2009, 6:06 pm Moose Post #3

We live in a society.

To be honest, this just sounds like propaganda. I can agree that Norton has become overbloated and ineffective in comparison to other programs, but this just sounds like bull to me. Evidence and sources please?

EDIT: Never mind. This is pretty recent, which is why I couldn't find anything. Things are starting to pop up in Google news just now.
http://www.theregister.co.uk/2009/03/10/norton_pifts_mystery/
http://www.tweaktown.com/news/11631/norton_avoiding_all_questions_about_pifts_exe/




Mar 10 2009, 8:17 pm Corbo Post #4

ALL PRAISE YOUR SUPREME LORD CORBO

I remember I had symantec back in 1998 on my Win95 computer :P

My laptop came with some norton internet security but I just deleted it when I saw it.



fuck you all

Mar 10 2009, 8:25 pm chuiu Post #5



http://www.telegraph.co.uk/scienceandtechnology/technology/technologynews/4969463/Internet-conspiracy-theories-abound-over-Symantec-Pifts.exe-file.html

Summary: No one thinks its anything harmful or a rootkit but they're waiting for a statement from the company about it.



None.

Mar 10 2009, 11:02 pm Fire_Kame Post #6

wth is starcraft

It isn't that pifts.exe exists that's giving Norton so much grief, its that Norton is doing their damnedest to ignore the problem. The only 'harmful' thing I heard about it is that apparently the .exe has a lot of PADDINGXX in it or something, which is strange for a legit program to have.




Mar 10 2009, 11:11 pm ShadowFlare Post #7



That is just something that some compilers add at the end instead of just 0's, but I don't know which one does it. Exe or dll files always have a multiple of a certain number as their size, but I don't remember which at the moment. Because of this, they always have some type of padding at the end. If it is just one byte over, it can't just round down, it has to round up to the next multiple.



None.

Mar 10 2009, 11:47 pm ClansAreForGays Post #8



I've been following this since last night, kept me up till about 3. Here's what I've learned from everything I've read(which is alot):

The second IP that it tries connecting to is not in Africa. 1 is in Virginia, and I think the other is in Washington.

The paddingXX doesn't mean anything, but is not typical for professionals to do this, which spawned the idea some amateur hacker snuck this into the update and is not from norton.

Symantec says they deleted the posts because someone alerted them of a 4chan /b/ topic that was asking for raids. This is false; people were already discussing PIFTS.exe for a good few pages on their forum, until users started discussing and posting specs as to what the program was actually doing. Then these people went to either zonealarm's forum or 4chan's /g/ and started spreading the news of what is going down. THEN a /b/ topic asking for raids came up, the whole while before this anyone that even mentioned pifts.exe was banned.

The moderation on the norton site deleted every post and banned every user that posted anything about pifts.exe, whether it was a legitimate question or not. I also read that they are just now starting to unban certain people that emailing the admin about their unjust ban.

People experienced in decompiling got their hands on the program via mediafire. They report the program searches through your internet history. Some how in the face this the 'experts' are saying this is probably harmless. Unfortunately they seem to only be thinking in terms of damage to your computer. The truth is this thing seems to be some kind of data mining tool that reports to Symantec everything you've been doing on the internet.

I've also many unconfirmed reports of other places where any mentioning of PIFTS.exe has been censored(ie Google Trends)

Post has been edited 2 time(s), last time on Mar 10 2009, 11:56 pm by ClansAreForGays.




Mar 11 2009, 12:54 am Heinermann Post #9

SDE, BWAPI owner, hacker.

So this is part of the big Google privacy conspiracy?

Quote
People experienced in decompiling got their hands on the program via mediafire. They report the program searches through your internet history. Some how in the face this the 'experts' are saying this is probably harmless. Unfortunately they seem to only be thinking in terms of damage to your computer. The truth is this thing seems to be some kind of data mining tool that reports to Symantec everything you've been doing on the internet.
That's hardly enough description from "experts" at reverse engineering. A program that just searches through your internet history? They could have integrated that into a module or the main program.

Quote
That is just something that some compilers add at the end instead of just 0's, but I don't know which one does it. Exe or dll files always have a multiple of a certain number as their size, but I don't remember which at the moment. Because of this, they always have some type of padding at the end. If it is just one byte over, it can't just round down, it has to round up to the next multiple.
EXE/DLL files can actually be aligned to a single byte. See Tiny PE for details on a valid 97-byte executable, and a 133-byte executable that downloads a file from the internet and executes the downloaded file.




Mar 11 2009, 3:02 am ShadowFlare Post #10



It is not typical for the alignment, though.



None.

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[07:46 am]
RIVE -- :wob:
[2024-4-22. : 6:48 pm]
Ultraviolet -- :wob:
[2024-4-21. : 1:32 pm]
Oh_Man -- I will
[2024-4-20. : 11:29 pm]
Zoan -- Oh_Man
Oh_Man shouted: yeah i'm tryin to go through all the greatest hits and get the runs up on youtube so my senile ass can appreciate them more readily
You should do my Delirus map too; it's a little cocky to say but I still think it's actually just a good game lol
[2024-4-20. : 8:20 pm]
Ultraviolet -- Goons were functioning like stalkers, I think a valk was made into a banshee, all sorts of cool shit
[2024-4-20. : 8:20 pm]
Ultraviolet -- Oh wait, no I saw something else. It was more melee style, and guys were doing warpgate shit and morphing lings into banelings (Infested terran graphics)
[2024-4-20. : 8:18 pm]
Ultraviolet -- Oh_Man
Oh_Man shouted: lol SC2 in SC1: https://youtu.be/pChWu_eRQZI
oh ya I saw that when Armo posted it on Discord, pretty crazy
[2024-4-20. : 8:09 pm]
Vrael -- thats less than half of what I thought I'd need, better figure out how to open SCMDraft on windows 11
[2024-4-20. : 8:09 pm]
Vrael -- woo baby talk about a time crunch
[2024-4-20. : 8:08 pm]
Vrael -- Oh_Man
Oh_Man shouted: yeah i'm tryin to go through all the greatest hits and get the runs up on youtube so my senile ass can appreciate them more readily
so that gives me approximately 27 more years to finish tenebrous before you get to it?
Please log in to shout.


Members Online: RIVE, IlyaSnopchenko