PDA

View Full Version : update file corrupt


blevit
January 16th, 2004, 12:46 PM
hello to all. today trying to update tds but the dowloaded file was corrupt. and say trying another server,is the second day with the same problem and no update at all .wot to do???? thanks in advance

gkweb
January 16th, 2004, 01:03 PM
me too, same pb.

Jooske
January 16th, 2004, 01:06 PM
Hello Celso, and GK (see your posting after i hit send)
did you see this thread here: http://www.wilderssecurity.com/showthread.php?t=19672 ?
Did you also try with a new fresh update.cfg file from the TDS update site? Drop the file in the TDS-3 directory and restart TDS to have another try, or get the radius from the site manually once you're there anyway, after which a TDS (re)start should bring you the new radius --
[Radius] • Systems Initialised [31222 references - 11118 primaries/8918 traces/11186 variants/other]
today.

gkweb
January 16th, 2004, 01:15 PM
Jooske, i have done this many times, and the problem still occurs each weeks.

This is why i think it is related to my ISP.

-{ Quote: "
;Radius.TD3 Database Update Sites
;See http://tds.diamondcs.com.au/index.php?page=update for latest server list
http://fractus.mat.uson.mx/~tds/radius.td3
http://radius.turvamies.com/radius.td3
http://www.zeylstra.nl/tds/radius.td3
http://www.toonbox.de/tds/radius.td3
http://www.rootgap.com/tds/radius.td3
http://www.attechnical.com/diamondcs/radius.td3
ftp://ftp.pc-techie.info/tds/radius.td3
http://tds.diamondcs.com.au/radius.td3
http://diamondcs.fileburst.com/radius.td3
" }-

Jooske
January 16th, 2004, 02:54 PM
ftp://ftp.pc-techie.info/tds/radius.td3
http://fractus.mat.uson.mx/~tds/radius.td3
http://www.rootgap.com/tds/radius.td3
http://radius.turvamies.com/radius.td3
http://www.toonbox.de/tds/radius.td3
http://www.zeylstra.nl/tds/radius.td3
http://www.attechnical.com/diamondcs/radius.td3
http://www.diamondcs.com.au/tds/radius.td3
http://diamondcs.fileburst.com/radius.td3

This list i just got a few moments ago.
When you rightclick and save target you get it as update.cfg.txt. Make sure you rename to update.cfg
when you drop it in the TDS directory and reload TDS to be able to use it.
If you have errors on the first server you can edit the file and move another one as mirror #1. Make sure you don't create extra empty lines or extra spaces for it might not work then properly anymore.

gkweb
January 17th, 2004, 11:15 AM
i got afresh upadte.cfg and again and again the same pb.
I must download it myself from the website, i think i will do my own updater
which will download from the website only to bypass something i guess is my ISP restriction (last time i wasn't able to send a mail to Jason, is this an ISP war ?)

blevit
January 17th, 2004, 01:50 PM
Hello gkweb looks like we are the only 2 wiht this problem or wot????
any one had the same problem. :'(

Caliban
January 17th, 2004, 02:14 PM
I have the same problem folks, as always I hope it is fixed next week. My ISP is DirecWay, so I don't believe it's an ISP issue. :'(

Paul Wilders
January 17th, 2004, 03:46 PM
mmm..no problems at all over here ::)

regards.

paul

gkweb
January 17th, 2004, 05:10 PM
may be it isn't related to ISP, but the pb exists.

-{ Quote: "
23:12:52 [Radius Update] Downloaded file was corrupt, trying next server...
" }-

Caliban
January 17th, 2004, 07:26 PM
The thousand words. :(

FanJ
January 17th, 2004, 08:24 PM
Have you tried to put these lines in your HOSTS file:

64.91.255.87 tds.diamondcs.com.au
64.91.255.87 www.diamondcs.com.au
64.91.255.87 www.dcsresearch.com

and checked whether is no other line with www.dcsresearch.com in it?

And what if you put now as first one in your update.cfg the tds.diamondcs.com.au server?
That means this one:
http://tds.diamondcs.com.au/radius.td3

Jooske
January 18th, 2004, 02:54 AM
http://www.diamondcs.com.au/tds/radius.td3
FanJ, did you see in the new update.cfg the DCS link has changed to the one i post here?

If a not registered user would try the update via the console, one will get error messages, not exactly sure which one.
But if licensed users get "corrupt" for every server each time then something is very wrong.

I don't expect firewalls b eing a blocking factor, as you see to be able to connect to the mirrors, getting those corruption messages, or.....?
Can you see in PE if there is a proper connection going on and maybe you're able to look with the socket spy to the first initialising packets?
I have it the one time f.e. mirror 1 is wrong several times, and 2 is ok, while others have that same mirror 1 doing fine all times, so at times i move such a mirror down some places or get a new update.cfg.
Just not seeing any logics, only that it seems more frequent.
Did you in your firewall make a rule for the update.exe to be granted trusted zone and internet connection and no restrictions on that?
If you click on any of the mirrors in the messages here, do make sure not any download helper program is used but the original windows downloader, maybe TDS is making those problems in such cases?
I have such a downloadhelper, but not set as default download program, maybe such settings can make a difference?
For ISPs you think they might have the former version in their caches? Are you using their proxies or own proxies maybe?

gkweb
January 18th, 2004, 08:17 AM
it was a firewall issue for me... :-X

in the past i have allowed only DCS IP's which in fact has changed since.
By giving full access to updates.exe the update works, but i don't understand the following :

-{ Quote: "
13:23:55 [Init] • Systems Initialised [31222 references - 11118 primaries/8918 traces/11186 variants/other]
13:23:55 [Init] Radius Systems loaded. <Databases updated 17-01-2004>
13:23:55 [Init] TDS-3 Ready. <Administrateur@192.168.0.1, 127.0.0.1 - France>
13:23:55 [TDS] Good afternoon Administrateur.
14:16:56 [Radius] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
14:16:59 [Radius] • Radius Advanced Specialist Extensions on standby for 13 trojan families
14:16:59 [Radius] • Systems Initialised [31180 references - 11094 primaries/8913 traces/11173 variants/other]
14:16:59 [Radius] Radius Systems loaded. <Databases updated 18-01-2004>
14:16:59 [Radius Update] Update complete.
" }-

The update give me an older version ?

Caliban
January 18th, 2004, 08:38 AM
Your post inspired me gkweb. I rechecked my firewall, not it, rechecked my proxy settings, my oh my do I feel dumb. I updated and got the same wrong update, but I'm happy none the less. ;D

gkweb
January 18th, 2004, 08:42 AM
by wanting too much security we prevent softwares from working :)

Caliban
January 18th, 2004, 08:48 AM
You are right, I locked down so tight I couldn't get to my bank login. It hurt to ease up the IE settings. ;)

Jooske
January 18th, 2004, 09:00 AM
For the update, you might remember if the first server gave you an older update (hmm!) so you might like to move that one to a lower place in the update.cfg file, and see what happens with a next update.
The older downgrade might have been in your ISP's caches.

Hope in your firewalls too it is possible to allow the update.exe some internet activity and if necessary to use other programs for that goal. You'll still be safe as you have to grant those other programs internet access individually too again.

spy1
January 18th, 2004, 01:59 PM
You know, I'm noticing that the size of the updates has gone down - for a long time, it went up and up and up - now it's back down to around, what 800K?

What's up with that?

Jooske - That one you put in the thread up above works great - it seems most of the mirrors still aren't updated, because I just tried a trial "Update" (after having had to manually install Friday's update) and it instantly down-graded the the updates to a lesser number.

It seems to me that something is definitely wrong in the "updating the servers" food-chain here. Pete

Pilli
January 18th, 2004, 02:17 PM
Hi Pete, I have a feeling that this is a propagation problem through cached servers that is affecting the updates. I have no way of proving whether this is so but I do know that ppl have been complaining in my ISP's user groups about Inktomi cached servers being slow to update. Though what could be causing the problem I have no idea ???

BTW ref. update size, maybe Gavin has been doing some database optimisation? My radius file in the TDS folder is 1198KB

FanJ
January 18th, 2004, 02:28 PM
Hi Pete,

-{ Quote: " quoting: spy1 link=board=5;threadid=19689;start=15#msg121218 date=1074452368]
You know, I'm noticing that the size of the updates has gone down - for a long time, it went up and up and up - now it's back down to around, what 800K?

What's up with that?" }-

Sometimes there is also an update for these files in your TDS3-dir:
advscan.dll and dcsmutex.dll
Put them in your crcfiles.txt (if they are not already there), and your crc32-test will notify you in case they've changed.

In this respect I have a question for DCS:
When you manually download the Radius-file, you simply copy it into your TDS3-dir.
In case advscan.dll and/or dcsmutex.dll are changed, you will not get those.
Am I right?

-{ Quote: "
Jooske - That one you put in the thread up above works great - it seems most of the mirrors still aren't updated, because I just tried a trial "Update" (after having had to manually install Friday's update) and it instantly down-graded the the updates to a lesser number.

It seems to me that something is definitely wrong in the "updating the servers" food-chain here. Pete
" }-

Yes, I tend to agree.
BTW: maybe a suggestion for DCS: would it be a good idea to notify us in case update.cfg has been changed on the DCS-server: maybe a little posting on the private-board for example, and/or maybe adding a date on the following DCS-site for the latest update.cfg.
http://tds.diamondcs.com.au/index.php?page=update
Well just a suggestion, nothing more ;)

FanJ
January 18th, 2004, 02:55 PM
Quoting myself:

-{ Quote: "Sometimes there is also an update for these files in your TDS3-dir:
advscan.dll and dcsmutex.dll
Put them in your crcfiles.txt (if they are not already there), and your crc32-test will notify you in case they've changed.
" }-

I just had a quick look at the Help-file.
Those 2 files are not by default in crcfiles.txt according to the Help-file.
In case you would like to add them, just add those two lines into your file crcfiles.txt:

%TDSDIR%\advscan.dll
%TDSDIR%\Dcsmutex.dll


In case you would like to check if you have the latest ones, here are their MD5-checksums at the moment on my machine:
fa43131291ea7db8aaf87c2037368813 advscan.dll
afc416da0ea38ea8c670a36e3a154016 DCSMUTEX.DLL

spy1
January 18th, 2004, 03:19 PM
Pilli - See screenshot for my radius file size. It's possible that I just didn't see the entire count before the Radius Updater finished the d/l and closed out - but I'm wondering (just as general information) - has the Radius file been "optimized"? And, if so, in what respect?

I'm a little concerned because of all the instances I've seen lately where someone comes in and says "TDS didn't detect this (fill-in-the-blank)", but then Gavin or someone comes back and says "TDS does so detect such-and-such using the database from this time-period...."

So what I'm asking is, are things being dropped from detection from one DB to the next? If so, is it by design or by accident?

FanJ - I'll be back with a response to what you posted as soon as I figure out how to do that! ;D What size are both of them supposed to be currently and what's their latest update dates? Pete

Pilli
January 18th, 2004, 03:33 PM
I have not noticed any smaller updates except when I get a corrupted download and I can see that the amount of primaries etc. is smaller than the ealier one.

Here is the latest 1.16MB radius file checksum from my desktop:
---------------------------------------------------
The file <C:\Documents and Settings\Alan\Desktop\radius.td3> has the following Checksum(s)

MD5 - 6C93D1697B62D74F83A2419A0E084B0C

;D

FanJ
January 18th, 2004, 03:35 PM
-{ Quote: "FanJ - I'll be back with a response to what you posted as soon as I figure out how to do that! What size are both of them supposed to be currently and what's their latest update dates? Pete " }-

Hi Pete,

With respect to adding those files into crcfiles.txt: see the sticky thread about the CRC-test.

With respect to their MD5 checksums:
Do you have CryptoSuite from DCS?
It's very easy to let CS calculate a MD5 checksum; Alan just told me how to copy it :D


advscan.dll
Size: 78.848
18 DEC 2003
The file <C:\...\advscan.dll> has the following Checksum(s)
MD5 - FA43131291EA7DB8AAF87C2037368813


Dcsmutex.dll
Size: 22.947
8 JAN 2004
The file <C:\...\DCSMUTEX.DLL> has the following Checksum(s)
MD5 - AFC416DA0EA38EA8C670A36E3A154016


PS: I prefer a checksum like MD5 ;)

spy1
January 18th, 2004, 03:43 PM
Okay, added those two to the CRC check (thanks, Jan!). Now, the screenshots show what I have for the advscan.dll/Dcsmutex.dll - are they the latest?

DCSMUTEX.DLL shown here - File Version 1.0.0.0/Product Version 2.0

spy1
January 18th, 2004, 03:44 PM
And this. (advscan.dll) File Version 1.0.0.0/Product Version 2.0

And, no, Jan - I don't have CS.

spy1
January 18th, 2004, 06:07 PM
fa43131291ea7db8aaf87c2037368813 advscan.dll

afc416da0ea38ea8c670a36e3a154016 DCSMUTEX.DLL

Got it and that one works fine, Jan! Thanks! Pete

FanJ
January 18th, 2004, 06:53 PM
I'm very happy you've got the right files, Pete :)

Some other remarks (and I know that I'm now going way off topic):

1.
Always mention which HASH (checksum) algorithm you were using: CRC32, MD5, SHA-1, etc.

2.
Don't bother whether characters like a, b, c are in capitals or not.

3.
Some checksum-algorithms can be and have been "compromised".
The stronger the HASH algorithm, the less the possibility that that happens. Much can be said about that, but this isn't the right place/topic to do that ;)

gkweb
January 18th, 2004, 06:56 PM
The file <C:\Program Files\DCS AT\Radius.TD3> has the following Checksum(s)

ADLER32 - 2E25DC35
CRC32 - 39D727A9
HAVAL128 - C11A1ADF80DFA41D4FFD13FE10DA6F6B
HAVAL256 - C0B738B8ED3BCC8E6F22B5BF837F0332F3F38F92D18C178F540C8E8F31349266
MD2 - 3F93BE56E9A63188ACDEE4E08BD798BB
MD4 - AE7C2E9B3FA48FF004E505C4CDD65285
MD5 - 2A7A06B3DB2FF83FCFDD41A79554A58A
SHA-160 - 0199A4168E0E82956257E0CE88B69AEC5EC08FCA
SHA-256 - E04DCD801D113E6A03660CDB95E86D3E5EF58AD3A87E2AA657D28B4344B9BB39
SHA-384 - FF949854ABE75AF4839BF9259210C7DBDFAC14F9415A6E42A0C0BBC095B2E42BDA5D3D52E920CE246D328E5F1329EF9A
SHA-512 - 9C4F5F80FB88F43695D9780A57A4D8ADDB2D6EC3BBB7B6FF3031EC4CABF0371CA0F2E420D2F745634FEF778EE8BB8B0CD0E30E21201D5F7092CA6CD7CDB7D361
TIGER - 58CFE5C8935E5D699DF3BB463D2FAFC1F5CB91937F551A8F



Like this ? ;D

FanJ
January 18th, 2004, 07:15 PM
Hi gkweb ;)

Let's for the moment stick to MD5.

I have:
The file <C:\...\Radius.TD3> has the following Checksum(s)
MD5 - 6C93D1697B62D74F83A2419A0E084B0C

You have:
MD5 - 2A7A06B3DB2FF83FCFDD41A79554A58A

So:
We do NOT have the same file !

FanJ
January 18th, 2004, 07:26 PM
I just checked:

I manually downloaded Radius.td3 from:
http://tds.diamondcs.com.au/index.php?page=update

It gives me (as far as I was able to see :-X ) the same MD5 checksum as I posted.

gkweb
January 18th, 2004, 07:28 PM
i know ;)

i just have an older version cause of a bad update, i will tomorrow put later on my list the server from i get an older version.

FanJ
January 18th, 2004, 07:35 PM
quote from me:

"It gives me (as far as I was able to see ) the same MD5 checksum as I posted."

quote from gkweb:

"i know"

[hr]

Sorry, I'm too old and have far too bad eyes to play further.

gkweb
January 18th, 2004, 07:55 PM
no, i have replied to "We do NOT have the same file !" ;)

i have just updated :
-{ Quote: "
01:55:02 [Radius] Loading Radius Advanced Scanning Systems ... <R3 Engine, DCS Labs>
01:55:05 [Radius] • Radius Advanced Specialist Extensions on standby for 13 trojan families
01:55:05 [Radius] • Systems Initialised [31222 references - 11118 primaries/8918 traces/11186 variants/other]
01:55:05 [Radius] Radius Systems loaded. <Databases updated 19-01-2004>
01:55:05 [Radius Update] Update complete.
" }-

MD5 - 6C93D1697B62D74F83A2419A0E084B0C

FanJ
January 19th, 2004, 03:38 PM
Sorry Gkweb: I completely mis-understood you; it's me who is to blame ! :-[

Best regards, Jan.

gkweb
January 19th, 2004, 03:53 PM
np FanJ :)

FanJ
January 19th, 2004, 06:57 PM
-{ Quote: " quoting: gkweb link=board=5;threadid=19689;start=30#msg121680 date=1074545623]
np FanJ :)
" }-

Thanks a lot Gkweb ! :)

Jooske
January 20th, 2004, 02:17 AM
For the statistics, in case you had those "corrupt" messages and also the next server might not have given the right new update via the console, can you remember which other programs might have been running?