MITM Checker

Discussion in 'other anti-malware software' started by svenfaw, May 21, 2019.

  1. guest

    guest Guest

     
  2. lucd

    lucd Registered Member

    thanks so I have a huge wall of alerts with kaspersky antivirus personal root certificate
    must be some compatibility stuff with KA free
     
  3. askmark

    askmark Registered Member

    It been renamed to NoSnoop. Although, the download link is not working at the moment until the author fixes it.
     
  4. guest

    guest Guest

    The download link for NoSnoop works now.
    https://www.trustprobe.com/fs1/download.php?appname=NoSnoop.zip
     
  5. Josh McCormick

    Josh McCormick Registered Member

    Quite an interesting tool!

    I'm on Cox Internet.
    I had an alert on "huawei.com" and an occasional alert on "www.bbc.co.uk" (it is currently NOT alerting)

    www.bbc.co.uk 0 GlobalSign Root CA - R1 B1BC968BD4F49D622AA89A81F2150152A41D829C
    www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC​

    I switched to a third-party's VPN (which sees a random amount of handshake failures).
    The "huawei.com" detection remained, and I wasn't able to get an alert on "www.bbc.co.uk" (but I can't say if the lack of a BBC hit had any real meaning here or not).

    www.bbc.co.uk 0 GlobalSign Root CA - R1 B1BC968BD4F49D622AA89A81F2150152A41D829C
    www.huawei.com 0 Actalis Authentication Root CA F373B387065A28848AF2F34ACE192BDDC78E9CAC​

    Still, the alert on Huawei kind of raises an eyebrow, doesn't it?

    I noticed someone on Hacker News seeing similar results. If I want to investigate this further, what's my next step? Suggestions for Linux tools are especially welcome.

    Thanks all.
     
  6. HempOil

    HempOil Registered Member

    I also get the alert on huawei
     
  7. liba

    liba Registered Member

    Clean your system. Save as .bat (like Clear.bat) and run

     
  8. Surt

    Surt Registered Member

    The zip file used to contain a hostlist.txt; top100.txt when it was MTM Checker.

    One could whip up one's own hostlist.txt. Not any more.

    The previous nosnoop.exe was 152 KB and the current exe is 377 KB.

    Looks like the hosts are now "built in," as hostlist.txt is ignored. :(

    https://www.trustprobe.com/ as of this posting opens with:
    TrustProbe
    Seriously cool things coming soon!

    I hope so...
     
  9. ravenise

    ravenise Registered Member

    @svenfaw
    Tried it, but both versions don't even load in windows 10 1909 x64, or fresh windows 10 1909 x64 VM, or fresh windows 7 x64 VM, not sure whats up. No error message, or warnings or window period, just nothing.
     
  10. ravenise

    ravenise Registered Member

    Got it working finally, had to change the date to July 8 2019; works only temporarily after each release
     
  11. svenfaw

    svenfaw Registered Member

  12. EASTER

    EASTER Registered Member

  13. Adric

    Adric Registered Member

    so what are you supposed to do when you find Alerts ?
    Not visit those sites? :D

    nosnoop.jpg
     
    Last edited: Jul 8, 2020
  14. Tarnak

    Tarnak Registered Member

    Always ready to try something new. So, here goes.

    NoSnoop_Untrusted File_ SecureAPlus_01.JPG >>> NoSnoop_Untrusted File_ SecureAPlus_02.JPG
    >>> NoSnoop_Untrusted File_ SecureAPlus_03.JPG

    NoSnoop_Untrusted File_ SecureAPlus_04.JPG
     
  15. svenfaw

    svenfaw Registered Member

    The AAA Certificate Services (D1EB23A46D17D68FD92564C2F1F1601764D8E349) alert is a false positive.

    Fixed in version 0.83.
     
  16. XIII

    XIII Registered Member

    Indeed. Thanks!
     
  17. Adric

    Adric Registered Member

    Any plans for a 32-bit version? Won't run on the system I'm currently on.
     
  18. Triple Helix

    Triple Helix Specialist

    All Good here!

    2020-07-09_19-55-12.png
     
  19. stapp

    stapp Global Moderator

    Doubleclick.net handshake failure n/a ?
     
  20. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    medlineplus.gov 0 Handshake failure
    The rest are all good.

    Anyway after re-scan all is ok now. :)
     
  21. svenfaw

    svenfaw Registered Member

    On my to-do list :)
     
  22. svenfaw

    svenfaw Registered Member

    A possible reason could be if you are using a system-wide adblocker, or have a doubleclick.net entry in your hosts file.
     
  23. paulderdash

    paulderdash Registered Member

    Ha. That explains it, I had a quite a few 'handshake failure N/A', and disabling AdGuard for Windows solved that. Neat.

    Except for utorrent ...
    Don't use it so not sure why it's even there ...
     
  24. svenfaw

    svenfaw Registered Member

    screenshot1.png


    New version: v0.87.003

    Some more specific host lists have been added:
    - Email services
    - Financial services
    - Communication services
     
  25. EASTER

    EASTER Registered Member

    Interesting additions. All fine on the home front with this new version :thumb:

    fd.jpg
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice