Recent Nirsoft update

Discuss anything related to portable freeware here.
Post Reply
Message
Author
abc
Posts: 74
Joined: Thu Aug 04, 2011 10:01 am

Recent Nirsoft update

#1 Post by abc »

There's quite a few updates to the Nirsoft Password utilities that have the same changes:

"Removed the command-line options that export the passwords to a file from the official version. A version of this tool with full command-line support will be posted on separated Web page."

What is going on :?:

User avatar
SYSTEM
Posts: 2043
Joined: Sat Jul 31, 2010 1:19 am
Location: Helsinki, Finland

Re: Recent Nirsoft update

#2 Post by SYSTEM »

My guess is that it's related to malware being able to launch these utilities with such a command line switch, in which case the utility will export passwords silently and the user of the computer can't notice anything.

Of course this is quite poor protection:
  • Old versions of these utilities still float around the Internet. Redistributing them is legal.
  • It is possible for more sophisticated malware to launch the utility and trigger the menu option to export all passwords (maybe when user activity hasn't been detected for a while).
  • Ability to read passwords can be implemented in malware itself.
It might be that the webhost Nir Sofer is using contacted him and threatened to close the website if he didn't remove those command-line options.
My YouTube channel | Release date of my 13th playlist: August 24, 2020

the_watcher
Posts: 164
Joined: Mon Dec 07, 2009 2:30 am

Re: Recent Nirsoft update

#3 Post by the_watcher »

There is a post about this issue at NirBlog : Command-line options removed from the official release of my password-recovery tools
Long story short, Google is the culprit :twisted:

Post Reply