(To maintain the privacy of users, and abide by versiontracker submission guidelines, all third party emails and links have been obfuscated. I'd like to thank the editors at versiontracker with the help they provided in getting this review compliant with their guidelines).
Upon startup, this program downloads a file called "monitor.txt" from http://web.onetel.com/*******/monitor.txt. That file is now gone, but at the time of the original review being written the file contained the following entries:
w***@m***.com 0 -
d***@aol.com 1 -
r***@aol.com 0 -
b***@yahoo.com 0 -
f***@mac.com 0 -
m***@gmail.com 1 -
m***@c***.net 0 -
o***@m***.com 0 -
c***@a***.com.br 2 http://web.onetel.com/*****/find.sh
a***@tin.it 1 -
k***@h***.com 0 -
g***@triad.rr.com 0 -
b***@silly.com 0 -
s***@t***.com 0 -
What is interesting is that for certain users, the vendor can execute arbitrary scripts on their machines. For example, if we check the contents of find.sh as shown above, we see the following:
#! /bin/tcsh
find "/Volumes/MacOS 9.2.2" -name \*DVBackup\* -print > /dev/console
This script searches a users machine for the vendor's product. He could conceivably execute or install any type of software.
My final comment is about the interaction I've had with the developer. I have purchased a license of this software and to this day I cannot run the software in a licensed manner. Additionally, because of my desire to publish this review the vendor will no longer respond to emails.
DV Backup
Use your digital camcorder to back up data.
Version: 1.4.4
DV Backup has the potential to be spyware.
Feedback Type: Review
Contributed by: ramcito Wednesday, July 09 2008 @ 06:23 PM PDT
Product Platform: MacOSX
Used Product For: 1-6 months
Recommend Product: NO
Overall Rating:
Ease of Use:
Support:
Features:
Quality / Stability:
Price:
Comments
DV Backup has the potential to be spyware. - Coolatoola.com
This mechanism has a bona fide purpose, which is to help defeat fraudulent and other unauthorised use of DV Backup.Tim Hewett.
Friday, September 05 2008 @ 02:38 PM PDT
DV Backup has the potential to be spyware. - ThrowAwayAccount
I downloaded the 1.4.3 version and Little Snitch reported that "DV Backup wants to connect to web-uk.onetel.net.uk on TCP port 80 (http)".I denied it. Then looked for a preference to "Not check for newer versions at startup." I couldn't find one.
Very troubling.
Reply to This
Thursday, September 04 2008 @ 09:06 PM PDT