5 ms·
As somebody else mentioned - this is a great honeypot opportunity! By serving malicious builds based on referer and user-agent, they might be able to gather rea
by t0mk 11y ago
As somebody else mentioned - this is a great honeypot opportunity! By serving malicious builds based on referer and user-agent, they might be able to gather really interesting data.
- deleted 11y ago[deleted]
- hatsunearu 11y agoWouldn't it accidentally serve malicious builds to unsuspecting non-botnet users?
- sbierwagen 11y agoChange the links on cURL's website to point at a different file.
- pavel_lishin 11y agoIsn't that rather hard to do ethically? How would you make this "malicious build", given that it's probably going to be running on my dad's laptop at some point?
- kej 11y agoYou could make it harmless but not a valid cURL, also. Something that just prints to the screen that there's a good chance it was downloaded by the original malware and points you to a page on haxx.se where you can get the real version.
- throwaway7767 11y ago> As somebody else mentioned - this is a great honeypot opportunity! By serving malicious builds based on referer and user-agent, they might be able to gather really interesting data. They said the malware used no referer header and changing user-agent. If the user-agent were useful to segment these downloads from others, they most likely would have refused downloads based on that, because by renaming the file like they did, they're breaking build scripts for lots of downstream projects. There's also the ethical issue of breaking into others machines, even if it's "for a good cause".
- oxplot 11y agoDaniel mentions in the comments [1] that this is a binary build and implies that it's not meant to be hotlinked to. [1]: http://daniel.haxx.se/blog/2015/11/16/the-most-popular-curl-download-by-a-malware/comment-page-1/#comment-17535 http://daniel.haxx.se/blog/2015/11/16/the-most-popular-curl-...