7 ms·
Non-official site with a tampered version of KeePass
- moviuro 8y agoWho did this without thinking about an exfiltration tool instead?
- octosphere 8y agoI thought this too. Obviously not a very creative use of the domain squat. Worth reading: - https://en.wikipedia.org/wiki/Cybersquatting https://en.wikipedia.org/wiki/Cybersquatting - https://en.wikipedia.org/wiki/Brandjacking https://en.wikipedia.org/wiki/Brandjacking
- slipstream- 8y agoone of those "make money online"/"internet marketing" type people just wanting to get the affiliate commissions from a pay-per-install network of the PUP bundler type.
- zmaj72 8y agoOk
- po1nter 8y agoI've reported the website here: https://safebrowsing.google.com/safebrowsing/report_phish/?tpl=mozilla&hl=en-US&url=https%3A%2F%2Fkeepass.fr%2F https://safebrowsing.google.com/safebrowsing/report_phish/?t... Hopefull it will be blocked by the browsers using the safe browsing list.
- Algent 8y agoI reported it to afnic too. Since it does use the same domain name maybe they will act. Look like it's a copy paste of the .com one, with same download links.
- pandasun 8y agoLooks like its hosted on wp.com: https://i0.wp.com/keepass.fr/wp-content/uploads/2018/05/keepass-interace.png?w=966&ssl=1 https://i0.wp.com/keepass.fr/wp-content/uploads/2018/05/keep... So maybe we can report it here too: https://en.wordpress.com/abuse/ https://en.wordpress.com/abuse/ Only works if you put this as URL though: https://wp.com/keepass.fr/ https://wp.com/keepass.fr/
- jbk 8y agosafebrowsing is useless. We've reported scams of VLC shipping malware for years. They are still there.
- moviuro 8y agoFWIW, report the domains to https://someonewhocares.org/ https://someonewhocares.org/ , as he keeps updating it, and it is used by e.g. PiHole and my own hostfile generator.
- amaccuish 8y agoThe french is also terrible, google-translated french.
- deleted 8y ago[deleted]
- fenga 8y agoThis is correct french, and there is no way this was machine translated. Source : am french
- oliviergg 8y agoIt's proper french. I think I can be fooled by this website.
- phito 8y agoExcept it's not? It's totally proper French, even if it has some grammar errors, but we're usually not that good in grammar so yeah...
- dddddaviddddd 8y agoExamples? There's some subject and possession disagreement here and there ("Cette clé, que vous définissez ... accéder à tous ses autres mots de passe"), but otherwise looks pretty good.
- ajnin 8y agoI'm getting a different installer file from this website with not as many ad bundles detected : https://www.virustotal.com/#/file/23c3a4564265bc996ab61c1227feda7aa5a3e41033717421310fef3e42871bfc/detection https://www.virustotal.com/#/file/23c3a4564265bc996ab61c1227... Anyway, this wouldn't be the first time an open source software is packaged with some adware. Unsavory, but I think within the limits of the license.
- slipstream- 8y agoseems to be just another bundler from the same network (installcore), but packed with a different exe packer
- oliviergg 8y agoPretty ironicly, Terms of use warn to be very careful when downloading files with an exe.,. Vbs,. Lnk,. Bat,. Sys, or a suffix com., Because these files may contain a virus or spyware !
- pbhjpbhj 8y agoIt's a common technique used by hucksters, "here's some friendly advice ...", it's both an attempt to signal good intent and to load the mark with a subconscious sense of having been done a favour (and so needing to do a favour back to the huckster/salesman.
- wool_gather 8y agoNot ironic: totally intentional marketing trick. It makes you more inclined to trust the provider of the warning. They seem knowledgable about something important, and they're sharing that information with you. More insidiously, it makes you less likely to apply the warning to them. Because (unconsciously you think this) why would someone warn you about a trick they themselves are trying to pull?
- adtac 8y agoHah, the Linux version points you to the original website (only the Mac and Windows versions appear to be modified)! The year of the Linux desktop is truly here.
- amarant 8y agodoesnt that just imply that these scammers thought the linux userbase to be too small to be worthwhile? the comparatively small userbase is actually an underappreciated security feature of linux ;)
- slipstream- 8y agonot the website owner but people involved in the PUP ecosystem. i'm sure that if installcore supported linux, then the linux binaries would also be bundlers.
- taneq 8y agoOr that Linux users would instantly raise a hue and cry on seeing ads?
- PascLeRasc 8y agoKind of like how scammers use bad grammar on purpose to weed out the people too smart to be a victim.
- taneq 8y agoYes, now that you mention it - they deliberately tried to design their dragnet to exclude victims who were likely to be problematic. :)
- elygre 8y agoIsn’t that the infamous “security by obscurity”?
- 8y ago
- pingec 8y agoWhat are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.
- slipstream- 8y agopup bundlers also tend to be signed. just checking for a valid signature would not be enough
- codeulike 8y agoSourceforge is under new management and they removed the bundled installers, as I understand it. https://sourceforge.net/blog/brief-history-sourceforge-look-to-future/ https://sourceforge.net/blog/brief-history-sourceforge-look-...
- mihaifm 8y agoCompile it from source, it's a standard Visual Studio solution that builds without issues.
- pingec 8y agoBut there are no guarantees about the source either unless I am willing to audit all of it?
- deleted 8y ago[deleted]
- mihaifm 8y agoI agree, that's why signed source code releases are the safest thing you can get. Keepass has signed releases (including the source code archive) that can be checked with OpenPGP. https://keepass.info/integrity.html https://keepass.info/integrity.html
- 8y ago
- campuscodi 8y agoThere are quite a few of these: https://keepass.fr/ https://keepass.fr/ https://7zip.fr https://7zip.fr https://audacity.fr https://audacity.fr https://gparted.fr https://gparted.fr https://keepass.fr https://keepass.fr https://nc3354.nexylan.net https://nc3354.nexylan.net https://paintnet.fr https://paintnet.fr
- redsec 8y agoThanks for the update, they all look to come from the same guys.
- campuscodi 8y agoThey do. They're all registered via one email: https://domainbigdata.com/gmail.com/mj/0DnwUjDWo0L7ysS4kB00pg https://domainbigdata.com/gmail.com/mj/0DnwUjDWo0L7ysS4kB00p...
- pandasun 8y agoGood find! Can't believe this person made that many fake domains.
- hengheng 8y agoSo, basically somebody went through the list of all tools most commonly installed trough ninite, and created a spoof for each of them.
- zokier 8y agoI've had discussions with coworkers on why you shouldn't ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads now, but imho it's just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned
- lakechfoma 8y agoRather unfortunate that "putty.org" is the first result in searches and looks a lot more legit than "chiark.greenend.org.uk" even if it (currently) links there. I've had discussions with coworkers on why they shouldn't look up "free online json beautifier" and dump thousands of lines of crown jewels into them (http too). Meanwhile we're doing web dev and JSON responses are autoformatted in Firefox dev tools so there's an amazingly convenient and perfectly safe alternative right there... How do we impart urgency with this kind of stuff?
- aeontech 8y agoShow your coworkers jq, it is amazing: https://stedolan.github.io/jq/ https://stedolan.github.io/jq/
- lakechfoma 8y agoThis looks great! Coworkers don't work in the shell at all though so there's that, but I might use it at times. They're lookin for that syntax highlighted and interactive experience you know.
- slededit 8y agoIt's putty's own fault. They used to (and perhaps still do) have a section on how they don't want your donated domain - they like their current one. From their FAQ: > No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned), and we don't believe the administrative hassle of moving the site would be worth the benefit.
- Kagerjay 8y agoSomething I don't understand though is when I do a google search, google sometimes sponsors these phony sites. One time I downloaded the wrong google chrome which was ironic because I was on google searching it. Other examples that come to mind with different sites are popcorn.sh vs popcorn-time.to. There not the same repository. Normally I just do a sanity check by checking the domain URL and checking if it has authority. If its on sourceforge... I just assume its malware or has bundled PUPware on it, run it through antivirus and SHA/MD5 checks. Ninite.com is pretty convenient I hope they don't get comprimised one of these days and get sold to a shady vendor
- greggarious 8y agoUnfortunately I can't read the article without enabling javascript - anyone care to post a summary? :)
- mar77i 8y agoUnrelated to the topic, the article points out a lot of things about certificates in the URL bar. That got me to think about the URLs themselves, can I set my browser up so it displays the punycode representation of my url?
- teget 8y agonetwork.IDN_show_punycode in firefox