Live data from Hacker News

Trojan found in Filezilla downloaded from SourceForge

forum.filezilla-project.org

151–160 of 217 posts

Re: Trojan found in Filezilla downloaded from SourceForge

#151
post #97

Earlier quoted context omitted.

That's interesting, but it doesn't reassure me much. The infrastructure behind Groups may be in use, it doesn't stop Google from shutting the UI down.

To be clear: it's not just the infrastructure; the set up a Google Apps mailing list you use the Google Groups UI.

Well, they already shut down the free tier of Google Apps, which was also used by some OSS projects.

So it’s possible.

Re: Trojan found in Filezilla downloaded from SourceForge

#152

The Filezilla forum admin in that thread obstinately blames users for "accidentally" accepting a bundeled "offer", when users are clearly warning project admins that the installer is infected with malware. Does sourceforge share revenue from bundeled installs with projects?

If you opt-in, they do. Filezilla was one of the first to opt-in.

If you say "no, I don’t want you to bundle your installer with my project", they will do so anyway (look at GIMP), and you get nothing.

Re: Trojan found in Filezilla downloaded from SourceForge

#153
post #43

Earlier quoted context omitted.

It doesn't come standard, not on all Windows flavours. It's a part of "Core networking utilities" package that used to have some really odd dependencies.

You're mis-remembering or something... There's no such thing as a "Core Networking Utilities" package on Windows (never has been) and ftp has been a command line tool since at least Windows 95. I don't particularly like the built in FTP command line utility (even with scripts). But it has existed a very long time indeed.

Eh, yes, it is. On the Windows 7 Home Basic and Home Premium edition, it’s not pre-installed, and you have to go to System Settings -> Programs and Features -> Install or Remove Features to install it.

Re: Trojan found in Filezilla downloaded from SourceForge

#154
It would seem that more projects would benefit from running their own free software on their own virtual server infrastructure. A decade ago, there was GNU Mailman and it's still around - http://www.list.org.

Yes, this means that a self-contained project needs the funds for basic hosting and also someone with system admin experience. But that should not be unreachable for major projects.

Re: Trojan found in Filezilla downloaded from SourceForge

#155
post #65

Earlier quoted context omitted.

I had contacted FileZilla's developer about this back in 2014. He let me know that bundling crapware was "intentional" http://i.imgur.com/AvfDuOA.png His statement about alternate download links was also incorrect, because I was asking about Filezilla server, which I could not find anywhere but sourceforge.

Does it mean that I have this crap installed since at least 2014 on all computers at work and Sophos didn't detect it ?

According to this [1] Sophos can detect it:

[1] https://www.virustotal.com/en/file/16e0ecda06ed98f835e449e1e...

Re: Trojan found in Filezilla downloaded from SourceForge

#156

The Filezilla forum admin in that thread obstinately blames users for "accidentally" accepting a bundeled "offer", when users are clearly warning project admins that the installer is infected with malware. Does sourceforge share revenue from bundeled installs with projects?

If you opt-in, they do. Filezilla was one of the first to opt-in. If you say "no, I don’t want you to bundle your installer with my project", they will do so anyway (look at GIMP), and you get nothing.

so yeah, it seems like there's kind of a conflict of interest here. if there's no way for a user to know whether the project opted in to revenue sharing, then how can they trust the project?

in other words, in my view, a project that opts in to revenue sharing with crapware bundlers who are known to sometimes distrubute malware, is behaving unethically.

so now i don't trust filezilla dev's in general, even if i get an package signed by my distro or whatever. very dissapointing. worse still, it makes projects that didn't opt in suspect in my view, simply because they are on sourceforge; if i can't find out whether they opted in, how can i know any project isn't taking kickbacks?

i really hope i'm missing something here....

Re: Trojan found in Filezilla downloaded from SourceForge

#157

Something came up last time Sourceforge was discussed here, namely "why are projects still using it?"... I'm the project lead for LXQt ( http://lxqt.org ). We inherited some infrastructure legacy from LXDE, which was hosted on sourceforge. Today, we have moved most of the legacy to Github but we're still using Sourceforge's mailing list system. We're moving to a self-hosted mailman3 instance but it's been excruciatin…

"So I'm pitching this to bored devs and entrepreneurs: Help us, and many other projects, by creating a "Github for mailing lists" with a web client featuring a clean high quality UI, easily browsable/linkable archives, etc. Make it open source, make it self-hostable, stuff in enterprise support. Make it quick and easy to create new lists."

Uggh ... really ?

So the simple, clean, extremely fast loading HTML indexes of mailman/majordomo[1] aren't going to do it for you anymore ?

Yes, I was getting so tired of one click getting me to a nice, clean index, ordered by year and month, and loading near-instantly. What a pain that's always been.

Get. Off. My. Lawn.

[1] https://lists.freebsd.org/pipermail/freebsd-fs/

Re: Trojan found in Filezilla downloaded from SourceForge

#158

Earlier quoted context omitted.

It's usually hidden in the EULA. Very hidden. It's not just Filezilla or sourceforge doing this. Lenovo do this routinely. They used to bundle something called BrowserGuard, which contains a PUP by Conduit. Conduit have since been partially acquired by another company Perion. I followed that rabbit hole last year, Lenovo point blank refuse to acknowledge it is spyware. And it IS spyware. I created a Perion account to…

Good to know - I was almost ready to consider Lenovo again after Superfish, but no...

It’s similar shit with Dell.

At least Lenovo’s business lineup wasn’t affected.

Re: Trojan found in Filezilla downloaded from SourceForge

#159
post #48

Clicking on the download link ws blocked by ublock origin. Weird.

After the last Sourceforge malware-bundling debacle (Can't even remember who it was at this point--someone who said Sourceforge seized their repo from them and then repackaged it with malware), gorhill added Sourceforge to the uBlock blacklists. Good riddance, I say.

It was the GIMP guys, btw.

Re: Trojan found in Filezilla downloaded from SourceForge

#160
post #72
post #29

Earlier quoted context omitted.

FWIW, Google Groups powers email distribution lists for Gmail for Work. Or at least, the two are strongly linked. At this point, unlike Reader, there's real cash behind the functionality. It's possible they could just fold it into Gmail, I guess, but with other mail interfaces like Inbox popping up in the Google ecosystem it seems if anything they're trying not to shoehorn too much more into a flagship product. My gu…

As someone using Gmail for Work: This is one of the things I absolutely detest about Gmail for Work. The Groups interface is absolutely horrendous, and we don't want groups, we want simple email distribution lists.

Do you know if people can manage their subscriptions themselves? I seem to be able to add "Admins" to a group, but I don't know what that does.
Post reply on HN