Live data from Hacker News

Sourceforge Hijacks the Nmap Sourceforge Account

seclists.org

51–60 of 201 posts

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#51

If your old account is listed here, you getting fuxxored: http://sourceforge.net/u/sf-editor1/profile/ http://sourceforge.net/u/sf-editor2/profile/ http://sourceforge.net/u/sf-editor3/profile/ Edit: added http://sourceforge.net/u/sf-editor/profile/ which includes MySQL and a few other high profile projects.

Damn, that's a lot of projects.

OpenOffice, Apache server, hadoop, Audacity, CDex, Colloquy, that's all projects I have at one at my computers, and I haven't gotten to "D" yet.

This is depressing

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#53
post #4
post #2

How to literally kill your company: 1. this

The company is already dead. This is simply looting the corps.

Nice, hopefully intentional, typo ;)

However, are SF really making money from these mirrors? As I understand it from other comments here, you can still download the tarballs, and they seem more 'official' that the non mirror-suffixed accounts? When does mirroring become bad practice, what is the line you need to cross?

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#55

Earlier quoted context omitted.

Plenty popular names on there. That's shocking.

To be clear - there is a difference between mirroring (which is good netizen behavior, and to be complimented), and trojaning (which is modifying the upstream sources before delivering them to users - which is decidedly not good netizen behavior). It's important to understand which is which for those accounts.

As long as one of those accounts is trojaning (or even just suspected of possibly having been trojaning once) it instantly poisons all the mirrors. Even if they are perfect netizens 99% of the time, that 1% makes all their other efforts useless.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#56

In spite of account hijacking, GIMP was still downloaded by almost 15k people this week. Six days ago they took over Audacity project as well, which was downloaded by more than 150k this week[0]. [0] http://sourceforge.net/projects/audacity/

What will happen if I run Audacity installer from sourceforge? I have done that an hour ago. Should I be concerned?

If you have ignored the crapware dialogs of the installer, you should be. But even then there is no telling what they could install without prompting first.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#58

This is the sort of behavior you get from a company that's lost, and is now trying to extract every penny they can from whatever shenanigans they can get away with. If they have no future brand value to be concerned about, then, from a game-theoretic approach, it's actually a pretty rational profit seeking move. (As long as they don't incur any downstream liabilities from outright illegal activity for which they migh…

The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.

No it isn't. The site was relevant before as it served what people needed, and was ranked high. It no longer is serving folks' interests, so it can be ranked lower, or de-listed. Completely fine.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#59

Earlier quoted context omitted.

Plenty popular names on there. That's shocking.

To be clear - there is a difference between mirroring (which is good netizen behavior, and to be complimented), and trojaning (which is modifying the upstream sources before delivering them to users - which is decidedly not good netizen behavior). It's important to understand which is which for those accounts.

No, it is not important at all - because today's mirror will silently be replaced with tomorrow's trojan.

It is important to expose this behavior for what it is.

And in the process, remind everyone that abuse of power is a question of WHEN, not IF, whether it's a government entity or a corporate one.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#60

This is the sort of behavior you get from a company that's lost, and is now trying to extract every penny they can from whatever shenanigans they can get away with. If they have no future brand value to be concerned about, then, from a game-theoretic approach, it's actually a pretty rational profit seeking move. (As long as they don't incur any downstream liabilities from outright illegal activity for which they migh…

The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.

Patio11 suggested that in relatoin to Gimp. Also, someone helpfully posted the google link to report websites:

https://www.google.com/safebrowsing/report_badware/

Suggested reason is "embeds malware/adware with downloads".

Post reply on HN