Live data from Hacker News

Non-official site with a tampered version of KeePass

security.infoteam.ch

11–20 of 82 posts

Re: Non-official site with a tampered version of KeePass

#13
post #2

Who did this without thinking about an exfiltration tool instead?

I thought this too. Obviously not a very creative use of the domain squat. Worth reading:

- https://en.wikipedia.org/wiki/Cybersquatting

- https://en.wikipedia.org/wiki/Brandjacking

Re: Non-official site with a tampered version of KeePass

#17
post #15

What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.

pup bundlers also tend to be signed. just checking for a valid signature would not be enough

Re: Non-official site with a tampered version of KeePass

#18
post #8

I'm getting a different installer file from this website with not as many ad bundles detected : https://www.virustotal.com/#/file/23c3a4564265bc996ab61c1227... Anyway, this wouldn't be the first time an open source software is packaged with some adware. Unsavory, but I think within the limits of the license.

seems to be just another bundler from the same network (installcore), but packed with a different exe packer

Re: Non-official site with a tampered version of KeePass

#19
post #15

What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.

Sourceforge is under new management and they removed the bundled installers, as I understand it.

https://sourceforge.net/blog/brief-history-sourceforge-look-...

Re: Non-official site with a tampered version of KeePass

#20
post #14

Hah, the Linux version points you to the original website (only the Mac and Windows versions appear to be modified)! The year of the Linux desktop is truly here.

doesnt that just imply that these scammers thought the linux userbase to be too small to be worthwhile?

the comparatively small userbase is actually an underappreciated security feature of linux ;)

Post reply on HN