Live data from Hacker News

Non-official site with a tampered version of KeePass

security.infoteam.ch

61–70 of 82 posts

Re: Non-official site with a tampered version of KeePass

#61
post #57

There are quite a few of these: https://keepass.fr/ https://7zip.fr https://audacity.fr https://gparted.fr https://keepass.fr https://nc3354.nexylan.net https://paintnet.fr

Thanks for the update, they all look to come from the same guys.

They do. They're all registered via one email: https://domainbigdata.com/gmail.com/mj/0DnwUjDWo0L7ysS4kB00p...

Re: Non-official site with a tampered version of KeePass

#63
post #51

I've had discussions with coworkers on why you shouldn't ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads now , but imho it's just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned

Rather unfortunate that "putty.org" is the first result in searches and looks a lot more legit than "chiark.greenend.org.uk" even if it (currently) links there. I've had discussions with coworkers on why they shouldn't look up "free online json beautifier" and dump thousands of lines of crown jewels into them (http too). Meanwhile we're doing web dev and JSON responses are autoformatted in Firefox dev tools so there'…

Show your coworkers jq, it is amazing:

https://stedolan.github.io/jq/

Re: Non-official site with a tampered version of KeePass

#64
post #51

I've had discussions with coworkers on why you shouldn't ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads now , but imho it's just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned

Rather unfortunate that "putty.org" is the first result in searches and looks a lot more legit than "chiark.greenend.org.uk" even if it (currently) links there. I've had discussions with coworkers on why they shouldn't look up "free online json beautifier" and dump thousands of lines of crown jewels into them (http too). Meanwhile we're doing web dev and JSON responses are autoformatted in Firefox dev tools so there'…

It's putty's own fault. They used to (and perhaps still do) have a section on how they don't want your donated domain - they like their current one.

From their FAQ:

> No, thank you. Even if you can find one (most of them seem to have been registered already, by people who didn't ask whether we actually wanted it before they applied), we're happy with the PuTTY web site being exactly where it is. It's not hard to find (just type ‘putty’ into google.com and we're the first link returned), and we don't believe the administrative hassle of moving the site would be worth the benefit.

Re: Non-official site with a tampered version of KeePass

#65
post #51

I've had discussions with coworkers on why you shouldn't ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads now , but imho it's just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned

Windows 10 has real OpenSSH ssh installed by default now (since April). The time for PuTTY has passed. May it rest in peace.

Re: Non-official site with a tampered version of KeePass

#66
post #38
post #20

Earlier quoted context omitted.

doesnt that just imply that these scammers thought the linux userbase to be too small to be worthwhile? the comparatively small userbase is actually an underappreciated security feature of linux ;)

Or that Linux users would instantly raise a hue and cry on seeing ads?

Kind of like how scammers use bad grammar on purpose to weed out the people too smart to be a victim.

Re: Non-official site with a tampered version of KeePass

#67
post #49

Earlier quoted context omitted.

In a perfect world I would love to, but every time I've tried to submit improvements to open-source software I've come out extremely frustrated with how many hoops I have to jump through just to get my code properly considered, let alone merged. Half the time the developers are extremely resistant to changes and believe the change is wrong/unnecessary, or the current state is already correct, or that the changes are…

> their upstream code is responsible Then you're not going to the good people. Stop going through intermediaries, go straight for the source (package specific issues on Ubuntu must be reported to Ubuntu -like python not recognizing a new module-, but bad code inside the package must be dealt with with upstream). > Half the time the developers are extremely resistant to changes and believe the change is wrong/unnecess…

I assure you I'm not naively just dumping code on random developers and telling them to merge it. I do talk to them first, that's exactly how I figure out they think their code is fine and my changes are unwelcome whenever that's the case. (Edit: Well, mostly. It's also happened that my changes were rejected after I made the patch, but that was nevertheless after discussions had already taken place. Like when I said they later decide the patch is too big.) And regarding the upstream project issue: in the case I had in mind, the upstream project had its own reasons for not doing things the way I mentioned. The changes really did belong in the downstream project, but the downstream guy just didn't care to have to maintain the changes. Although, I also have to point out that upstream projects tend to present even more obstacles for merging code -- not only when the entire reason there's a downstream fork is that upstream is not going to support the entire platform/architecture/whatever, but also when they're big projects with their own hoops I don't care to jump through on my end as I explained earlier.

Re: Non-official site with a tampered version of KeePass

#68

Earlier quoted context omitted.

> That was worded a bit ambiguously then Sorry, I hope it's clear now. > You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced Huh? This is obviously wrong; I'm doing literally this with KeePass. I haven't installed anything, and it has a plugin to sync directly with Google Drive that doesn't mess with or care about anything in the rest of…

So then you have installed a Google drive agent, or at least you use the service? That is the problem you're discussing.

I don't follow you. I use Google Drive, and I don't install additional software on the OS. I just sync with it directly using KeePass. There is no "problem". It works just just fine.

Re: Non-official site with a tampered version of KeePass

#69
post #38

Earlier quoted context omitted.

Or that Linux users would instantly raise a hue and cry on seeing ads?

Kind of like how scammers use bad grammar on purpose to weed out the people too smart to be a victim.

Yes, now that you mention it - they deliberately tried to design their dragnet to exclude victims who were likely to be problematic. :)

Re: Non-official site with a tampered version of KeePass

#70

There are quite a few of these: https://keepass.fr/ https://7zip.fr https://audacity.fr https://gparted.fr https://keepass.fr https://nc3354.nexylan.net https://paintnet.fr

So, basically somebody went through the list of all tools most commonly installed trough ninite, and created a spoof for each of them.
Post reply on HN