Live data from Hacker News

7zip.com Is Serving Malware

malwarebytes.com

81–90 of 104 posts

Re: 7zip.com Is Serving Malware

#81
post #15

Earlier quoted context omitted.

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

How would you ensure that the "average user" actually gets to the page he expects to get to? There are risks in everything you do. If the average user doesn't know where the application he wants to download _actually_ comes from then maybe the average user shouldn't use the internet at all?

> How would you ensure that the "average user" actually gets to the page he expects to get to?

I think you practically can't and that's the problem.

TLS doesn't help with figuring out which page is the real one, EV certs never really caught on and most financial incentives make such mechanisms unviable. Same for additional sources of information like Wikipedia, since that just shifts the burden of combatting misinformation on the editors there and not every project matters enought to have a page. You could use an OS with a package manager, but not all software is packaged like that and that doesn't immediately make it immune to takeovers or bad actors.

An unreasonable take would be:

> A set of government run repositories and mirrors under a new TLD which is not allowed for anything other than hosting software packages, similar to how .gov ones already owrk - be it through package manager repositories or websites. Only source can be submitted by developers, who also need their ID verified and need to sign every release, it then gets reviewed by the employees and is only published after automated checks as well. Anyone who tries funny business, goes to jail. The unfortunate side effect is that you now live in a dystopia and go to jail anyways.

A more reasonable take would be that it's not something you can solve easily.

> If the average user doesn't know where the application he wants to download _actually_ comes from then maybe the average user shouldn't use the internet at all?

People die in car crashes. We can't eliminate those altogether, but at least we can take steps towards making things better, instead of telling them that maybe they should just not drive. Tough problems regardless.

Re: 7zip.com Is Serving Malware

#82
post #29

Earlier quoted context omitted.

There is normally a wiki page for every popular program which normally contains an official site URL. That's how I remember where to actually get PuTTY. Wiki can potentially be abused if it's a lesser known software, but, in general, it's a good indicator of legitimacy.

So wikipedia is now part of the supply chain (informally) which means there is another set of people who will try to hijack Wikipedia, as if we didn't had enough, just great.

You can corroborate multiple trusted sources, especially those with histories. You can check the edit history of the Wikipedia article. Also, if you search "7zip" on HN, the second result with loads of votes and comments is 7-zip.org. Another is searching the Archlinux package repos; you can check the git history of the package build files to see where it's gotten the source from.

Re: 7zip.com Is Serving Malware

#83
post #15

Earlier quoted context omitted.

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

> How can the average 7zip user know which one it is? I dunno, if you type "download 7zip" into Google, the top result is the official website. Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website. This is actually a pretty good case of the regular user being pretty safe from downloading malware.

[deleted]

Re: 7zip.com Is Serving Malware

#84

I tested with the 3 major browsers and all 3 block it as "Suspected Phishing". So looks like the system is working as designed. Lookalike websites serving malware have always existed. So this isn't exactly news. But the browsers are blocking them like they should.

Yes, and I think this case gets somewhat more notoriety because the phishing site has the .com domain and the legitimate one has a .org.

Like it or not, .com adds perceived trustworthiness and works as a branding signal, especially in these times of VCs throwing large amounts of money at branding and buying 3 to 6 letter .com domains, but a small project like 7zip cannot afford that kind of expense.

Re: 7zip.com Is Serving Malware

#85
post #15
post #6

7zip.com has never been the official website of the project. It's been 7-zip.org

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

Avoid downloading stuff of internet and avoid search engines.

In a post AI world asking how not be scammed is hard cause now everything can be faked.

Trust what you definitely know but still verify.

Especially in the next 5-10 years that's going to become the reality so I guess sit tight and prepare for the waves and sunamis of scams.

Re: 7zip.com Is Serving Malware

#86
post #61
post #39

I've started using winget to install my apps for exactly this reason. I can't keep track of every url for every piece of software.

Is that safe? Microsoft's policy [1] seems to say that anyone can publish an update to a package as long as it passes "an automated process" which checks that it's "not known to be malicious". [1] https://learn.microsoft.com/en-us/windows/package-manager/pa...

It would have prevented both this 7zip attach and the recent notepad++ one.

Re: 7zip.com Is Serving Malware

#87
post #82

Earlier quoted context omitted.

So wikipedia is now part of the supply chain (informally) which means there is another set of people who will try to hijack Wikipedia, as if we didn't had enough, just great.

You can corroborate multiple trusted sources, especially those with histories. You can check the edit history of the Wikipedia article. Also, if you search "7zip" on HN, the second result with loads of votes and comments is 7-zip.org. Another is searching the Archlinux package repos; you can check the git history of the package build files to see where it's gotten the source from.

And we're really going to do all the brouhaha for a single dl of an alternative compressor ? And then multiple that work as a best practice for every single interaction on the Internet? No we're not.

Re: 7zip.com Is Serving Malware

#88
It says the code signing cert has been revoked by now.

How does verification work? Only at installation time or will it prevent running the installed files later if installation happened when the cert was still accepted?

Linux user asking out of curiousity...

Re: 7zip.com Is Serving Malware

#89

Earlier quoted context omitted.

> How can the average 7zip user know which one it is? I dunno, if you type "download 7zip" into Google, the top result is the official website. Also, 7zip.com is nowhere on the first page, and the most common browsers show you explicitly it's a phishing website. This is actually a pretty good case of the regular user being pretty safe from downloading malware.

> Also, 7zip.com is nowhere on the first page In incognito window, for me, it's 3rd result

It's possible, although I can't replicate this result anymore.

On google search I don't see it on the first page, and the only sketchy link on page 2 is https://7zip.dev/en/download/.

Bing is worse, since it shows 7zip.com on the 2nd page, but the site refuses to load.

But I am using Thorium with manifest v2 ublock and Edge with medium setting for tracker/ad block.

Re: 7zip.com Is Serving Malware

#90
post #82

Earlier quoted context omitted.

You can corroborate multiple trusted sources, especially those with histories. You can check the edit history of the Wikipedia article. Also, if you search "7zip" on HN, the second result with loads of votes and comments is 7-zip.org. Another is searching the Archlinux package repos; you can check the git history of the package build files to see where it's gotten the source from.

And we're really going to do all the brouhaha for a single dl of an alternative compressor ? And then multiple that work as a best practice for every single interaction on the Internet? No we're not.

The dl for some programs are often on some subdomain page with like 2 lines of text and 10 dl links for binaries, even for official programs. Its so hard to know whether they are legit or not.
Post reply on HN