Author Topic: SourceForge takes over projects; injects malware?!  (Read 1242 times)

0 Members and 1 Guest are viewing this topic.

Offline jr2

  • The Mail Man
  • 212
  • It's prounounced jayartoo 0x6A7232
    • Steam
SourceForge takes over projects; injects malware?!
Unsure if this is as bad as it seems, but:

http://seclists.org/nmap-dev/2015/q2/194

The comments on reddit have links to compromised projects.

http://reddit.com/r/technology/comments/38dnue/sourceforge_has_begun_hijacking_popular_accounts/


Shorter list of more recognizable ones:

openoffice, audacity, fedora, firefox, gimp, gnu privacy guard, joomla, libre office, multiwii, neverball, nmap, sqlite, simulationcraft, snort, texworks, transmission, vlc media player, wordpress, recaptcha, apache, mame, mysql, thunderbird

So be sure to get those goodies from another source. :ick:  (alternatives mentioned in the reddit comments)

  

Offline Bobboau

  • Just a MODern kinda guy
    Just MODerately cool
    And MODest too
  • 213
Re: SourceForge takes over projects; injects malware?!
yeah, and the same company owns slashdot and has been censoring any news of this for a while (oh wait, they aren't a government, I guess this is just fine). Also, some of the affiliated projects are complicit, like filezilla, they have received complaints about this and have been like "tough ****"

related article: http://arstechnica.com/information-technology/2015/06/sourceforge-locked-in-projects-of-fleeing-users-cashed-in-on-malvertising/

I don't get why anyone was still using them as of four years ago, github had them beat on all fronts.
« Last Edit: June 04, 2015, 08:43:52 am by Bobboau »
Bobboau, bringing you products that work... in theory
learn to use PCS
creator of the ProXimus Procedural Texture and Effect Generator
My latest build of PCS2, get it while it's hot!
PCS 2.0.3


DEUTERONOMY 22:11
Thou shalt not wear a garment of diverse sorts, [as] of woollen and linen together