It is currently Thu Mar 28, 2024 2:44 pm


All times are UTC - 5 hours [ DST ]



Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 43 posts ]  Go to page 1, 2, 3  Next
Author Message
 Post subject: Sourceforge Using ADs As Download Vectors For Malware
PostPosted: Mon Aug 19, 2013 7:41 am  (#1) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
GIMP Version: 2.8.4
Operating System: Windows
OS Version: Windows
GIMP Experience: Beginner Level



I want to recommend GIMP to Windows using friends, but it is not supported officially for Windows.
Even worse, the download link for the Windows build goes to an ad-driven filesharing site with ads masquerading as download buttons. A friend on mine clicked on one of these and her antivirus software went nuts!

This is a serious problem! Is there anything we can do to help? Does anyone know the dev for the Windows build? I will not be able to recommend GIMP to Windows using friends until that problem is solved! :gaah


Share on Facebook Share on Twitter Share on Orkut Share on Digg Share on MySpace Share on Delicious Share on Technorati
Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 7:44 am  (#2) 
Offline
GimpChat Member
User avatar

Joined: Aug 05, 2013
Posts: 46
Location: Germany
Uhm, whats the sites url? The official not-that-official builds for windows are here: Because of malware being found in SourceForge downloads, this link has been removed.


sf.net has ads, yes but there shouldn't be any harmful ads.

_________________
My Youtube Channel with Timelapse Videos: -> bloodywing1 :: My Facebook Page / Art with MyPaint and GIMP


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 7:51 am  (#3) 
Offline
Script Coder
User avatar

Joined: Apr 23, 2010
Posts: 1553
Location: not from Guildford after all
CRogers wrote:
Even worse, the download link for the Windows build goes to an ad-driven filesharing site with ads masquerading as download buttons. A friend on mine clicked on one of these and her antivirus software went nuts!

I Because of malware being found in SourceForge downloads, this link has been removed.
, let alone virus inducing ones. And this is the only link to a Windows installer from the GIMP.ORG website.

_________________
Any sufficiently primitive technology is indistinguishable from a rock.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:12 am  (#4) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
Yes, it's the source forge website. Brings up 4 ads, sometimes with big green download buttons (though no buttons are necessary)... when did source forge become such a spammy advert-ridden piece of crap? :P

They need a new host, asap!Image


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:18 am  (#5) 
Offline
GimpChat Member

Joined: Aug 05, 2011
Posts: 606
Location: limestone,ny
I'm not seeing any ads
Because of malware being found in SourceForge downloads, this link has been removed.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:22 am  (#6) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
alc59 wrote:
I'm not seeing any ads
Because of malware being found in SourceForge downloads, this link has been removed.

Click the download link.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:26 am  (#7) 
Offline
GimpChat Member

Joined: Aug 05, 2011
Posts: 606
Location: limestone,ny
I did

Image


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:27 am  (#8) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
No one here is clicking far enough. If you click on the download links off of the gimp branded pages you invariably get a page like this (sometimes FULL of fake download buttons):
Image


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:28 am  (#9) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
alc59 wrote:
I did

[ Image ]

Turn off your ad-blocker.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:30 am  (#10) 
Offline
GimpChat Member
User avatar

Joined: Nov 09, 2011
Posts: 726
If you do not have AdBlock enabled, in SourceForge are some ads after download. I do not know if any antivirus detects malicious code for Windows in any of this ads, I use GNU/Linux.
If the antivirus is alerting, you must report to SourceForge and your antivirus software to detect if it's a false positive.

Edit: Oh! Now I see one of those ads can be misleading with that big green "Download" button. That is a problem and that kind of ads should not be allowed on SourceForge.

_________________
Image
Be patient, English is not my language.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:40 am  (#11) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
YAFU wrote:
If you do not have AdBlock enabled, in SourceForge are some ads after download. I do not know if any antivirus detects malicious code for Windows in any of this ads, I use GNU/Linux.
If the antivirus is alerting, you must report to SourceForge and your antivirus software to detect if it's a false positive.

Edit: Oh! Now I see one of those ads can be misleading with that big green "Download" button. That is a problem and that kind of ads should not be allowed on SourceForge.


Yes, that's the real problem. :/ Even if they aren't viruses, the very nature of these ads is misleading, and could lead to the user installing something other than GIMP.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 8:53 am  (#12) 
Offline
GimpChat Member

Joined: Aug 05, 2011
Posts: 606
Location: limestone,ny
Seen this a while back on ghacks
SourceForge’s new Installer bundles program downloads with adware


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 9:04 am  (#13) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
alc59 wrote:


That's unacceptable! D:<


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 9:19 am  (#14) 
Offline
Global Moderator
User avatar

Joined: Nov 16, 2011
Posts: 5128
Location: Metro Vancouver, BC
I noticed their is a normal download for Gimp 2.8.
Because of malware being found in SourceForge downloads, this link has been removed.


There is another entry for just 'Gimp'.
Because of malware being found in SourceForge downloads, this link has been removed.

This one contains no download files.
This entry could easily confuse someone into using one of the fake download buttons on the page.

Image

Image

_________________
Image
Gimp 2.8.18, Linux, median user
Gimp Chat Tutorials Index
Spirit Bear (Kermode)


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 9:27 am  (#15) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
Odinbc wrote:
I noticed their is a normal download for Gimp 2.8.
Because of malware being found in SourceForge downloads, this link has been removed.


There is another entry for just 'Gimp'.
Because of malware being found in SourceForge downloads, this link has been removed.

This one contains no download files.
This entry could easily confuse someone into using one of the fake download buttons on the page.


That's the Ubuntu version page. What I'm talking about is the Windows download page. And yes, that confusion is the main probably
I gave a co-worker the gimp.org link, and she came back to me today very angry. I don't blame her. If that was my first encounter with Open Source software, I probably wouldn't come back.

I'm so upset I could break things. :P


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 9:46 am  (#16) 
Offline
GimpChat Member
User avatar

Joined: Nov 09, 2011
Posts: 726
@CRogers, you could send an email to the developers mailing list to pose your concerns to be discussed. Perhaps also you can indicate this gimpchat link.
This is the mail address:
https://mail.gnome.org/mailman/listinfo ... loper-list

Please, be nice in your message :)

_________________
Image
Be patient, English is not my language.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 9:55 am  (#17) 
Offline
GimpChat Member

Joined: Aug 15, 2013
Posts: 125
YAFU wrote:
@CRogers, you could send an email to the developers mailing list to pose your concerns to be discussed. Perhaps also you can indicate this gimpchat link.
This is the mail address:
https://mail.gnome.org/mailman/listinfo ... loper-list

Please, be nice in your message :)


Thanks for the info. Yes, I'll be nice. I wouldn't assume it's the developer's fault anyway.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 10:09 am  (#18) 
Offline
GimpChat Member
User avatar

Joined: Sep 24, 2010
Posts: 12513
Just click the link from the main page and it will not give you span hopfully. :)


Attachments:
Clipboard01.png
Clipboard01.png [ 53.09 KiB | Viewed 3462 times ]

_________________
Lyle

Psalm 109:8

Image
Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 10:10 am  (#19) 
Offline
GimpChat Member
User avatar

Joined: Nov 09, 2011
Posts: 726
I really do not know where would be best to to pose the problem, whether developers or GIMP Web List:
https://mail.gnome.org/mailman/listinfo/gimp-web-list
I know the developers list is more active.

_________________
Image
Be patient, English is not my language.


Top
 Post subject: Re: GIMP currently being used as virus bait
PostPosted: Mon Aug 19, 2013 10:52 am  (#20) 
Offline
Global Moderator
User avatar

Joined: Nov 16, 2011
Posts: 5128
Location: Metro Vancouver, BC
The SourceForge Installer is not in all Windows downloads from SourceForge.
Is there any evidence that the Because of malware being found in SourceForge downloads, this link has been removed.
download uses it?

_________________
Image
Gimp 2.8.18, Linux, median user
Gimp Chat Tutorials Index
Spirit Bear (Kermode)


Top
Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 43 posts ]  Go to page 1, 2, 3  Next

All times are UTC - 5 hours [ DST ]


   Similar Topics   Replies 
No new posts Beware of fake GIMP sites that distribute malware

4

No new posts Attachment(s) Double Curve Bend using paths/vectors

6

No new posts Attachment(s) A little Subroutine to build Means between two Dimensional Vectors

2

No new posts 3rd Toolbox disappeared after download

7

No new posts photo download failure

4



* Login  



Powered by phpBB3 © phpBB Group