Fosshub downloads compromised

Fosshub downloads compromised.

ghacks.net/2016/08/03/attention-fosshub-downloads-compromised/

Other urls found in this thread:

youtube.com/watch?v=DD9CvHVU7B4
twitter.com/CultOfRazer/status/760749305598705664
cvedetails.com/top-50-vendors.php
virustotal.com/en/file/a848bf24651421fbcd15c7e44f80bb87cbacd2599eb86508829537693359e032/analysis/1470182253/
qbforums.shiki.hu/index.php/topic,4474.0.html
sourceforge.net/projects/qbittorrent/files/qbittorrent-win32/qbittorrent-3.3.6/qbittorrent_3.3.6_setup.exe/download
twitter.com/SFWRedditGifs

STALLEDtorrent confirmed Bitcoin miner!

>AS YOU REBOOT, YOU FIND THAT SOMETHING HAS OVERWRITTEN YOUR MNR !
FUCK WHATS A GOOD ANTIVIRUS FOR MY MNR i use windows 10 btw

I downloaded qb 3.3.6 last week and no malware or suspicious activity, when did this start?

Tonight. There was a thread earlier with someone whose new Classic Shell overwrote their MBR.
Downloads are just being replaced with a 35K exe, so it's not like the programs are being replaced with a rooted version or anything.

freetards on suicide watch xD

>using freetard sofware
>ever

lmao, that's what you get lincucks,

>windows 10

welp, found your problem.

They still haven't fixed their fucking downloads

youtube.com/watch?v=DD9CvHVU7B4

>using freetard site
>downloading freetard shit
>getting miners,ransomwares and other kinds of viruses

>got qb in July

Thank God.

Wew good thing they have a Sourceforge link so I can update it.

>freetards in charge of security
Say what you want about proprietary software from huge companies like Microsoft, but at least you know it's secure.

Download from their official website.

Why cant freetards do security?

twitter.com/CultOfRazer/status/760749305598705664

AAAAAAAAAHHHHHHHHHH FUCK I JUST GOT AUDACITY FROM THERE

WHAT DO I DOOOO?

JUST

FOSS MY SHIT UP

So, if Microsoft or Apple say that their OS is secure, you're just going to take their word for it? That's really the only thing you can do, since you don't even have the changelogs of so called security updates. And let's see what security researchers say about the security of your favorite freeā„¢ OS:
cvedetails.com/top-50-vendors.php

Are you fucking retarded? They aren't "freetards" just because they run an open source mirror. They even host proprietary software on their website.

I know these are just shitposts after shitposts, but if you're so concerned about security, why are you even downloading software (that you don't have to pay for) through anything rather than the official sites?

>implying 'freetards' get their software from this website instead of retarded winbabies

First of all, we don't use windows, and second, we either get our software from our distros repos or we get it from the source

most foss actually use fosshub as their main host for example audacity

Is this detectable by Anti Virus?

Bit Defender. It ranks high in detection and low resource usage.

>>Is this detectable by Anti Virus?
Only AVG, Kaspersky, and AegisLab caught it.

FOSS HUB CURRENTLY DOWN

FOSS HUB ON SUICIDE WATCH

Audacity uses Fosshub, but the majority of Foss projects are either hosted on github, or on sourceforge.

Why the fuck would you download software fr that POS instead of your repository?

Classic Shell isn't found in any repo, of course.

Fosstards, do you ever get tired of being btfo?

Using Classic Shell 4.2.5c Hope it's not compromised.

I thought Windows had its own repo. NuGet or something.

What's the name of the virus?

Just 4.3.0 as far as we know

ClassicShellSetup_4_2_5c.exe
6.64MB
SHA256: 46139997048f4f41926398910ed3164be29190046c7ecfbea98607ac51aa515e

Did a test and it's safe, so it must be the 4.3.0 as you say.

No idea. Those three caught it generically.

So Foss Hubb just took down their site so basically any hash could be false.

memeware.exe

Found it: virustotal.com/en/file/a848bf24651421fbcd15c7e44f80bb87cbacd2599eb86508829537693359e032/analysis/1470182253/

>freetards use windows
Nice misdirection paj, enjoy your malware

>using freetard junk
you get what you pay for :^)

Funny that I downloaded Audacity just yesterday from Fosshub.
Lucky me I downloaded the portable version which seems to be virus free.

Good thing i've never used that site.

Windows 10 is free faggot
Enjoy your ads or subscription
>just install classic shell and you don't have ads
you got cucked

>qbforums.shiki.hu/index.php/topic,4474.0.html

>Yeah but I meant it like... fosshub is a "good" site.
>It's not Facebook, it's not some evil site, not some organization, business, whatever.
>It's actually a site that offers free downloads for free software with no strings attached.

>Why would you even target that?
Makes no sense...

What a moron.

I can't blame them, wincucks deserve all the ads

>use Windows 10 bro it's much more secure
>just use classic shell if you dislike the UI

AHHAHAHAHAHAHAHA

i installed qbittorent from ninite, am i safe?

Nope.

Who gives a shit, you cannot get viruses if you just use common sense.

KeK

Good thing my stalledbittorrent version is old as fuck.
Next you're going to tell me someone put a bitcoinminer on the latest winamp. I haven't updated my installer in 14 years.

sourceforge.net/projects/qbittorrent/files/qbittorrent-win32/qbittorrent-3.3.6/qbittorrent_3.3.6_setup.exe/download
Why?

why doesn't qbitorrent distribute itself using magnet links? yeah I know you'd need a torrent client for that, but for updates it makes a lot of sense

That's kinda like using IE / EDGE to get FF or something

What the hell is this and why have a load of mouth-breathers downloaded it?

Reminder: Even legit sites can get hit or haxored occasionally.

1. Download portable editions if possible
2. Verify CHECKSUM, the highest given
3. jotti or virustotal
4. ?????
5. something happened

It's not like we warned you about the fosshub meme or anything.

This legitimately made me laugh.

Oh boy, it's real.

kek'd heartily

Finding exploits don't matter so long as they are promptly fixed when identified.

>common sense
>that one useful piece of software you've safety installed many times in the past now requires "common sense" to know if it's bundled with malware

Good bait.

>ITT fags who dont have virtualized test environments

>I am a moron that disabled UAC because /g

>he thinks UAC will warn him if he's about to install malware infested software

>Donwloads and runs ClassicShell setup
>unsigned UAC says if I want to destroy my MBR
>UAC is not useful

UAC DID WARN FAGGOTS THAT THE FAKE INSTALLER WASN'T SIGNED, MORON

THEY JUST SKIPPED THE WARNING FAGGOT

MICROSOFT DID ITS PART TO PROTECT THE USERS

prove it

wtf is fosshub?

hahahahahahahahahaha

a
haha
h
a
h
a
ha
h
ah
a


IT'S FUCKING REAL

Finally those run everything as admin disable UAC kids get what they deserve.

This.

I feel sad for ClasicShell developer because the damage has been dramatic and he will be sued for sure.

>AS YOU REBOOT, YOU FIND THAT SOMETHING HAS OVERWRITTEN YOUR MBR !
>IT IS A SAD THING YOUR ADVENTURES HAVE ENDED HERE

Bitch I fucked up my MBR shittons on times installing testing builds of Linux distros while multi booting with Windows. Shit takes me 5 mins to fix.

Pajeet-tier virus confirmed.