PC Review


Reply
Thread Tools Rate Thread

Cnet is accused of bundling malware with downloads

 
 
Virus Guy
Guest
Posts: n/a
 
      7th Dec 2011
Cnet is accused of bundling malware with downloads

http://www.theinquirer.net/inquirer/...ware-downloads

The down low on low down Cnet downloads
By Dave Neal
Tue Dec 06 2011, 12:12

TECHNOLOGY PUBLISHER Cnet has been accused of bundling malware with the
security scanning software Nmap through its Downloads web site.

The accusation comes from the creator of Nmap, who in a forum post on
the Seclists.org web site chose not to mince his words.

"I've just discovered that C|Net's Download.Com site has started
wrapping their Nmap downloads (as well as other free software like VLC)
in a trojan installer which does things like installing a sketchy
'StartNow' toolbar, changing the user's default search engine to
Microsoft Bing, and changing their home page to Microsoft's MSN," wrote
Gordon 'Fyodor' Lyon in his post.

"The way it works is that C|Net's download page offers what they claim
to be Nmap's Windows installer. They even provide the correct file size
for our official installer. But users actually get a Cnet-created trojan
installer. That program does the dirty work before downloading and
executing Nmap's real installer."

People trust the web site, he added, and so are happy to click through
its installer screens, which they do at their own cost.

"Then the next time the user opens their browser, they find that their
computer is hosed with crappy toolbars, Bing searches, Microsoft as
their home page, and whatever other shenanigans the software performs!,"
he added. "The worst thing is that users will think we (Nmap Project)
did this to them!"

This is bad for users, he explained, but it's also bad for his Nmap
Project since allegedly Cnet is misusing its trademark to shill the
malware, and could be violating copyright laws.

"Note how they use our registered 'Nmap' trademark in big letters right
above the malware 'special offer' as if we somehow endorsed or allowed
this. Of course they also violated our trademark by claiming this
download is an Nmap installer when we have nothing to do with the
proprietary trojan installer," he added.

"We've long known that malicious parties might try to distribute a
trojan Nmap installer, but we never thought it would be C|Net's
Download.com, which is owned by CBS! And we never thought Microsoft
would be sponsoring this activity!"

Lyon added that once the Trojan Cnet executable is unpacked it is
detected as malware by Panda, McAfee and F-Secure.

Meanwhile Graham Cluley, security expert and blogger for Sophos in the
UK, expressed his surprise on Twitter, saying, "What on earth is CNET
playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"

Lyon is perhaps understandably annoyed by his failed attempts to resolve
the situation amicably with Cnet. "F*ck them!" he added. "If anyone
knows a great copyright attorney in the U.S., please send me the details
or ask them to get in touch with me."

We've asked Cnet to comment on the allegations. µ
 
Reply With Quote
 
 
 
 
G. Morgan
Guest
Posts: n/a
 
      7th Dec 2011
Virus Guy wrote:

>Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"


I broke this story months ago and provided a homemade video on how to
get around it. The AV companies and software distributors are just now
acknowledging it?

--

"I don't like to discriminate against terrorists based on nationality.
If you declare war on the United States and you want to kill us,
We're going to kill you first, period."

October 19, 2011 - Ali Soufan (Colbert Report)


 
Reply With Quote
 
~BD~
Guest
Posts: n/a
 
      7th Dec 2011
G. Morgan wrote:
> Virus Guy wrote:
>
>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"

>
> I broke this story months ago and provided a homemade video on how to
> get around it. The AV companies and software distributors are just now
> acknowledging it?
>


Is your video on YouTube or similar, Graham?

May one take a peek? If so, a link please! :-)
 
Reply With Quote
 
G. Morgan
Guest
Posts: n/a
 
      7th Dec 2011
~BD~ wrote:

>G. Morgan wrote:
>> Virus Guy wrote:
>>
>>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"

>>
>> I broke this story months ago and provided a homemade video on how to
>> get around it. The AV companies and software distributors are just now
>> acknowledging it?
>>

>
>Is your video on YouTube or similar, Graham?
>
>May one take a peek? If so, a link please! :-)


http://groups.google.com/group/alt.c...a6b121ee?hl=en

--

"I don't like to discriminate against terrorists based on nationality.
If you declare war on the United States and you want to kill us,
We're going to kill you first, period."

October 19, 2011 - Ali Soufan (Colbert Report)


 
Reply With Quote
 
~BD~
Guest
Posts: n/a
 
      7th Dec 2011
G. Morgan wrote:
> ~BD~ wrote:
>
>> G. Morgan wrote:
>>> Virus Guy wrote:
>>>
>>>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>>>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>>>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"
>>>
>>> I broke this story months ago and provided a homemade video on how to
>>> get around it. The AV companies and software distributors are just now
>>> acknowledging it?
>>>

>>
>> Is your video on YouTube or similar, Graham?
>>
>> May one take a peek? If so, a link please! :-)

>
> http://groups.google.com/group/alt.c...a6b121ee?hl=en



Thank you! :-)

Great desktop piccie too - I somehow doubt that you took it yourself!
 
Reply With Quote
 
G. Morgan
Guest
Posts: n/a
 
      7th Dec 2011
~BD~ wrote:

>G. Morgan wrote:
>> ~BD~ wrote:
>>
>>> G. Morgan wrote:
>>>> Virus Guy wrote:
>>>>
>>>>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>>>>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>>>>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"
>>>>
>>>> I broke this story months ago and provided a homemade video on how to
>>>> get around it. The AV companies and software distributors are just now
>>>> acknowledging it?
>>>>
>>>
>>> Is your video on YouTube or similar, Graham?
>>>
>>> May one take a peek? If so, a link please! :-)

>>
>> http://groups.google.com/group/alt.c...a6b121ee?hl=en

>
>
>Thank you! :-)
>
>Great desktop piccie too - I somehow doubt that you took it yourself!


Nah, someone posted a link to it on a newsgroup and I liked it. I'm back
to a plain solid color now.

--

"I don't like to discriminate against terrorists based on nationality.
If you declare war on the United States and you want to kill us,
We're going to kill you first, period."

October 19, 2011 - Ali Soufan (Colbert Report)


 
Reply With Quote
 
~BD~
Guest
Posts: n/a
 
      7th Dec 2011
G. Morgan wrote:
> ~BD~ wrote:
>
>> G. Morgan wrote:
>>> ~BD~ wrote:
>>>
>>>> G. Morgan wrote:
>>>>> Virus Guy wrote:
>>>>>
>>>>>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>>>>>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>>>>>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"
>>>>>
>>>>> I broke this story months ago and provided a homemade video on how to
>>>>> get around it. The AV companies and software distributors are just now
>>>>> acknowledging it?
>>>>>
>>>>
>>>> Is your video on YouTube or similar, Graham?
>>>>
>>>> May one take a peek? If so, a link please! :-)
>>>
>>> http://groups.google.com/group/alt.c...a6b121ee?hl=en

>>
>>
>> Thank you! :-)
>>
>> Great desktop piccie too - I somehow doubt that you took it yourself!

>
> Nah, someone posted a link to it on a newsgroup and I liked it. I'm back
> to a plain solid color now.
>


It's nice that one may change things whenever one wishes!

I should also have said that I enjoyed your video. You were certainly
ahead of the game! Well done! :-)

OT - are you still having trouble sleeping, Graham?
 
Reply With Quote
 
G. Morgan
Guest
Posts: n/a
 
      7th Dec 2011
~BD~ wrote:


>I should also have said that I enjoyed your video. You were certainly
>ahead of the game! Well done! :-)


Thanks

>OT - are you still having trouble sleeping, Graham?


Not exactly, just sleeping at appropriate hours is the problem! My back
is all ****ed up again. I'm supposed to go for some physical therapy
that my doctor recommended, but I can't seem to get it scheduled at 3
am.

--

"I don't like to discriminate against terrorists based on nationality.
If you declare war on the United States and you want to kill us,
We're going to kill you first, period."

October 19, 2011 - Ali Soufan (Colbert Report)


 
Reply With Quote
 
Nemo
Guest
Posts: n/a
 
      7th Dec 2011
On 07/12/2011 05:38, G. Morgan wrote:
> Virus Guy wrote:
>
>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"

>
> I broke this story months ago and provided a homemade video on how to
> get around it. The AV companies and software distributors are just now
> acknowledging it?
>

I've just checked a few trial downloads and can't see any evidence of
the wrapper. I wonder if Cnet has pulled it from its site, or maybe it
is selective in some way - I'm using Win7/IE9 and based in the UK.

Could others report on their experiences?
(obviousy, don't let the installer run fully if the wrapper is evident)
 
Reply With Quote
 
~BD~
Guest
Posts: n/a
 
      7th Dec 2011
Nemo wrote:
> On 07/12/2011 05:38, G. Morgan wrote:
>> Virus Guy wrote:
>>
>>> Meanwhile Graham Cluley, security expert and blogger for Sophos in the
>>> UK, expressed his surprise on Twitter, saying, "What on earth is CNET
>>> playing at wrapping downloads (VLC, Nmap, etc) with a cruddy toolbar?"

>>
>> I broke this story months ago and provided a homemade video on how to
>> get around it. The AV companies and software distributors are just now
>> acknowledging it?
>>

> I've just checked a few trial downloads and can't see any evidence of
> the wrapper. I wonder if Cnet has pulled it from its site, or maybe it
> is selective in some way - I'm using Win7/IE9 and based in the UK.
>
> Could others report on their experiences?
> (obviously, don't let the installer run fully if the wrapper is evident)



Have you read here, Nemo?

http://krebsonsecurity.com/2011/12/d...lbars-trojans/

HTH
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:50 PM.