TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Reverse Engineering an Eclipse Plugin

135 pointsby RKoutnikover 7 years ago

8 comments

guildanover 7 years ago
The plugin that is inspected in this article is now delisted in the Eclipse Marketplace. You can&#x27;t download it from there anymore (Checked with STS 3.9.0.RELEASE). A new fork without the ad related code as been publish and you can inspect the code on <a href="https:&#x2F;&#x2F;github.com&#x2F;ecd-plugin&#x2F;ecd" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;ecd-plugin&#x2F;ecd</a> .<p>It&#x27;s nice to see the community stepping in to &quot;fix&quot; the situation.
philbarrover 7 years ago
Original author doing a pretty bad job of explaining himself [0]. Mainly:<p>Anyone who does not like it, please uninstall this plugin.<p>I will not explain it anymore.<p>I&#x27;m not interested in stealing your privacy.<p>[0] <a href="https:&#x2F;&#x2F;github.com&#x2F;cnfree&#x2F;Eclipse-Class-Decompiler&#x2F;issues&#x2F;30" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;cnfree&#x2F;Eclipse-Class-Decompiler&#x2F;issues&#x2F;30</a>
评论 #15457331 未加载
philbarrover 7 years ago
Alternative version:<p><a href="http:&#x2F;&#x2F;marketplace.eclipse.org&#x2F;content&#x2F;enhanced-class-decompiler?mpc=true&amp;mpc_state=" rel="nofollow">http:&#x2F;&#x2F;marketplace.eclipse.org&#x2F;content&#x2F;enhanced-class-decomp...</a>
hiram112over 7 years ago
Good writeup on the reverse engineering.<p>I&#x27;m still a little confused as to what the code was doing, though. It gathers statistics about your user machine (none of which seemed too personal - basically IP, OS, country, etc).<p>But then what is it doing? Opening a virtual browser or simulating clicks to some ad network?
评论 #15456223 未加载
ramshankerover 7 years ago
Guess author of the plugin is pretty smart but not smart enough to encrypt the traffic back home or obscure his&#x2F;her nasty secrets.<p>I guess it might be keeping the black stuff for some cool down time just after installation. Many malware seem to do there days. We might have got true clicks targeted.
评论 #15456889 未加载
nalleroothover 7 years ago
While this was a popular plugin for Eclipse - I&#x27;m sure there are plugins for other editors, IDEs and browsers which do the same (or worse). Yet, we often try a multitude of plugins without a single thought about any unwanted features bundled with the main features.
moocowtruckover 7 years ago
and so many people make fun of js&#x2F;node... this dude made over 400k installs part of his personal ad clicking bot net..
zaphirplaneover 7 years ago
Thank you for doing this, makes you think how many other highly rated&#x2F;used s&#x2F;w is malicious