TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Non-official site with a tampered version of KeePass

151 点作者 redsec将近 7 年前

12 条评论

adtac将近 7 年前
Hah, the Linux version points you to the original website (only the Mac and Windows versions appear to be modified)! The year of the Linux desktop is truly here.
评论 #17624954 未加载
po1nter将近 7 年前
I&#x27;ve reported the website here: <a href="https:&#x2F;&#x2F;safebrowsing.google.com&#x2F;safebrowsing&#x2F;report_phish&#x2F;?tpl=mozilla&amp;hl=en-US&amp;url=https%3A%2F%2Fkeepass.fr%2F" rel="nofollow">https:&#x2F;&#x2F;safebrowsing.google.com&#x2F;safebrowsing&#x2F;report_phish&#x2F;?t...</a><p>Hopefull it will be blocked by the browsers using the safe browsing list.
评论 #17625209 未加载
评论 #17625382 未加载
评论 #17624773 未加载
zokier将近 7 年前
I&#x27;ve had discussions with coworkers on why you shouldn&#x27;t ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads <i>now</i>, but imho it&#x27;s just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned
评论 #17626050 未加载
评论 #17627552 未加载
campuscodi将近 7 年前
There are quite a few of these:<p><a href="https:&#x2F;&#x2F;keepass.fr&#x2F;" rel="nofollow">https:&#x2F;&#x2F;keepass.fr&#x2F;</a> <a href="https:&#x2F;&#x2F;7zip.fr" rel="nofollow">https:&#x2F;&#x2F;7zip.fr</a> <a href="https:&#x2F;&#x2F;audacity.fr" rel="nofollow">https:&#x2F;&#x2F;audacity.fr</a> <a href="https:&#x2F;&#x2F;gparted.fr" rel="nofollow">https:&#x2F;&#x2F;gparted.fr</a> <a href="https:&#x2F;&#x2F;keepass.fr" rel="nofollow">https:&#x2F;&#x2F;keepass.fr</a> <a href="https:&#x2F;&#x2F;nc3354.nexylan.net" rel="nofollow">https:&#x2F;&#x2F;nc3354.nexylan.net</a> <a href="https:&#x2F;&#x2F;paintnet.fr" rel="nofollow">https:&#x2F;&#x2F;paintnet.fr</a>
评论 #17628603 未加载
评论 #17626145 未加载
pingec将近 7 年前
What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary?<p>Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.
评论 #17624950 未加载
评论 #17625004 未加载
评论 #17625272 未加载
评论 #17625899 未加载
评论 #17624928 未加载
评论 #17625054 未加载
ajnin将近 7 年前
I&#x27;m getting a different installer file from this website with not as many ad bundles detected : <a href="https:&#x2F;&#x2F;www.virustotal.com&#x2F;#&#x2F;file&#x2F;23c3a4564265bc996ab61c1227feda7aa5a3e41033717421310fef3e42871bfc&#x2F;detection" rel="nofollow">https:&#x2F;&#x2F;www.virustotal.com&#x2F;#&#x2F;file&#x2F;23c3a4564265bc996ab61c1227...</a><p>Anyway, this wouldn&#x27;t be the first time an open source software is packaged with some adware. Unsavory, but I think within the limits of the license.
评论 #17624940 未加载
oliviergg将近 7 年前
Pretty ironicly, Terms of use warn to be very careful when downloading files with an exe.,. Vbs,. Lnk,. Bat,. Sys, or a suffix com., Because these files may contain a virus or spyware !
评论 #17625007 未加载
评论 #17625480 未加载
moviuro将近 7 年前
Who did this without thinking about an exfiltration tool instead?
评论 #17624841 未加载
评论 #17624924 未加载
greggarious将近 7 年前
Unfortunately I can&#x27;t read the article without enabling javascript - anyone care to post a summary? :)
mar77i将近 7 年前
Unrelated to the topic, the article points out a lot of things about certificates in the URL bar. That got me to think about the URLs themselves, can I set my browser up so it displays the punycode representation of my url?
评论 #17629433 未加载
amaccuish将近 7 年前
The french is also terrible, google-translated french.
评论 #17624781 未加载
评论 #17624819 未加载
评论 #17624812 未加载
评论 #17624766 未加载
swaggyBoatswain将近 7 年前
Something I don&#x27;t understand though is when I do a google search, google sometimes sponsors these phony sites.<p>One time I downloaded the wrong google chrome which was ironic because I was on google searching it.<p>Other examples that come to mind with different sites are popcorn.sh vs popcorn-time.to. There not the same repository.<p>Normally I just do a sanity check by checking the domain URL and checking if it has authority.<p>If its on sourceforge... I just assume its malware or has bundled PUPware on it, run it through antivirus and SHA&#x2F;MD5 checks.<p>Ninite.com is pretty convenient I hope they don&#x27;t get comprimised one of these days and get sold to a shady vendor