public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* Re: Re: setup.exe hijacked?
@ 2009-09-10 11:21 Michael PARKER
  0 siblings, 0 replies; only message in thread
From: Michael PARKER @ 2009-09-10 11:21 UTC (permalink / raw)
  To: gchicares, dave.korn.cygwin; +Cc: cygwin

Greg, Dave,

A repeat of my activities earlier (file download via IE8 *and* wget) shows the problem to have now gone away.

I've still got a copy of the "bad" file - same file size as the "good" setup.exe but with a earlier timestamp:

-rwx------+  1 585728 Aug  5  2008 setup.exe_bad*
-rwx------+  1 585728 Sep 10 11:56 setup.exe* 

A "file" (OK, not difficult to fool) shows both to be:

MS-DOS executable PE  for MS Windows (GUI) Intel 80386 32-bit, UPX compressed

---

A browser hijack is possible (and something I'll look into), although the fact I'm now able to download without problem (via both IE8 and wget) suggests otherwise. I've not rebooted in the meantime and besides, a download via wget was giving the same problem earlier. This latter observation may be explained by local proxy caching, though.

The fact that the "bad" setup.exe crashed when executed suggests it might be corrupted in some way. Could some form of proxy issue result in transient data from two independent sources (the genuine setup.exe plus some transient "ebuddy" traffic) being merged into a single file?

Interestingly, I see multiple WinXP crash dialogs when attmpting to run the "bad" executable. Not something I've seen with other crashing applications before. 

If either of you guys are sufficiently interested, I can send over a gzip'ed copy of the bad file.

Thanks for the interest,

Mike





--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2009-09-10 11:21 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2009-09-10 11:21 Re: setup.exe hijacked? Michael PARKER

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).