{"id":184934,"date":"2011-12-05T22:38:00","date_gmt":"2011-12-06T03:38:00","guid":{"rendered":"https:\/\/www.panix.com\/~msaroff\/40years\/2011\/12\/05\/dont-use-download-com\/"},"modified":"2011-12-05T22:38:00","modified_gmt":"2011-12-06T03:38:00","slug":"dont-use-download-com","status":"publish","type":"post","link":"https:\/\/www.panix.com\/~msaroff\/40years\/2011\/12\/05\/dont-use-download-com\/","title":{"rendered":"Don&#8217;t Use Download.com"},"content":{"rendered":"<p>Seriously.&nbsp; They have <a href=\"http:\/\/seclists.org\/nmap-hackers\/2011\/5\">taken to bundling malware with their download installers<\/a>:<\/p>\n<blockquote style=\"color: blue;\"><p><i>From: Fyodor <fyodor ()=\"\" insecure=\"\" org=\"\"><br \/>Date: Mon, 5 Dec 2011 14:35:30 -0800<\/fyodor><\/i><\/p>\n<p>Hi Folks.  I&#8217;ve just discovered that C|Net&#8217;s Download.Com site has<br \/>started wrapping their Nmap downloads (as well as other free software<br \/>like VLC) in a trojan installer which does things like installing a<br \/>sketchy &#8220;StartNow&#8221; toolbar, changing the user&#8217;s default search engine<br \/>to Microsoft Bing, and changing their home page to Microsoft&#8217;s MSN.<\/p>\n<p>The way it works is that C|Net&#8217;s download page (screenshot attached)<br \/>offers what they claim to be Nmap&#8217;s Windows installer.  They even<br \/>provide the correct file size for our official installer.  But users<br \/>actually get a Cnet-created trojan installer.  That program does the<br \/>dirty work before downloading and executing Nmap&#8217;s real installer.<\/p><\/blockquote>\n<div style=\"border: 1px solid black; float: right; margin: 0px 10px; padding: 5px; text-align: center; width: 200px;\"><a \"=\"\" href=\"http:\/\/img99.imageshack.us\/img99\/3903\/13zathras1zu5.jpg\"><img decoding=\"async\" \"=\"\" border=\"0\" bordercolor=\"white\" src=\"http:\/\/img99.imageshack.us\/img99\/3903\/13zathras1zu5.jpg\" width=\"190\" \/><\/a><br \/><span style=\"font-style: italic;\">At least, there is symmetry<\/span><\/div>\n<p>Note that the author of this post is also the author of Nmap, and this violates his license.<\/p>\n<p>Here&#8217;s <a href=\"http:\/\/www.extremetech.com\/computing\/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations\">some more background<\/a>.<\/p>\n<p>The fact that they (CNET\/Download.com) also employ &#8220;<a href=\"http:\/\/www.extremetech.com\/computing\/93504-download-com-wraps-downloads-in-bloatware-lies-about-motivations\">Draw by Crayon Libertarian<\/a>&#8221; Declan McCullagh, who is still proud of creating the &#8220;Al Gore created the Internet&#8221; lie provides a book end for this crap.<\/p>\n<p>I&#8217;m not suggesting a boycott here.&nbsp; I&#8217;m suggesting that CNET, and more specifically Download.com, has crossed a line and is now a purveyor of malware.<\/p>\n<p>It&#8217;s just not me saying this, it&#8217;s, &#8220;Panda, McAfee, F-Secure,&#8221; (top link) who are classifying their wrappers as spyware.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Seriously.&nbsp; They have taken to bundling malware with their download installers: From: Fyodor Date: Mon, 5 Dec 2011 14:35:30 -0800 Hi Folks. I&#8217;ve just discovered that C|Net&#8217;s Download.Com site hasstarted wrapping their Nmap downloads (as well as other free softwarelike VLC) in a trojan installer which does things like installing asketchy &#8220;StartNow&#8221; toolbar, changing the &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1005,969,1064,989],"tags":[],"class_list":["post-184934","post","type-post","status-publish","format-standard","hentry","category-business","category-evil","category-media","category-software"],"_links":{"self":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/posts\/184934"}],"collection":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/comments?post=184934"}],"version-history":[{"count":0,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/posts\/184934\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/media?parent=184934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/categories?post=184934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/tags?post=184934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}