Download.com not so safe.

  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 12th, 2008, 4:12 am

Well I was always under the impression that http://www.download.com was 100% safe, and I thought that checked those files before adding them to the website.

I downloaded a SQL Injection scanner, To try and protect myself ( seeing if my site had any security issues)

After download AVG and my other AV picked up 3 trojans and 1 keylogger. Now I was shocked at this becuase I really did think the site was safe.

Do you think there is any point in emailing them if I have proof of the spyware and trojans? and also the file that is effected?

As anyone else had issues like this with download.com?
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post April 12th, 2008, 4:12 am

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post April 12th, 2008, 5:37 am

I'm glad you mentioned that because I ran across a site that claims to scan other sites for safety and I entered download.com into it. It said it was safe.

http://www.explabs.com/

They are also selling their software.
How do you know when a politician is lying? His mouth is moving.
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23404
  • Loc: Woodbridge VA
  • Status: Offline

Post April 12th, 2008, 7:04 am

Maybe it's just me, but I would think that it would be logical to assume that a good virus scanner would see a SQL Injection scanner as a threat/risk. Having a bit of deja vu here. Could have sworn you posted something similar to this before.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • joebert
  • Sledgehammer
  • Genius
  • No Avatar
  • Joined: Feb 10, 2004
  • Posts: 13455
  • Loc: Florida
  • Status: Offline

Post April 12th, 2008, 7:11 am

That's a pretty good point ATNO.

I haven't used download.com in quite awhile now, but when I used to use it alot of the applications there were filled with crapware.
Strong with this one, the sudo is.
  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 12th, 2008, 9:52 am

ATNO/TW wrote:
Maybe it's just me, but I would think that it would be logical to assume that a good virus scanner would see a SQL Injection scanner as a threat/risk. Having a bit of deja vu here. Could have sworn you posted something similar to this before.


That was something slightly different. IP scanner from another source. But from download.com how could they justify a keylogger?
  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post April 12th, 2008, 10:48 am

Penguin: download.com is part of cnet. Why don't you contact them and tell them what you have found? If you don't want to do it, then I will. Let me know.

arin-tech@cnet.com
How do you know when a politician is lying? His mouth is moving.
  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 12th, 2008, 11:15 am

My luck sucks on emailing people, Would you like me to give you the file name, And everything?
  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post April 12th, 2008, 12:23 pm

I'm going to point them to this thread, so go ahead and post it.
How do you know when a politician is lying? His mouth is moving.
  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 12th, 2008, 12:31 pm

Link: http://www.download.com/3001-2181_4-103 ... d9b289f0fe
  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 12th, 2008, 12:31 pm

That should be correct if not I will look again.
  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post April 12th, 2008, 12:38 pm

Ok, I sent an email and I'll post the response when I get it.
How do you know when a politician is lying? His mouth is moving.
  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 12th, 2008, 1:00 pm

Ok Thank you Don2007 :P
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23404
  • Loc: Woodbridge VA
  • Status: Offline

Post April 15th, 2008, 12:46 pm

Just for kicks and giggles, I downloaded it, scanned it with Symantec Enterprise, installed it, and ran it, and at no point did it pick up any virus or threat.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • kc0tma
  • o|||||||o
  • Web Master
  • User avatar
  • Joined: Jul 20, 2007
  • Posts: 3318
  • Loc: Trout Creek, MT
  • Status: Offline

Post April 15th, 2008, 12:57 pm

Since we're kind of (but not really) on the subject, what is the purpose of the hack safe label you see on so many sites?

Image

Because I have read that those are foney and they aren't really tested daily. To the average person surfing the web, they do give a false sense of security, but for me it is kind of annoying. Anyone feel the same?

And I once read an article about some company that you could submit your open source code to and they would test it and approve it and you could display their little picture on your site. So one guy decided to probe them and see how good they really test submitted software. He sent them a plain jane text file with a single line in it that served absolutely no purpose. And wouldn't you believe it, they approved his "program".

This concludes my random thought.
Like Mr Spork, I also write about my interest in alcoholic beverages.
  • penguin
  • Flying penguins
  • Banned
  • User avatar
  • Joined: Oct 12, 2007
  • Posts: 1647
  • Loc: Behind you !
  • Status: Offline

Post April 15th, 2008, 1:48 pm

ATNO/TW wrote:
Just for kicks and giggles, I downloaded it, scanned it with Symantec Enterprise, installed it, and ran it, and at no point did it pick up any virus or threat.


I am positive I have the right file, Why would my AV show a trojan / keylogger?
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post April 15th, 2008, 1:48 pm

Post Information

  • Total Posts in this topic: 23 posts
  • Users browsing this forum: No registered users and 123 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.